Principal Engineer - Application Security: Secure Development
Job
Wells Fargo
Remote
Full-Time
Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
79
out of 100
Average of individual scores
Skill Insights
Compare your current skills to what this opportunity needs—we'll show you what you already have and what could strengthen your application.
Job Description
- About this role:
- Application Security enhances the ability of the development organization to consistently deliver highly functional applications that are secure and resilient against attack.
- In this role, you will:
- + Act as an advisor to leadership to develop or influence applications, network, information security, database, operating systems, or web technologies for highly complex business and technical needs across multiple groups + Lead the strategy and resolution of highly complex and unique challenges requiring in-depth evaluation across multiple areas or the enterprise, delivering solutions that are long-term, large-scale and require vision, creativity, innovation, advanced analytical and inductive thinking + Translate advanced technology experience, an in-depth knowledge of the organizations tactical and strategic business objectives, the enterprise technological environment, the organization structure, and strategic technological opportunities and requirements into technical engineering solutions + Provide vision, direction and expertise to leadership on implementing innovative and significant business solutions + Maintain knowledge of industry best practices and new technologies and recommends innovations that enhance operations or provide a competitive advantage to the organization + Strategically engage with all levels of professionals and managers across the enterprise and serve as an expert advisor to leadership + Lead and mentor a federated network of Application Security Champions (ASCs), establishing standards, playbooks, and metrics to scale secure development practices consistently across non CIO engineering teams + Drive integration of application security controls into CI/CD pipelines and developer tooling, enabling automated detection and remediation of vulnerabilities across the software development lifecycle + Oversee threat modeling, vulnerability assessments, and secure design reviews for complex, high risk applications and shared services, ensuring alignment with enterprise security policies and standards + Champion secure adoption of emerging technologies, including AI/LLM-enabled applications, by defining guardrails, patterns, and risk mitigation strategies for safe enterprise use •
Required Qualifications:
- + 7+ years of Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education + 7+ years Application Security Engineering + Experience building AI/LLM Application Security scalable solutions for enterprise production environments
- Required Qualifications for Europe, Middle East & Africa only:
- + Experience in Engineering, or equivalent demonstrated through one or a combination of the following: work experience, training, education
Desired Qualifications:
- + Demonstrated deep, hands-on expertise in: + Secure application architecture and design + Secure coding practices and code-level vulnerability analysis + Threat modeling and abuse case analysis + Authentication, authorization, session management, API security, and secrets management + Common application vulnerabilities and exploit patterns (e.
- Java, .NET, Python, JavaScript/TypeScript, Node.js, Go
- , or similar. + Experience integrating security into
- CI/CD pipelines
- , developer workflows, and engineering platforms. + Experience with one or more of the following:
- SAST, SCA, DAST, IaC scanning, container security, API security testing, code review, threat modeling, runtime protection
- , or software supply chain security controls. + Hands-on experience with
- AI security
- , including securing AI-enabled applications or advising engineering teams on the secure use of AI/LLM-based capabilities.
- Application Security Champion
- , Security Champion, embedded security lead, or senior engineer responsible for driving security within product/application teams. + Experience designing security controls for
- cloud-native
- and distributed systems running in
- Azure, AWS, or GCP
- . + Experience with
- software supply chain security
- , including dependency risk management, build pipeline hardening, SBOM, artifact integrity, provenance, and package governance. + Experience with
- runtime application protection
- , threat detection, or exploit prevention technologies. + Familiarity with
- Zero Trust
- , secure platform engineering, and policy-as-code approaches.
Certifications:
CSSLP, GIAC GWEB, CISSP, GIAC GWAPT, CCSP, CCSP
Job Expectations:
- + • Ability to travel up to 10% of the time.
- Ability to work a hybrid schedule - 3 days per week on-site/in office and 2 days per week remote
- This position is not eligible for Visa sponsorship
Posting End Date:
- 29 May 2026
- _•Job posting may come down early due to volume of applicants.
- We Value Equal Opportunity
- Wells Fargo is an equal opportunity employer.
Canada:
Applications for employment are encouraged from all qualified candidates, including women, persons with disabilities, aboriginal peoples and visible minorities. Accommodation for applicants with disabilities is available upon request in connection with the recruitment process.- Applicants with Disabilities
- To request a medical accommodation during the application or interview process, visit Disability Inclusion at Wells Fargo (https://www.wellsfargojobs.com/en/diversity/disability-inclusion/) .
- Drug and Alcohol Policy
- Wells Fargo maintains a drug free workplace. Please see our Drug and Alcohol Policy (https://www.wellsfargojobs.com/en/wells-fargo-drug-and-alcohol-policy) to learn more.
Wells Fargo Recruitment and Hiring Requirements:
- a. Third-Party recordings are prohibited unless authorized by Wells Fargo. b. Wells Fargo requires you to directly represent your own experiences during the recruiting and hiring process.
Req Number:
- R-546631
Similar jobs in Charlotte, NC
Beacon Hill Staffing Group
Charlotte, NC
Posted1 day ago
Updated7 hours ago
Campbell Soup Company
Charlotte, NC
Posted1 day ago
Updated7 hours ago
BCforward
Charlotte, NC
Posted1 day ago
Updated7 hours ago
Similar jobs in North Carolina
Acadia Physician Recruiters
North Carolina
Posted1 day ago
Updated7 hours ago
UNC Health
North Carolina
Posted1 day ago
Updated7 hours ago
Angels of Care Pediatric Home Health
Chapel Hill, NC
Posted1 day ago
Updated7 hours ago