[Skip To Content]
Laptop

Lead Information Security Engineer- Certificate Management Services

About this role:

Wells Fargo is seeking a Lead Information Security Engineer within Cybersecurity Critical Infrastructure Services.

The Lead Information Security Engineer will support the Digital Certificate Management Services team. This team is responsible for engineering, automation, and operation of enterprise Public Key Infrastructure (PKI), machine identity, and certificate lifecycle management services that protect critical business applications and infrastructure across the enterprise.

In this role, you will design, develop, automate, and support large-scale PKI and certificate management solutions. You will work with modern automation, API integration, source control, and software engineering practices to improve security, reliability, and operational efficiency while helping drive cryptographic modernization and emerging machine identity capabilities.


In this role, you will:

    • Lead the design, engineering, automation, and operation of enterprise PKI and certificate lifecycle management services.
    • Design, document, test, maintain, and improve highly scalable security solutions related to cryptography, authentication, machine identity, and certificate management.
    • Develop automation that streamlines certificate issuance, renewal, discovery, inventory, compliance monitoring, and lifecycle management.
    • Engineer integrations between certificate management platforms and enterprise applications using APIs and automation frameworks.
    • Design and support standards-based certificate enrollment and lifecycle solutions using technologies such as ACME, EST, and SCEP.
    • Contribute to cryptographic modernization initiatives including crypto-agility and post-quantum cryptography (PQC) readiness.
    • Evaluate and implement emerging machine identity and workload identity technologies such as SPIFFE/SPIRE and related industry standards.
    • Develop reusable automation, tooling, and self-service capabilities using source control and modern software engineering practices.
    • Identify security risks, vulnerabilities, and control gaps and recommend remediation strategies.
    • Collaborate with application teams, infrastructure teams, architects, and security partners to drive adoption of certificate management and machine identity services.
    • Provide technical leadership and mentorship across PKI and certificate management initiatives.
    • Collaborate and influence all levels of professionals including managers.

Required Qualifications:

  • 7+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
  • 1+ years of experience providing production support
  • 1+ years of experience using ticket tracking tools for change management, problem and incident management, and availability management


Desired Qualifications:

    • hands-on experience designing, implementing, or operating enterprise PKI and certificate lifecycle management solutions.
    • experience supporting certificate use cases including TLS, machine identities, code signing, S/MIME, SSH, and workload identities.
    • Strong understanding of PKI concepts including Certificate Authorities (CA), Registration Authorities (RA), certificate enrollment, revocation, OCSP, CRL, key management, and cryptographic trust models.
    • experience with one or more certificate management platforms such as Venafi, DigiCert, Microsoft ADCS, Keyfactor, or comparable solutions.
    • Experience with certificate enrollment and lifecycle protocols such as ACME, EST, and SCEP.
    • Experience developing automation using Python, PowerShell, Ansible, Terraform, or similar technologies.
    • Experience developing and consuming REST APIs to automate integrations and workflows.
    • Experience using Git-based development workflows including source control, pull requests, code reviews, testing, and CI/CD pipelines.
    • Experience with modern software engineering practices including automation, Infrastructure as Code (IaC), and platform integration.
    • Knowledge of cryptographic modernization initiatives, crypto-agility, and post-quantum cryptography (PQC).
    • Familiarity with machine identity frameworks such as SPIFFE/SPIRE and emerging certificate-based identity technologies.
    • Experience applying NIST and industry security standards related to PKI and cryptography.
    • Experience leveraging modern engineering tools and AI-assisted development practices to improve engineering productivity and solution quality.
    • Experience working with Agile methodologies including Kanban or Scrum and workflow management using Jira.
    • Self-starter with the ability to manage multiple engineering projects.
    • Strong communication and interpersonal skills.

Job Expectations:

  • This position offers a hybrid work schedule
  • This position is not eligible for Visa sponsorship

Pay Range
 

Reflected is the base pay range offered for this position. Pay may vary depending on factors including but not limited to demonstrated examples of prior performance, skills, experience, or work location. Employees may also be eligible for incentive opportunities.

$119,000.00 - $187,000.00

Benefits

Wells Fargo provides eligible employees with a comprehensive set of benefits, many of which are listed below. Visit Benefits - Wells Fargo Jobs for an overview of the following benefit plans and programs offered to employees.

  • Health benefits
  • 401(k) Plan
  • Paid time off
  • Disability benefits
  • Life insurance, critical illness insurance, and accident insurance
  • Parental leave
  • Critical caregiving leave
  • Discounts and savings
  • Commuter benefits
  • Tuition reimbursement
  • Scholarships for dependent children
  • Adoption reimbursement

Posting End Date:

17 Sep 2026

*Job posting may come down early due to volume of applicants.

We Value Equal Opportunity

Wells Fargo is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other legally protected characteristic.

Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit’s risk appetite and all risk and compliance program requirements.

Applicants with Disabilities

To request a medical accommodation during the application or interview process, visit Disability Inclusion at Wells Fargo.

Drug and Alcohol Policy

 

Wells Fargo maintains a drug free workplace.  Please see our Drug and Alcohol Policy to learn more.

Wells Fargo Recruitment and Hiring Requirements:

a. Third-Party recordings are prohibited unless authorized by Wells Fargo.

b. Wells Fargo requires you to directly represent your own experiences during the recruiting and hiring process.


Rejoignez notre communauté de talents

Renseignez-vous sur les événements à venir et les possibilités de carrière chez Wells Fargo.

Adhérer maintenant
JK 1212 1236 B 4MP