layiq
worthy; deserving; fitting; suitable.
A role, opportunity, or path that merits attention, time, and pursuit.
Loading LAYIQ…Job opportunity
Wells Fargo
CHARLOTTE, NC; 141278-NC-CIC Customer Information Ctr; IRVING, TX; COLUMBUS, OH
Source: Wells Fargo careers · View original posting
From Wells Fargo's posting. “We” and “our” refer to the employer.
Wells Fargo is seeking an Information Security Engineering Manager to lead a Privileged Access Management (PAM) engineering organization. This role is responsible for securing, modernizing, and evolving enterprise privileged access capabilities, including credential vaulting, secrets management, session control, and least‑privilege enforcement. The manager will oversee risk reduction related to privileged identities while driving automation, DevSecOps integration, and standardized access patterns.
This position will guide the team through PAM modernization initiatives, including retiring legacy access models, improving platform architecture, and enabling scalable, cloud‑ready privileged access solutions across hybrid environments.
Provide strategic leadership for the Privileged Access Management (PAM) platform, defining vision, roadmaps, and long‑term evolution for credential vaulting, session management, secrets management, and least‑privilege access across the enterprise
Lead teams responsible for securing privileged credentials and access paths, including account onboarding, rotation, session isolation, and policy enforcement for human and non‑human identities
Drive modernization of PAM capabilities, transitioning from legacy, manually managed access models to automated, policy‑driven, and API‑integrated solutions aligned with Zero Trust principles
Guide adoption of DevSecOps and automation patterns for privileged access, including CI/CD integrations, secrets delivery, ephemeral credentials, and infrastructure‑as‑code enablement
Oversee vulnerability reduction and risk mitigation related to privileged access, including elimination of hard‑coded credentials, shared accounts, excessive entitlements, and standing access
Partner closely with security architecture, IAM, cloud, infrastructure, and application teams to embed privileged access controls into platforms, pipelines, and operating models
Manage a team of engineers designing, implementing, documenting, and supporting highly complex PAM solutions spanning CyberArk, secrets management platforms, directory services, cloud IAM, and hybrid environments
Provide security consulting and design oversight for large enterprise initiatives to ensure privileged access patterns conform to information security policy, regulatory requirements, and audit expectations
Serve as a subject matter expert in PAM technologies and best practices, staying current on emerging threats, access models, and platform capabilities
Lead technical investigation and response for privileged access–related incidents, including root cause analysis and remediation recommendations to prevent recurrence
Ensure PAM controls support availability, confidentiality, integrity, access governance, monitoring, and incident response, while enabling business agility and developer productivity
5+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
2+ years of Leadership experience
Strong knowledge of DevSecOps patterns as they relate to privileged access, including secure CI/CD integration, automated credential delivery, secrets injection, and control enforcement
Hands‑on understanding of Kubernetes and cloud‑native environments from a privileged access perspective, including workload identity, service accounts, secrets distribution, and container access controls
Experience leading modernization of privileged access for legacy and home‑grown systems, including removal of hard‑coded credentials, reduction of shared accounts, and elimination of standing access
Track record of transformation leadership to establish new privileged access patterns, operating models, and Zero Trust–aligned controls across the enterprise
Expertise in automation and CI/CD enablement for PAM, including policy‑as‑code, secrets management, credential rotation, and integration across on‑prem and cloud environments
Ability to define and execute a cloud and platform readiness roadmap for privileged access, guiding teams through staged adoption or hybrid models while maintaining uptime, auditability, and compliance
Ability to work on-site in one of the listed locations in a hybrid environment. There is no option for fully remote work
This position is not available for visa sponsorship
Pay Range
Reflected is the base pay range offered for this position. Pay may vary depending on factors including but not limited to demonstrated examples of prior performance, skills, experience, or work location. Employees may also be eligible for incentive opportunities.
$119,000.00 - $187,000.00
LAYIQ is an independent job-discovery service. This listing does not imply a partnership with or endorsement by the employer. Review the original posting for current details and availability.
Employer posted: