Senior Information Security Analyst-Cybersecurity Attestations
About this role:
Wells Fargo is seeking a Senior Information Security Analyst for Cybersecurity Attestations to supports the governance, coordination, and execution of cybersecurity attestation programs aligned to the CISO organization
In this role, you will:
Provide information security consultation to improve awareness and compliance with Enterprise Information Security policy, processes and standards
Perform remediation of security assessment review issues, complex ad hoc data, and reporting to support information security risk management
Provide guidance and direction in reviewing assessment findings and mitigating controls to optimize information security
Identify and direct information asset portfolio reconciliations and certifications
Provide advanced data aggregation and data of information security risk exposure
Develop and deliver Information Security Education Awareness and Training in accordance with the Enterprise Information Security Program standards
Review draft and proposed control standards for business impact and recommend modifications or clarifications as required
Conduct security control testing and consultation with stakeholders
Evaluate and interpret internal and Enterprise Information Security policies, processes and standards, and provide recommendations to improve them
Collaborate and consult with peers, colleagues, and managers to resolve issues and achieve goals
Interact with internal customers
Serve as a mentor to less experienced staff
Required Qualifications:
4+ years of Information Security Analysis experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
Desired Qualifications:
Bachelor’s or master’s degree in relevant Technology /Security discipline
One or more professional certifications such as CISA, CISM, CCSK, CRISC or other industry security certifications
Working knowledge of cybersecurity control frameworks and regulatory environments
Experience supporting assessments, audits, or attestations
Strong analytical skills with ability to interpret regulatory or technical requirements
Experience with tools such as Jira, SharePoint, Confluence, and Microsoft Office suite
Familiarity with financial services regulatory frameworks (e.g., SWIFT CSP, FedLine SRAP, NYDFS, OCC, DTCC, CHIPS)
Knowledge of cybersecurity frameworks (e.g., NIST, ISO 27001, CRI)
Experience with evidence management, control testing, or audit support
Experience working with executive reporting or regulatory deliverables
Strong attention to detail and documentation rigor (audit-ready mindset)
Ability to manage multiple attestation cycles and deadlines simultaneously
Effective communication with both technical and non-technical stakeholders
Critical thinking and problem-solving skills
Job Expectations:
Execute cybersecurity attestation activities in accordance with defined control procedures and regulatory timelines
Support attestation programs including: 1) SWIFT Customer Security Programme (CSP) 2) FedLine Solutions (SRAP), 3) CHIPS Security Attestation, 4) OCC and DTCC requirements, 5) NYDFS Cybersecurity Regulation attestation
Assess organizational adherence to external cybersecurity regulatory and industry attestation requirements
Monitor and document material changes to attestation requirements and scope
Assist in scoping new attestations aligned to cybersecurity governance (when assigned)
Support process improvements, standardization, and automation of attestation workflows
Contribute to maintaining documentation, procedures, and templates
Maintain attestation tracking artifacts (e.g., Jira, SharePoint, evidence repositories)
Support governance routines, status reporting, and stakeholder communications
Contribute to preparation of executive-level materials and attestation packages
Support CISO or executive sign-off processes for attestations
Partner with Technology, Cybersecurity, Risk, Compliance, and Business teams to obtain required evidence and validate controls
Coordinate with SMEs to clarify requirements and validate responses
Support cross-functional alignment for externally governed attestation requirements
Posting End Date:
15 Jun 2026*Job posting may come down early due to volume of applicants.
We Value Equal Opportunity
Wells Fargo is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other legally protected characteristic.
Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit’s risk appetite and all risk and compliance program requirements.
Candidates applying to job openings posted in Canada: Applications for employment are encouraged from all qualified candidates, including women, persons with disabilities, aboriginal peoples and visible minorities. Accommodation for applicants with disabilities is available upon request in connection with the recruitment process.
Applicants with Disabilities
To request a medical accommodation during the application or interview process, visit Disability Inclusion at Wells Fargo.
Drug and Alcohol Policy
Wells Fargo maintains a drug free workplace. Please see our Drug and Alcohol Policy to learn more.
Wells Fargo Recruitment and Hiring Requirements:
a. Third-Party recordings are prohibited unless authorized by Wells Fargo.
b. Wells Fargo requires you to directly represent your own experiences during the recruiting and hiring process.