Skip to main content
Laptop

SOC Manager - Cyber Threat Fusion Centers

  • Technology
  • Full time
  • R-568035

About this role:

Wells Fargo is seeking an Information Security Engineering Manager in Technology as part of Cybersecurity. Learn more about the career areas and lines of business at wellsfargojobs.com

Wells Fargo is seeking an experienced Cybersecurity Professional to lead one of its Cyber Threat Fusion Teams that is responsible for monitoring and responding to cyber threats. The Information Security Engineering Manager will lead a Cyber Threat Fusion Center team responsible for the detection, triage, investigation, escalation, and response of cybersecurity threats impacting Wells Fargo. This leader will oversee a high-volume operational environment during peak periods of cyber activity, ensuring timely response to security incidents, adherence to operational standards, and achievement of service delivery objectives. The manager will provide leadership during security incidents, coordinate cross-functional response activities, drive continuous improvement initiatives, and develop a highly skilled team of cybersecurity professionals. The role requires strong technical expertise, operational leadership, incident management experience, and the ability to influence stakeholders across cybersecurity, technology, risk, and business organizations.

In this role, you will:

  • Manage a team of cybersecurity analysts and incident responders responsible for the monitoring, triage, investigation, escalation, and response of cybersecurity threats and security incidents.
  • Lead daily Security Operations Center (SOC) activities to ensure timely detection, containment, mitigation, and resolution of cybersecurity events impacting the organization.
  • Partner with cybersecurity, technology, risk, and business stakeholders to ensure alignment with information security policies, standards, and operational objectives.
  • Provide subject matter expertise on security operations, cyber threat detection, incident response, threat hunting, and emerging cyber threats and adversary tactics.
  • Oversee the review, analysis, and correlation of security alerts, threat intelligence, and security telemetry to identify malicious activity and emerging risks.
  • Direct and coordinate cybersecurity incident response activities for high-severity and complex security events, ensuring appropriate escalation, communication, and resolution.
  • Serve as an incident commander or senior response leader during major cybersecurity incidents, coordinating cross-functional response efforts and executive communications.
  • Lead post-incident reviews and lessons-learned activities to identify root causes, improve detection and response capabilities, and reduce future risk.
  • Ensure operational effectiveness of security monitoring, incident response, threat management, and escalation processes through continuous improvement initiatives and performance measurement.
  • Drive the development, maintenance, and optimization of security operations procedures, response playbooks, workflows, and operational documentation.
  • Collaborate with cybersecurity engineering and platform teams to enhance the effectiveness of SOC technologies, detection capabilities, and automation initiatives.
  • Monitor operational metrics and service-level objectives to ensure timely incident handling, response quality, workload management, and overall team performance.
  • Build strong partnerships with senior leaders, business partners, and cybersecurity stakeholders to communicate risks, operational trends, and incident response activities.
  • Manage allocation of personnel and operational resources to ensure appropriate staffing, readiness, and coverage during peak periods of cyber activity.
  • Mentor, develop, and coach cybersecurity professionals, fostering technical growth, leadership development, and a culture of operational excellence.
  • Lead recruiting, hiring, succession planning, and talent management activities to build and retain a high-performing cybersecurity operations team.
  • Promote a culture of accountability, collaboration, continuous learning, and operational resilience across the Cyber Threat Fusion Center.
  • Demonstrate proficiency in using AI‑assisted development and analysis tools (e.g., GitHub Copilot and approved code‑centric agents)
  • Leverage AI to accelerate system design, coding, testing, analysis, and troubleshooting
  • Apply strong technical judgment when validating and integrating AI‑assisted outputs into solutions
  • Understand and account for model limitations, security risks, and operational considerations
  • Apply AI responsibly in development and production environments
  • Ensure AI usage aligns with security, compliance, privacy, and ethical standards

Required Qualifications:

  • 5+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
  • 2+ years of Leadership experience
  • 5+ years of cybersecurity, security operations, incident response, threat hunting, digital forensics, or related information security experience.
  • 2+ years of leadership or management experience within a Security Operations Center (SOC), Cyber Defense Center, Fusion Center, or Incident Response organization.


Desired Qualifications:

  • Experience leading high-performing operational teams in a 24x7 or mission-critical environment.
  • Experience serving in an Incident Commander, Incident Handler, Action Officer, or Major Incident Management role during significant cybersecurity events.
  • Proven ability to coordinate cross-functional response efforts across cyber defense, infrastructure, application, risk, legal, and business stakeholders.
  • Experience developing and mentoring analysts, team leads, and incident responders.
  • Experience investigating and responding to malware, phishing, insider threat, credential compromise, ransomware, data loss, cloud security, and network intrusion incidents.
  • Strong understanding of cybersecurity detection and response methodologies, threat intelligence, threat hunting, and adversary tactics, techniques, and procedures (TTPs).
  • Experience conducting root cause analysis, incident containment, eradication, recovery, and post-incident reviews.
  • Knowledge of MITRE ATT&CK, Cyber Kill Chain, NIST Incident Response Framework, and security operations best practices.
  • Experience with one or more of the following technologies: Security Information and Event Management (SIEM), Security Orchestration, Automation and Response (SOAR), Endpoint Detection and Response (EDR), Network Detection and Response (NDR), Threat Intelligence Platform (TIP), Case Management Tools, and Cloud Security Platforms.


Job Expectations:

  • This position is considered shift work (4x10) - Monday through Thursday 7am ET to 5pm ET. Hybrid work model.

This position is considered shift work (4x10) - Monday through Thursday 7am ET to 5pm ET. Hybrid work model.

Posting End Date: 

23 Aug 2026

*Job posting may come down early due to volume of applicants.

We Value Equal Opportunity

Wells Fargo is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other legally protected characteristic.

Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit’s risk appetite and all risk and compliance program requirements.

Candidates applying to job openings posted in Canada: Applications for employment are encouraged from all qualified candidates, including women, persons with disabilities, aboriginal peoples and visible minorities. Accommodation for applicants with disabilities is available upon request in connection with the recruitment process.

Applicants with Disabilities

To request a medical accommodation during the application or interview process, visit Disability Inclusion at Wells Fargo.

Drug and Alcohol Policy

 

Wells Fargo maintains a drug free workplace.  Please see our Drug and Alcohol Policy to learn more.

Wells Fargo Recruitment and Hiring Requirements:

a. Third-Party recordings are prohibited unless authorized by Wells Fargo.

b. Wells Fargo requires you to directly represent your own experiences during the recruiting and hiring process.


Join our talent community

Learn about upcoming events and career opportunities at Wells Fargo

Talent Community
JK 1212 1236 B 4MP