Skip to main content
Laptop

Senior Information Security Engineer - Directory Services

About this role:

Wells Fargo is seeking a Senior Information Security Engineer to be a key member of the Directory Services Engineering team. This individual will be responsible for securing and modernizing the enterprise identity infrastructure that supports workforce, application, service, and machine authentication across the organization. The ideal candidate will serve as both a security architect and hands-on engineer, partnering across Cyber Security, Infrastructure, Cloud, Application Development, and Operations teams to design, implement, and maintain secure identity services that support regulatory, audit, and operational requirements.


In this role, you will:

  • Design, implement, and maintain secure Active Directory environments, including: Domain Services, Group Policy, Organizational Unit (OU) Design, Delegation Models, Trust Relationships, and Authentication Services.
  • Develop and maintain security standards, hardening baselines, and control frameworks for Active Directory and cloud identity platforms.
  • Lead initiatives focused on reducing identity-related attack surface and improving directory hygiene.Assess and remediate identity security risks, misconfigurations, and excessive privileges.
  • Engineer and support Microsoft Entra ID security controls, including: Conditional Access, Multi-Factor Authentication (MFA), Passwordless Authentication, FIDO2 and Passkeys, Temporary Access Pass (TAP), Identity Protection, Privileged Identity Management (PIM), and Workload Identity Security.
  • Design and implement authentication and authorization controls for cloud applications and enterprise integrations.
  • Develop monitoring and reporting capabilities for Entra sign-in activity, authentication events, and security posture metrics.
  • Support cloud identity modernization and Zero Trust initiatives.
  • Design, support, and secure enterprise virtual directory services utilizing Radiant Logic Virtual Directory.
  • Integrate multiple identity repositories including: Active Directory, LDAP, Cloud Identity Providers, HR Systems, and Application Repositories.
  • Develop identity aggregation, attribute transformation, and identity correlation strategies.
  • Ensure security, resiliency, and scalability of virtual directory services supporting enterprise applications and regulatory requirements.
  • Engineer and maintain Linux authentication and authorization integrations.
  • Implement and support: LDAP, Kerberos, SSSD, PAM, SSH Security Controls, and Certificate-Based Authentication
  • Secure privileged access across Linux environments through integration with PAM solutions and enterprise credential management platforms.
  • Develop and maintain hardening standards for Linux operating systems and directory service integrations.
  • Support enterprise IAM initiatives including: Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), Privileged Access Management (PAM), Service Account Governance, and Non-Person Entity Security.
  • Evaluate emerging authentication technologies and industry best practices.
  • Support identity lifecycle management and governance processes.
  • Investigate directory service security incidents and suspicious authentication activity.
  • Develop detection content leveraging: Microsoft Sentinel, Splunk, KQL, and Security Information and Event Management (SIEM) platforms.
  • Partner with Cyber Defense and Incident Response teams to mitigate identity-based threats.
  • Support threat modeling and security assessments of identity platforms.
  • Partner with internal audit, risk, and regulatory organizations to demonstrate identity control effectiveness.
  • Produce technical documentation, architecture diagrams, control evidence, and security standards.
  • Support regulatory examinations and security reviews involving identity and authentication controls.
  • Drive remediation activities for audit findings and risk observations.


Required Qualifications:

  • 4+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
  • 4+ years of experience in Active Directory, Microsoft Entra ID, Radiant Virtual Directory, or Linux security platforms
  • 4+ years of experience in identity governance, authentication technologies, privileged access management, and enterprise security controls.


Desired Qualifications:

  • 7+ years of Information Security, Identity Security, or Infrastructure Security experience
  • Experience with Radiant RBDS platform
  • Experience administering and securing Microsoft Entra ID environments
  • Experience with LDAP and directory service architectures
  • Experience securing Linux platforms and authentication services
  • Strong understanding of: Kerberos, LDAP, SAML, OAuth, and MFA
  • Experience with PowerShell automation and scripting
  • Experience supporting enterprise-scale identity environments
  • Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent experience

Job Expectations:

  • This role is not eligible for visa sponsorship now or in the future
  • Ability to work on-site in one of the listed locations in a hybrid model. There is no option for 100% remote work.

Posting End Date: 

2 Oct 2026

*Job posting may come down early due to volume of applicants.

We Value Equal Opportunity

Wells Fargo is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other legally protected characteristic.

Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit’s risk appetite and all risk and compliance program requirements.

Candidates applying to job openings posted in Canada: Applications for employment are encouraged from all qualified candidates, including women, persons with disabilities, aboriginal peoples and visible minorities. Accommodation for applicants with disabilities is available upon request in connection with the recruitment process.

Applicants with Disabilities

To request a medical accommodation during the application or interview process, visit Disability Inclusion at Wells Fargo.

Drug and Alcohol Policy

 

Wells Fargo maintains a drug free workplace.  Please see our Drug and Alcohol Policy to learn more.

Wells Fargo Recruitment and Hiring Requirements:

a. Third-Party recordings are prohibited unless authorized by Wells Fargo.

b. Wells Fargo requires you to directly represent your own experiences during the recruiting and hiring process.


Join our talent community

Learn about upcoming events and career opportunities at Wells Fargo

Talent Community
JK 1212 1236 B 4MP