Senior Information Security Engineer
JOB TITLE: Senior Info Security Engineer – SCD AAD
About Wells Fargo India
Wells Fargo India enables global talent capabilities for Wells Fargo Bank NA., by supporting business lines and staff functions across Technology, Operations, Risk, Audit, Process Excellence, Automation and Product, Analytics and Modeling. We are operating in Hyderabad, Bengaluru and Chennai locations.
Wells Fargo views information & Cyber Security as enabling lines of business to mitigate information security risk in accordance with our risk appetite. Through a framework that addresses policy, process, operations, people, and technology, ICS protects our infrastructure, company data, and customer assets while ensuring alignment with applicable regulations and laws.
Our vision is to provide Wells Fargo with world-leading cyber security risk management.
About the Role:
Our Information and Cyber Security (ICS) team is looking for a senior Cyber Security professional to join our Security Content Development (SCD- AAD) team.
The SCD Advanced Adversarial Defense team is responsible for working with Cyber Threat Fusion Center (CTFC), Lines of Business (LOB), security council and analysts by building and maintaining advanced visibility into security events using advanced correlation tools like Splunk, EDR and various network intrusion detection/prevention systems and feeding downstream case management tools for events of interest that are to be analyzed for malicious activity
Duties include creating, improving, and delivering events of interest from both upstream security tools and big data solutions for the benefit of the Cyber Security teams. The ideal candidate will have extensive experience in SIEM, network-focused forensics and threat hunting utilizing both Deep Packet Inspection (i.e. full packet capture) and EDR solutions.
The ideal candidate will additionally have a well-rounded background in endpoint/network defenses and security incident response, as well as some offensive security knowledge to allow the ability to think like an adversary. Polished verbal and written communication skills are desired, in order to ensure thorough and accurate reporting during the work to visualize, investigate, contain, and conclude a security incident.
The candidate will play a major role in our cyber threat hunt automation efforts, including the vetting of new models and procedures to identify and react to anomalous network and/or endpoint behaviors. This position is designed to assure success in our next-generation ability to discover and react to advanced security threats.
- 8+ years of demonstrated information security applications and systems experience
- 5+ years of demonstrated experience leveraging security technologies such as SIEM, EDR, firewalls
- 5+ years of demonstrated experience in performing technical analysis and enrichment of pertinent attacks, threats and their indicators
- Good understanding on agile methodology
- 4+ years of demonstrated experience with at least one scripting language (preferably Python, YARA, REGEX) working on automation and engineering projects
- Sound Knowledge on developing use cases in SPLUNK, Google Chronicle and EDR based on MITRE ATT&CK framework
- Develop IOA based use cases on EDR (Crowd strike/Fire eye) to mitigate zero-day attacks
- Understanding of CIM and SPL development
- Should be familiar with Splunk SPL development
- Good understanding of firewall (Checkpoint/Palo Alto) logs to take necessary action and mitigate zero-day attacks
- Should possess understanding of third party/vendor/supply chain cyber footprint and associated risks (attacks, threats, vulnerabilities) over the internet
- Should possess understanding of security and threat landscape relevant to cloud technologies
- Demonstrated experience with creating and communication of reports and presentations regarding cyber-attacks, threats and vulnerabilities to various level of personnel within large organization and its vendors
- Ability to manage complex security scenarios and develop innovative solutions to address the most recent cyber threats
- Advanced knowledge of networks, protocols, standards, Linux/Unix/Window OS internals, and system configuration
- Experience with least one scripting language, such as: PowerShell, Python, Bash, PHP, YARA etc.
- Bachelor’s and/or Master’s degree in computer science or information systems
- 4+ years of experience with network security, endpoint security/EDR, firewalls or security threat vectors
- Experience with host-based and/or network-based forensics tools and techniques
- Knowledge and understanding of banking or financial services industry
- Knowledge and understanding of malware reverse engineering including: code or behavior analysis for endpoints and the network
- Knowledge and understanding of data security controls including malware protection, firewalls, intrusion detection systems, content filtering, Internet proxies, encryption controls, and log management solutions
- Experience analyzing large data sets
- Excellent verbal, written, and interpersonal communication skills
- Knowledge of offensive security, with the ability to think like an adversary when hunting and responding to incidents
- Strong ability to identify anomalous behavior on endpoint devices and/or network communications
- Advanced problem-solving skills, ability to develop effective long-term solutions to complex problems
- Familiar with field extractions, regex and having knowledge on SIEM infrastructure issues will be added advantage
- Certifications in one or more of the following: Certified Information Systems Security Professional (CISSP), GIAC Certified Incident Handler (GCIH), GIAC Reverse Engineering Malware (GREM), GIAC Certified Forensic Analyst (GCFA), GIAC Network Forensics Analyst (GNFA), Offensive Security (OSCP/OSCE/etc), or other relevant certifications.
We Value Diversity
At Wells Fargo, we believe in diversity, equity and inclusion in the workplace; accordingly, we welcome applications for employment from all qualified candidates, regardless of race, color, gender, national origin, religion, age, sexual orientation, gender identity, gender expression, genetic information, individuals with disabilities, pregnancy, marital status, status as a protected veteran or any other status protected by applicable law.
Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit’s risk appetite and all risk and compliance program requirements.
Candidates applying to job openings posted in US: All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Candidates applying to job openings posted in Canada: Applications for employment are encouraged from all qualified candidates, including women, persons with disabilities, aboriginal peoples and visible minorities. Accommodation for applicants with disabilities is available upon request in connection with the recruitment process.
Drug and Alcohol Policy
Wells Fargo maintains a drug free workplace. Please see our Drug and Alcohol Policy to learn more.