Enter a job title or keyword

Senior Information Security Engineer Directory Services

Wells Fargo Bank


Job Location:

Charlotte, VT - USA

Monthly Salary: Not provided by the employer
Posted: 29 September 2026 (23 hours ago)
Application Deadline: 27 December 2026
Vacancies: 1 Vacancy

Job Summary

About this role:

Wells Fargo is seeking a Senior Information Security Engineer to be a key member of the Directory Services Engineering team. This individual will be responsible for securing and modernizing the enterprise identity infrastructure that supports workforce application service and machine authentication across the organization. The ideal candidate will serve as both a security architect and hands-on engineer partnering across Cyber Security Infrastructure Cloud Application Development and Operations teams to design implement and maintain secure identity services that support regulatory audit and operational requirements.


In this role you will:

  • Design implement and maintain secure Active Directory environments including: Domain Services Group Policy Organizational Unit (OU) Design Delegation Models Trust Relationships and Authentication Services.
  • Develop and maintain security standards hardening baselines and control frameworks for Active Directory and cloud identity platforms.
  • Lead initiatives focused on reducing identity-related attack surface and improving directory and remediate identity security risks misconfigurations and excessive privileges.
  • Engineer and support Microsoft Entra ID security controls including: Conditional Access Multi-Factor Authentication (MFA) Passwordless Authentication FIDO2 and Passkeys Temporary Access Pass (TAP) Identity Protection Privileged Identity Management (PIM) and Workload Identity Security.
  • Design and implement authentication and authorization controls for cloud applications and enterprise integrations.
  • Develop monitoring and reporting capabilities for Entra sign-in activity authentication events and security posture metrics.
  • Support cloud identity modernization and Zero Trust initiatives.
  • Design support and secure enterprise virtual directory services utilizing Radiant Logic Virtual Directory.
  • Integrate multiple identity repositories including: Active Directory LDAP Cloud Identity Providers HR Systems and Application Repositories.
  • Develop identity aggregation attribute transformation and identity correlation strategies.
  • Ensure security resiliency and scalability of virtual directory services supporting enterprise applications and regulatory requirements.
  • Engineer and maintain Linux authentication and authorization integrations.
  • Implement and support: LDAP Kerberos SSSD PAM SSH Security Controls and Certificate-Based Authentication
  • Secure privileged access across Linux environments through integration with PAM solutions and enterprise credential management platforms.
  • Develop and maintain hardening standards for Linux operating systems and directory service integrations.
  • Support enterprise IAM initiatives including: Role-Based Access Control (RBAC) Attribute-Based Access Control (ABAC) Privileged Access Management (PAM) Service Account Governance and Non-Person Entity Security.
  • Evaluate emerging authentication technologies and industry best practices.
  • Support identity lifecycle management and governance processes.
  • Investigate directory service security incidents and suspicious authentication activity.
  • Develop detection content leveraging: Microsoft Sentinel Splunk KQL and Security Information and Event Management (SIEM) platforms.
  • Partner with Cyber Defense and Incident Response teams to mitigate identity-based threats.
  • Support threat modeling and security assessments of identity platforms.
  • Partner with internal audit risk and regulatory organizations to demonstrate identity control effectiveness.
  • Produce technical documentation architecture diagrams control evidence and security standards.
  • Support regulatory examinations and security reviews involving identity and authentication controls.
  • Drive remediation activities for audit findings and risk observations.


Required Qualifications:

  • 4 years of Information Security Engineering experience or equivalent demonstrated through one or a combination of the following: work experience training military experience education
  • 4 years of experience in Active Directory Microsoft Entra ID Radiant Virtual Directory or Linux security platforms
  • 4 years of experience in identity governance authentication technologies privileged access management and enterprise security controls.


Desired Qualifications:

  • 7 years of Information Security Identity Security or Infrastructure Security experience
  • Experience with Radiant RBDS platform
  • Experience administering and securing Microsoft Entra ID environments
  • Experience with LDAP and directory service architectures
  • Experience securing Linux platforms and authentication services
  • Strong understanding of: Kerberos LDAP SAML OAuth and MFA
  • Experience with PowerShell automation and scripting
  • Experience supporting enterprise-scale identity environments
  • Bachelors Degree in Cybersecurity Information Technology Computer Science or related field or equivalent experience

Job Expectations:

  • This role is not eligible for visa sponsorshipnow or in the future
  • Ability to work on-site in one of the listed locations in a hybrid model. There is no option for 100% remote work.

Posting End Date:

2 Oct 2026

*Job posting may come down early due to volume of applicants.

We Value Equal Opportunity

Wells Fargo is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race color religion sex sexual orientation gender identity national origin disability status as a protected veteran or any other legally protected characteristic.

Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit Market Financial Crimes Operational Regulatory Compliance) which includes effectively following and adhering to applicable Wells Fargo policies and procedures appropriately fulfilling risk and compliance obligations timely and effective escalation and remediation of issues and making sound risk decisions. There is emphasis on proactive monitoring governance risk identification and escalation as well as making sound risk decisions commensurate with the business units risk appetite and all risk and compliance program requirements.

Candidates applying to job openings posted in Canada: Applications for employment are encouraged from all qualified candidates including women persons with disabilities aboriginal peoples and visible minorities. Accommodation for applicants with disabilities is available upon request in connection with the recruitment process.

Applicants with Disabilities

To request a medical accommodation during the application or interview process visitDisability Inclusion at Wells Fargo.

Drug and Alcohol Policy

Wells Fargo maintains a drug free workplace. Please see our Drug and Alcohol Policy to learn more.

Wells Fargo Recruitment and Hiring Requirements:

a. Third-Party recordings are prohibited unless authorized by Wells Fargo.

b. Wells Fargo requires you to directly represent your own experiences during the recruiting and hiring process.


Required Experience:

Director


About Company

Company Logo

Whether you’re just beginning your career or taking it to the next level, we have an opportunity for you.

View Profile View Profile