Lead Security Architect (Application Security)
Job Description
Wells Fargo is seeking a Lead Security Architect focused on application security to set security architecture direction across application development, APIs, DevSecOps practices, and emerging technologies. This role supports secure-by-design delivery at enterprise scale through threat modeling, architecture reviews, and technical guidance throughout the project lifecycle.
Role Summary
In this position, you will lead security architecture efforts that influence how enterprise applications and platforms are designed, assessed, and secured. Responsibilities include shaping architectural artifacts, partnering across engineering and risk functions, and providing guidance that aligns solutions with established Wells Fargo standards, policies, methodologies, and industry best practices.
Key Responsibilities
- Lead the implementation of complex projects and initiatives with companywide scope
- Drive secure-by-design practices across applications, APIs, cloud-native platforms, and AI-enabled solutions
- Develop architectural artifacts including standards, reference architectures, design patterns, and security requirements
- Contribute to future technology architecture definition and Application Security strategy
- Identify medium to high architectural impact projects and provide security architecture guidance across the lifecycle
- Conduct complex technology, security, and system assessments for architecture solutions
- Perform threat modeling, architecture reviews, and risk assessments for critical applications and platforms
- Provide guidance on DevSecOps, software supply chain security, CI/CD security, and application security testing
- Make decisions related to the development and maintenance of security architectures and controls
- Understand compliance and risk management requirements for supported areas
- Ensure applications adhere to Wells Fargo standards, policies, methodologies, and industry best practices
- Collaborate and consult with peers, colleagues, and managers to resolve issues and achieve goals
Required Experience
- 5+ years of Architecture experience (or equivalent through work experience, training, military experience, or education)
- 5+ years of Information Security, Security Architecture, Application Security, or Software Security experience
- Experience performing threat modeling, architecture reviews, and security assessments
- Knowledge of secure software development lifecycle (SSDLC) and secure coding practices
- Experience securing cloud-based applications, APIs, and modern application architectures
Technical Focus and Tools
- OWASP Top 10
- Azure, AWS, Google Cloud
- SAST, DAST, SCA
- IaC scanning
- GitHub Copilot
- Kubernetes, microservices, containers
- AI/GenAI
Preferred / Desired Qualifications
- Strong knowledge of application security principles, OWASP Top 10, API Security, and common attack vectors
- Experience with SAST, DAST, SCA, IaC scanning, and software supply chain security controls
- Experience with cloud-native architectures, containers, Kubernetes, microservices, and APIs
- Knowledge of Azure, AWS, or Google Cloud security architectures
- Experience developing security standards, patterns, and reference architectures
- Familiarity with AI/GenAI security risks and mitigation strategies
- Strong verbal and written communication skills and stakeholder management experience
Job Expectations
- Hybrid work schedule
- Visa sponsorship not available
- Demonstrate proficiency using AI-assisted development and analysis tools (for example, GitHub Copilot and approved code-centric agents)
- Use AI to accelerate system design, coding, testing, analysis, and troubleshooting
- Apply technical judgment when validating and integrating AI-assisted outputs
- Account for model limitations, security risks, and operational considerations
- Use AI responsibly in development and production environments
- Ensure AI usage aligns with security, compliance, privacy, and ethical standards
- Serve as a trusted security architecture advisor for application and platform teams
- Partner with engineering, architecture, risk, and cybersecurity teams to drive secure technology adoption
- Deliver architecture reviews, threat models, and security recommendations for strategic initiatives
- Support and enhance enterprise Application Security standards and secure-by-design practices
- Mentor architects and engineers on application security and emerging technology risks
- Operate effectively in a highly regulated and risk-driven environment
- Influence security strategy, architecture patterns, and technology decisions across the enterprise
Compensation
USD 119,000 - 206,000 per yearly
- $119,000 - $187,000 - Charlotte, NC
- $119,000 - $187,000 - Irving, TX
- $119,000 - $187,000 - Columbus, OH
- $131,000 - $206,000 - Minneapolis, MN
Benefits
- Health benefits
- 401(k) Plan
- Paid time off
- Disability benefits
- Life insurance, critical illness insurance, and accident insurance
- Parental leave
- Critical caregiving leave
- Discounts and savings
- Commuter benefits
- Tuition reimbursement
- Scholarships for dependent children
- Adoption reimbursement
Additional Information
- Posting end date: 24 Sep 2026 (job posting may come down early due to volume of applicants)
- Wells Fargo is an equal opportunity employer.
- For disability-related accommodations during the application or interview process, visit Disability Inclusion at Wells Fargo.
- Wells Fargo maintains a drug-free workplace (see Drug and Alcohol Policy).
- Third-party recordings are prohibited unless authorized by Wells Fargo.
- Wells Fargo requires applicants to directly represent their own experiences during the recruiting and hiring process.
Location
Charlotte, NC (hybrid)