Senior Lead Information Protection Security Analyst
Wells Fargo
- Location
- ISELIN, NJ
- Work model
- On-Site
- Level
- Senior
- Posted
- 4h ago
Skills
About this role
About this role: Wells Fargo is seeking a Senior Lead Information Protection Security Analyst to join the Information Protection Domain within Cybersecurity. This role provides enterprise leadership for information protection strategy, governance, and risk management programs focused on safeguarding the firm's sensitive data assets. The successful candidate will drive initiatives related to data discovery, classification, protection, governance, and regulatory compliance while partnering across technology, cybersecurity, legal, privacy, risk, and business teams to reduce information security risk and improve the firm's overall data protection posture. In this role, you will: Provide oversight to the Information Security program for a major line of business Consult with line of business on the consistent implementation of the enterprise information security model and solutions to remediate information security risks Ensure that risks to all information assets are being managed in a timely and effective manner to meet the Information Security Program requirements and the current threat landscape Ensure information security capabilities are included in all aspects of the company's technology architecture Proactively manage the information security risk profile of line of business information assets throughout the lifecycle of the asset Provide vision, direction, and expertise to more experienced leadership on implementing innovative and significant business solutions that are large-scale, cross-functional, or companywide strategies Ensure the team has the necessary training and is keeping abreast of regulatory and compliance issues Engage with all levels of professionals and managers companywide and serve as an experienced advisor to leadership Develop, implement, and maintain the enterprise cryptographic governance framework, including policies, standards, and procedures. Develop and maintain cryptographic policies, standards, and control requirements (e.g., encryption, key management, certificates), ensuring alignment with applicable regulatory and industry frameworks (e.g., NIST, PCI DSS, ISO 27001). Operate governance routines to ensure consistent application of cryptographic controls across the enterprise. Review and evaluation new or updated cryptographic new solutions. Lead governance forums, reporting, and escalation processes to senior leadership. Align governance activities with the enterprise cryptographic strategy, including roadmap initiatives and long-term objectives. Participate in periodic reviews of cryptographic strategy and data protection initiatives. Ensure governance supports enterprise priorities related to data protection, risk management, and security modernization. Establish and maintain visibility into cryptographic risks, including vulnerabilities and non-compliance. Define key metrics and reporting mechanisms to monitor cryptographic posture. Escalate issues related to non-adherence to cryptographic policy through established governance channels. Support the identification, prioritization, and tracking of risk remediation activities. Assist with exception management, ensuring appropriate documentation, risk acceptance, and tracking. Collaborate regularly with cross-functional stakeholders, including Cybersecurity Architecture, Secure Network Services (SNS), Cloud Security, and application teams, on solutions, strategies, and policies. Act as a central point of coordination for cryptographic governance activities. Provide guidance and direction to engineering and operational teams on governance expectations. Support internal and external audits by providing required documentation, control evidence, and governance artifacts. Participate in the evaluation of cryptographic discovery tools and capabilities. Develop program to cryptographic discovery tools, capabilities, reporting and metrics. Monitor enterprise cryptographic posture and identify risks through tool outputs. Demonstrate foundational AI