Lead Infrastructure Engineer

Wells Fargo

Bengaluru, INonsitePosted Jul 31, 2026
Posting intelligenceActively listed

Skills

kubernetesterraformgithubpythonazurecicdgooglecloudaws

About the role

About this role:

Wells Fargo is seeking a Lead Infrastructure Engineer

In this role, you will:

Lead computer security incident response activities for highly complex events

Conduct technical investigation of security related incidents and post incident digital forensics to identify causes and recommend future mitigation strategies

Provide security consulting on large projects for internal clients to ensure conformity with corporate information, security policy, and standards

Design, document, test, maintain, and provide issue resolution recommendations for highly complex security solutions related to networking, cryptography, cloud, authentication and directory services, email, internet, applications, and endpoint security

Review and correlate security logs

Utilize subject matter knowledge in industry leading security solutions and best practices to implement one or more components of information security such as availability, integrity, confidentiality, risk management, threat identification, modeling, monitoring, incident response, access management, and business continuity

Identify security vulnerabilities and issues, perform risk assessments, and evaluate remediation alternatives

Collaborate and influence all levels of professionals including managers

Lead a team to achieve objectives

Required Qualifications:

5+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education

Desired Qualifications:

5+ years of overall technology engineering experience, including 5+ years of hands-on experience in Cloud Security Engineering, Cloud Governance, Cloud Platform Security, or related disciplines

Professional cloud certifications in AWS or GCP or Azure

Good Understanding of Python Programming

Experience working in large-scale regulated environments, preferably within Financial Services or highly regulated industries.

Strong understanding of Cloud Native Application Protection Platforms (CNAPP), CSPM, CWPP, and Cloud Infrastructure Entitlement Management (CIEM) solutions.

Experience with Kubernetes, OpenShift, and container security best practices.

Experience designing enterprise-scale cloud governance and security programs.

Strong analytical and problem-solving capabilities with a focus on automation, scalability, and operational excellence.

Demonstrated ability to influence technical direction, lead strategic initiatives, and drive adoption of cloud security standards across multiple engineering organizations.

Strong ownership mindset, collaboration skills, and ability to deliver results in a fast-paced enterprise environment.

Job Expectations:

Strong hands-on experience with AWS security services and governance capabilities, including IAM, Organizations, SCPs, Security Hub, GuardDuty, CloudTrail, Config, KMS, and related cloud-native security services.

Hands-on experience with at least two public cloud platforms among AWS, Azure, and GCP.

Advanced expertise in Infrastructure-as-Code (IaC) and Policy-as-Code (PaC) technologies, including: Terraform, HashiCorp Sentinel, Azure Policy, GCP Organization Policies, Open Policy Agent (OPA) / Rego

Strong understanding of policy lifecycle management, cloud governance, posture management, drift management, exception management, and policy enforcement strategies.

Proven experience implementing cloud control frameworks and translating regulatory, compliance, and security requirements into enforceable technical controls.

Deep understanding of Defense-in-Depth architecture and implementation of preventive, detective, corrective, and reporting controls.

Strong knowledge of Cloud Security Posture Management (CSPM), cloud security governance, compliance monitoring, vulnerability management, and security reporting.

Hands-on experience designing and implementing automated remediation solutions using cloud-native services, Infrastructure-as-Code, scripting, and CI/CD pipelines.

Strong understanding of cloud networking and security controls, including network segmentation, perimeter security, private connectivity, Zero Trust principles, and workload isolation.

Deep expertise in GCP security capabilities, including: Security Command Center (SCC),VPC Service Controls (VPC-SC),GCP Organization Policies, Access Levels, Ingress and Egress Controls, Service Perimeters, Data Exfiltration Protection

Proven experience troubleshooting VPC-SC access issues through analysis of Cloud Audit Logs, policy violations, service perimeter configurations, and governance controls.

Strong understanding of cloud-native data protection controls, including: Encryption at Rest and In Transit, Key Management Systems (KMS),Hardware Security Modules (HSM),Secrets Management, Certificate Management, Cryptographic Key Lifecycle Governance

Experience implementing and maintaining identity and access management controls, privileged access models, authentication, authorization, and federation patterns.

Good knowledge of DevOps and SDLC practices, including: GitHub, GitOps, Branching Strategies, Release Management, CI/CD Pipelines, Infrastructure Delivery Automation

Experience integrating security controls into developer workflows and enterprise cloud operating models.

Excellent verbal, written, and interpersonal communication skills with the ability to communicate technical concepts to both technical and business audiences.

Posting End Date:

6 Aug 2026

Job posting may come down early due to volume of applicants.

We Value Equal Opportunity

Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit’s risk appetite and all risk and compliance program requirements.

Candidates applying to job openings posted in Canada: Applications for employment are encouraged from all qualified candidates, including women, persons with disabilities, aboriginal peoples and visible minorities. Accommodation for applicants with disabilities is available upon request in connection with the recruitment process.

Applicants with Disabilities

To request a medical accommodation during the application or interview process, visit Disability Inclusion at Wells Fargo.

Drug and Alcohol Policy

Wells Fargo maintains a drug free workplace. Please see our Drug and Alcohol Policy to learn more.

Wells Fargo Recruitment and Hiring Requirements:

a. Third-Party recordings are prohibited unless authorized by Wells Fargo.

b. Wells Fargo requires you to directly represent your own experiences during the recruiting and hiring process.

Questions about this role

Click "Apply with AI Applyd" above and you are done. Your resume is rewritten for this advert, the screening questions are answered, and it is submitted on Wells Fargo's own hiring system. No retyping your history, no fourteen tabs, no evening lost.

Compensation for Platform Engineer roles in India varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Platform Engineer hub for India medians across recent openings.

You never touch the form - the application is filled and submitted for you on Wells Fargo's own hiring system. It is not marked sent when we press submit. It is marked sent when a confirmation from their system arrives at the address we apply with, and your dashboard shows which stage each application is at until then.

Twelve applicant tracking systems have a real apply path: Workday, Greenhouse, Lever, Ashby, Workable, iCIMS, Personio, Recruitee, Teamtailor, Rippling, Breezy and SmartRecruiters. Your application goes in on the employer's own hiring system, never into an aggregator queue.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.