Lead Information Security Engineer
Wells Fargo is seeking a Lead SIEM Engineer for our Cyber Security Operations team to lead the design, implementation, and optimization of Splunk-based observability and security solutions across the enterprise. The ideal candidate will have deep expertise in Splunk architecture and administration, and will collaborate with cross-functional teams to ensure reliable, scalable, and secure log management. Experience with data pipeline engineering is a strong plus.
In this role, you will:
- Lead computer security incident response activities for highly complex events
- Conduct technical investigation of security related incidents and post incident digital forensics to identify causes and recommend future mitigation strategies
- Provide security consulting on large projects for internal clients to ensure conformity with corporate information, security policy, and standards
- Design, document, test, maintain, and provide issue resolution recommendations for highly complex security solutions
- Review and correlate security logs
- Utilize subject matter knowledge in industry leading security solutions and best practices to implement one or more components of information security
- Identify security vulnerabilities and issues, perform risk assessments, and evaluate remediation alternatives
- Collaborate and influence all levels of professionals including managers
- Lead a team to achieve objectives
- Act as a subject matter expert for Splunk architecture and engineering
- Translate business and compliance requirements into technical solutions using Splunk
- Maintain awareness of industry best practices and emerging technologies in observability and log management
- Drive continuous improvement and innovation across Splunk deployments
- Collaborate with leadership to align technical solutions with enterprise priorities
Key Duties:
- Lead the engineering and operational support of Splunk Cloud architecture, CRIBL Stream deployment, and data pipeline optimization
- Design and implement scalable log ingestion frameworks using CRIBL and Splunk forwarders
- Develop and maintain Splunk dashboards, alerts, and reports for security and operational use cases
- Collaborate with cybersecurity, infrastructure, and application teams to ensure log fidelity and performance
- Provide technical guidance and mentorship to junior Splunk engineers
- Evaluate and integrate complementary technologies such as CRIBL, SOAR, and cloud-native logging tools
- Contribute to the development of observability and telemetry strategies
- Support automation and orchestration efforts to streamline data onboarding and enrichment
Required Qualifications, US:
- 5+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
- 3+ years of hands-on experience with Splunk architecture, administration, and content development
- Strong understanding of log ingestion, parsing, and data normalization
- Experience with Splunk Cloud and/or hybrid deployments
- Familiarity with automation tools (e.g., Python, Ansible, Terraform)
Desired Qualifications:
- Experience with CRIBL Stream or similar data routing platforms
- Experience designing or managing data pipelines for enterprise environments
- Certifications in Splunk (e.g., Splunk Certified Power User, Admin, Architect)
- Experience integrating Splunk with cloud-native services (AWS, Azure, GCP)
- Familiarity with SIEM, SOAR, and threat detection use cases
- Ability to communicate technical concepts to non-technical stakeholders
Pay Range: $119,000.00 - $224,000.00
Benefits: Wells Fargo provides eligible employees with a comprehensive set of benefits including health benefits, 401(k) Plan, paid time off, disability benefits, life insurance, parental leave, critical caregiving leave, discounts and savings, commuter benefits, tuition reimbursement, scholarships for dependent children, and adoption reimbursement.