AppSec Jobs
← Back to all jobs

Wells Fargo

Principal Engineer - Application Security: Secure Development

Remote
Chandler, AZPosted 1 week agoWebsite
Apply on LinkedIn →

At a Glance

AWSAzureGCPPythonJavaJavaScript/TypeScript

About This Role

Application Security enhances the ability of the development organization to consistently deliver highly functional applications that are secure and resilient against attack. Wells Fargo is seeking a Principal Engineer who will lead a team of Application Security Champions (ASCs) that support Wells Fargo's Technology development teams, which deliver centralized shared services to our lines of business. ASCs promote and enable the security awareness to protect the Bank's applications by conducting vulnerability and fix reviews and training developers in secure coding best practices.

Responsibilities

  • Act as an advisor to leadership to develop or influence applications, network, information security, database, operating systems, or web technologies for highly complex business and technical needs across multiple groups
  • Lead the strategy and resolution of highly complex and unique challenges requiring in-depth evaluation across multiple areas of the enterprise, delivering solutions that are long-term, large-scale and require vision, creativity, innovation, advanced analytical and inductive thinking
  • Translate advanced technology experience, an in-depth knowledge of the organizations tactical and strategic business objectives, the enterprise technological environment, the organization structure, and strategic technological opportunities and requirements into technical engineering solutions
  • Provide vision, direction and expertise to leadership on implementing innovative and significant business solutions
  • Maintain knowledge of industry best practices and new technologies and recommends innovations that enhance operations or provide a competitive advantage to the organization
  • Strategically engage with all levels of professionals and managers across the enterprise and serve as an expert advisor to leadership
  • Lead and mentor a federated network of Application Security Champions (ASCs), establishing standards, playbooks, and metrics to scale secure development practices consistently across non CIO engineering teams
  • Drive integration of application security controls into CI/CD pipelines and developer tooling, enabling automated detection and remediation of vulnerabilities across the software development lifecycle
  • Oversee threat modeling, vulnerability assessments, and secure design reviews for complex, high risk applications and shared services, ensuring alignment with enterprise security policies and standards
  • Champion secure adoption of emerging technologies, including AI/LLM-enabled applications, by defining guardrails, patterns, and risk mitigation strategies for safe enterprise use

Requirements

OWASPJavaPythonJavaScriptTypeScriptGoCI/CDSASTSCADASTAzureAWSGCPCISSP
  • 7+ years of Engineering experience
  • 7+ years Application Security Engineering
  • Experience building AI/LLM Application Security scalable solutions for enterprise production environments
  • Demonstrated deep expertise in secure application architecture and design
  • Demonstrated deep expertise in secure coding practices and code-level vulnerability analysis
  • Demonstrated deep expertise in threat modeling and abuse case analysis
  • Demonstrated deep expertise in authentication, authorization, session management, API security, and secrets management
  • Knowledge of common application vulnerabilities and exploit patterns (e.g., OWASP Top 10, deserialization, injection, SSRF, access control issues, insecure design, dependency risk)
  • Strong hands-on experience securing applications built in Java, .NET, Python, JavaScript/TypeScript, Node.js, Go, or similar
  • Experience integrating security into CI/CD pipelines, developer workflows, and engineering platforms
  • Experience with SAST, SCA, DAST, IaC scanning, container security, API security testing, code review, threat modeling, runtime protection, or software supply chain security controls
  • Hands-on experience with AI security, including securing AI-enabled applications or advising engineering teams on the secure use of AI/LLM-based capabilities
  • Ability to independently investigate complex technical problems, identify root causes, and drive practical remediation
  • Strong written and verbal communication skills with the ability to influence both engineers and senior stakeholders
  • Proven ability to operate both strategically and tactically—moving from enterprise patterns to code-level detail as needed
  • Prior experience serving as an Application Security Champion, Security Champion, embedded security lead, or senior engineer responsible for driving security within product/application teams
  • Experience designing security controls for cloud-native and distributed systems running in Azure, AWS, or GCP
  • Experience with software supply chain security, including dependency risk management, build pipeline hardening, SBOM, artifact integrity, provenance, and package governance
  • Experience with runtime application protection, threat detection, or exploit prevention technologies
  • Familiarity with Zero Trust, secure platform engineering, and policy-as-code approaches
  • Experience defining standards, playbooks, or secure reference architectures that can be adopted broadly by engineering organizations
  • Background in software engineering or architecture prior to moving into security
  • Certifications: CSSLP, GIAC GWEB, CISSP, GIAC GWAPT, CCSP

About Wells Fargo

Wells Fargo & Company is a diversified multinational financial services institution based in San Francisco, California. Founded in 1852, the company has grown from its origins as an express shipping service during the California Gold Rush to become one of the largest financial services providers globally. With over 250,000 employees, Wells Fargo serves more than 70 million customers across more than 40 countries. The company offers a wide range of financial services, including retail and commercial banking, mortgages, wealth and asset management, credit cards, business banking, commercial finance, insurance, and investment services. Wells Fargo manages approximately $1.9 trillion in assets and operates over 12,000 ATMs and more than 7,300 retail locations. The leadership team includes CEO Charles W. Scharf and Board Chair Steven D. Black.

Industry

financial services

Employees

215,000

20566 engineers

Revenue

$122B

Website

Visit →

Security at Wells Fargo

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

Stated AppSec mission / SSDLC emphasis: • "Drive continuous improvement in Secure SDLC Requirements"– Wells Fargo Jobs (https://www.wellsfargojobs.com/en/jobs/r-510396/principal-engineer-application-security/), Job Posting • "embedding security in every stage of the build–deploy–operate loop"– Wells Fargo Jobs (r-510396), Job Posting

Security Team

Org structure & reporting line: • Job postings describe alignment to enterprise security and governance but do not state a single reporting chain explicitly. Information not publicly available.

Key Initiatives

Security Champions Program: • Status: Evidence Found (job posting for an "Application Security Champion") • Quote: "Application Security Champion responsible for reviewing security requirements"– AnitaB.org job listing (Wells Fargo), Job Posting

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.

Interested in this role?

Apply on LinkedIn