About this role:
Wells Fargo is seeking a Principal Vulnerability & Patch Management Security Engineer to provide enterprise leadership for the modernization and transformation of Vulnerability Management (VM) capabilities across the organization. This role will serve as a strategic technical leader driving the evolution of the Vulnerability and Patch Management (VPM) program through automation, platform modernization, cloud-native security engineering, and AI-enabled vulnerability intelligence.
The Principal Security Engineer will be responsible for defining and executing the long-term strategy for vulnerability management technologies, including deprecating legacy VM platforms, implementing modern vulnerability management solutions, and driving adoption across a complex hybrid and multi-cloud environment. This individual will partner across Infrastructure, Cloud Engineering, Cyber Security, DevOps, and Application Development teams to eliminate technical roadblocks, improve operational efficiency, and deliver scalable security engineering solutions that reduce enterprise risk.
This role requires a unique blend of security engineering, automation, cloud security, data engineering, platform transformation, and executive influence to support the next generation of Wells Fargo's Vulnerability Management capabilities.
In this role, you will:
- Act as a trusted advisor to executive leadership and engineering organizations to develop and influence enterprise-wide vulnerability management, security engineering, cloud security, and automation strategies.
- Lead the transformation of the Vulnerability and Patch Management (VPM) program by identifying opportunities to automate manual processes and implement AI-driven security capabilities.
- Define and execute strategies for decommissioning legacy vulnerability management platforms and transitioning teams to modern vulnerability management technologies and operating models.
- Drive enterprise adoption of next-generation vulnerability management capabilities through technical leadership, stakeholder engagement, and cross-functional partnership.
- Lead the strategy and resolution of highly complex security engineering challenges requiring evaluation across multiple technology domains and business lines.
- Translate advanced technical expertise and deep knowledge of enterprise security architecture into innovative engineering solutions that support long-term business objectives.
- Design and oversee API-first security architectures that enable automation, orchestration, and integration across vulnerability management, cloud security, and enterprise security platforms.
- Develop and influence automation frameworks, scripting solutions, and engineering standards that improve vulnerability identification, prioritization, remediation, and reporting.
- Partner with DevOps, Infrastructure, and Engineering teams to integrate vulnerability management tools and controls into CI/CD pipelines and Infrastructure as Code (IaC) frameworks.
- Establish best practices for implementing and maintaining security controls within modern software development and deployment environments.
- Provide strategic guidance on operating effectively across hybrid and multi-cloud environments, including cloud-native vulnerability management and security monitoring capabilities.
- Lead initiatives that aggregate, correlate, normalize, and enrich vulnerability data from multiple security tools, cloud platforms, and enterprise systems.
- Partner with data engineering teams to develop scalable security data pipelines, leverage enterprise data lakes, and utilize advanced SQL analytics to improve vulnerability intelligence and decision-making.
- Act as a human-in-the-loop technical expert for data-driven vulnerability management capabilities that leverage automated deduplication, correlation, prioritization, and AI-based recommendations.
- Research emerging cyber threats, vulnerability management technologies, and innovative security solutions that enhance organizational security posture and operational efficiency.
- Maintain expert-level knowledge of industry best practices, security architecture trends, cloud technologies, vulnerability management frameworks, and AI-driven security solutions.
- Provide vision, direction, and expertise to senior leadership on implementing significant and innovative cyber security engineering solutions.
- Strategically engage with all levels of professionals and managers across the enterprise, influencing technical decisions, operational priorities, and security roadmaps.
- Drive consensus across multiple organizations and remove organizational and technical barriers that impede security transformation initiatives.
- Serve as a recognized subject matter expert in vulnerability management, security automation, cloud security engineering, and enterprise security architecture.
- Demonstrate proficiency in using AI‑assisted development and analysis tools (e.g., GitHub Copilot and approved code‑centric agents)
- Leverage AI to accelerate system design, coding, testing, analysis, and troubleshooting
- Apply strong technical judgment when validating and integrating AI‑assisted outputs into solutions
- Understand and account for model limitations, security risks, and operational considerations
- Apply AI responsibly in development and production environments
- Ensure AI usage aligns with security, compliance, privacy, and ethical standards
Required Qualifications:
- 7+ years of Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
Desired Qualifications:
- 5+ years of experience in Vulnerability Management, Patch Management, Security Engineering, or Cyber Security Operations.
- Proven success modernizing enterprise vulnerability management programs, including retirement of legacy platforms and implementation of next-generation VM solutions.
- Experience developing API-based integrations, security automation solutions, and scripting using Python, PowerShell, or similar technologies.
- Strong understanding of CI/CD pipelines, DevSecOps practices, and Infrastructure as Code (IaC).
- Experience integrating vulnerability scanning and security controls into software development and cloud engineering workflows.
- Experience securing hybrid and multi-cloud environments, including AWS, Azure, and Google Cloud Platform.
- Knowledge of security data aggregation, data lakes, data correlation, and SQL-based analytics.
- Experience leveraging AI, machine learning, or advanced analytics to improve vulnerability prioritization and risk reduction.
- Strong understanding of vulnerability management frameworks, exposure management, and risk-based remediation strategies.
- Exceptional stakeholder management, executive communication, and cross-functional influence skills.
- Experience leading enterprise-wide initiatives and removing organizational and technical roadblocks in highly matrixed environments.
- Experience within a large, regulated organization, preferably financial services.
Job Expectations:
- Ability to travel up to 10% of the time.
- Ability to work a hybrid work schedule – 3 days a week on-site/in office and 2 days a week remote.
- This position is not eligible for Visa sponsorship.
Locations:
- Charlotte, NC
- Chandler, AZ
- Irving, TX
Pay Range
Reflected is the base pay range offered for this position. Pay may vary depending on factors including but not limited to demonstrated examples of prior performance, skills, experience, or work location. Employees may also be eligible for incentive opportunities.
$159,000.00 - $254,000.00
Benefits
Wells Fargo provides eligible employees with a comprehensive set of benefits, many of which are listed below. Visit for an overview of the following benefit plans and programs offered to employees.
- Health benefits
- 401(k) Plan
- Paid time off
- Disability benefits
- Life insurance, critical illness insurance, and accident insurance
- Parental leave
- Critical caregiving leave
- Discounts and savings
- Commuter benefits
- Tuition reimbursement
- Scholarships for dependent children
- Adoption reimbursement
Posting End Date:
7 Aug 2026
*Job posting may come down early due to volume of applicants.