Demo

Principal Engineer - Application Security: Secure Development

Wells Fargo
Wells Fargo Salary
Charlotte, NC Full Time
POSTED ON 5/26/2026
AVAILABLE BEFORE 6/24/2026
About This Role

Application Security enhances the ability of the development organization to consistently deliver highly functional applications that are secure and resilient against attack. We develop policies, processes, controls and tools to proactively embed security into Wells Fargo-developed applications.

Wells Fargo is seeking a Principal Engineer who will lead a team of Application Security Champions (ASCs) that support Wells Fargo's Technology development teams, which deliver centralized shared services to our lines of business. ASCs promote and enable the security awareness to protect the Bank's applications by conducting vulnerability and fix reviews and training developers in secure coding best practices.

In This Role, You Will

  • Act as an advisor to leadership to develop or influence applications, network, information security, database, operating systems, or web technologies for highly complex business and technical needs across multiple groups
  • Lead the strategy and resolution of highly complex and unique challenges requiring in-depth evaluation across multiple areas or the enterprise, delivering solutions that are long-term, large-scale and require vision, creativity, innovation, advanced analytical and inductive thinking
  • Translate advanced technology experience, an in-depth knowledge of the organizations tactical and strategic business objectives, the enterprise technological environment, the organization structure, and strategic technological opportunities and requirements into technical engineering solutions
  • Provide vision, direction and expertise to leadership on implementing innovative and significant business solutions
  • Maintain knowledge of industry best practices and new technologies and recommends innovations that enhance operations or provide a competitive advantage to the organization
  • Strategically engage with all levels of professionals and managers across the enterprise and serve as an expert advisor to leadership
  • Lead and mentor a federated network of Application Security Champions (ASCs), establishing standards, playbooks, and metrics to scale secure development practices consistently across non CIO engineering teams
  • Drive integration of application security controls into CI/CD pipelines and developer tooling, enabling automated detection and remediation of vulnerabilities across the software development lifecycle
  • Oversee threat modeling, vulnerability assessments, and secure design reviews for complex, high risk applications and shared services, ensuring alignment with enterprise security policies and standards
  • Champion secure adoption of emerging technologies, including AI/LLM-enabled applications, by defining guardrails, patterns, and risk mitigation strategies for safe enterprise use

Required Qualifications:

  • 7 years of Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
  • 7 years Application Security Engineering
  • Experience building AI/LLM Application Security scalable solutions for enterprise production environments

Required Qualifications for Europe, Middle East & Africa only:

  • Experience in Engineering, or equivalent demonstrated through one or a combination of the following: work experience, training, education

Desired Qualifications:

  • Demonstrated deep, hands-on expertise in:
    • Secure application architecture and design
    • Secure coding practices and code-level vulnerability analysis
    • Threat modeling and abuse case analysis
    • Authentication, authorization, session management, API security, and secrets management
    • Common application vulnerabilities and exploit patterns (e.g., OWASP Top 10, deserialization, injection, SSRF, access control issues, insecure design, dependency risk)
  • Strong hands-on experience securing applications built in one or more modern technology stacks such as Java, .NET, Python, JavaScript/TypeScript, Node.js, Go, or similar.
  • Experience integrating security into CI/CD pipelines, developer workflows, and engineering platforms.
  • Experience with one or more of the following: SAST, SCA, DAST, IaC scanning, container security, API security testing, code review, threat modeling, runtime protection, or software supply chain security controls.
  • Hands-on experience with AI security, including securing AI-enabled applications or advising engineering teams on the secure use of AI/LLM-based capabilities.
  • Ability to independently investigate complex technical problems, identify root causes, and drive practical remediation.
  • Strong written and verbal communication skills with the ability to influence both engineers and senior stakeholders.
  • Proven ability to operate both strategically and tactically-moving from enterprise patterns to code-level detail as needed.
  • Prior experience serving as an Application Security Champion, Security Champion, embedded security lead, or senior engineer responsible for driving security within product/application teams.
  • Experience designing security controls for cloud-native and distributed systems running in Azure, AWS, or GCP.
  • Experience with software supply chain security, including dependency risk management, build pipeline hardening, SBOM, artifact integrity, provenance, and package governance.
  • Experience with runtime application protection, threat detection, or exploit prevention technologies.
  • Familiarity with Zero Trust, secure platform engineering, and policy-as-code approaches.
  • Experience defining standards, playbooks, or secure reference architectures that can be adopted broadly by engineering organizations.
  • Background in software engineering or architecture prior to moving into security.
  • Certifications: CSSLP, GIAC GWEB, CISSP, GIAC GWAPT, CCSP, CCSP
Job Expectations:

  • Ability to travel up to 10% of the time.
  • Ability to work a hybrid schedule - 3 days per week on-site/in office and 2 days per week remote
  • This position is not eligible for Visa sponsorship

Posting End Date:

29 May 2026

  • Job posting may come down early due to volume of applicants.

We Value Equal Opportunity

Wells Fargo is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other legally protected characteristic.

Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit's risk appetite and all risk and compliance program requirements.

Candidates applying to job openings posted in Canada: Applications for employment are encouraged from all qualified candidates, including women, persons with disabilities, aboriginal peoples and visible minorities. Accommodation for applicants with disabilities is available upon request in connection with the recruitment process.

Applicants With Disabilities

To request a medical accommodation during the application or interview process, visit Disability Inclusion at Wells Fargo .

Drug and Alcohol Policy

Wells Fargo maintains a drug free workplace. Please see our Drug and Alcohol Policy to learn more.

Wells Fargo Recruitment And Hiring Requirements

  • Third-Party recordings are prohibited unless authorized by Wells Fargo.
  • Wells Fargo requires you to directly represent your own experiences during the recruiting and hiring process.

Reference Number

R-546631-1

Salary.com Estimation for Principal Engineer - Application Security: Secure Development in Charlotte, NC
$200,013 to $236,482
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Principal Engineer - Application Security: Secure Development?

Sign up to receive alerts about other jobs on the Principal Engineer - Application Security: Secure Development career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$205,834 - $254,869
Income Estimation: 
$150,467 - $192,499
Income Estimation: 
$149,289 - $190,988
Income Estimation: 
$97,457 - $126,589
Income Estimation: 
$176,972 - $219,172
Income Estimation: 
$131,745 - $167,716
Income Estimation: 
$150,756 - $194,140
Income Estimation: 
$172,191 - $221,861
Income Estimation: 
$114,549 - $164,025
Income Estimation: 
$153,752 - $200,235
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Wells Fargo

  • Wells Fargo Jackson, WY
  • Why Wells Fargo Are you looking for more? Find it here. At Wells Fargo, we're more than a financial services leader - we're a global trailblazer committed ... more
  • 1 Day Ago

  • Wells Fargo Casper, WY
  • Why Wells Fargo Are you looking for more? Find it here. At Wells Fargo, we're more than a financial services leader - we're a global trailblazer committed ... more
  • 1 Day Ago

  • Wells Fargo Evanston, WY
  • Why Wells Fargo Are you looking for more? Find it here. At Wells Fargo, we're more than a financial services leader - we're a global trailblazer committed ... more
  • 1 Day Ago

  • Wells Fargo Bozeman, MT
  • Why Wells Fargo Are you looking for more? Find it here. At Wells Fargo, we're more than a financial services leader - we're a global trailblazer committed ... more
  • 1 Day Ago


Not the job you're looking for? Here are some other Principal Engineer - Application Security: Secure Development jobs in the Charlotte, NC area that may be a better fit.

  • Innova Solutions, Inc Charlotte, NC
  • A client of Innova Solutions is immediately hiring for an Application Security Engineer. Position type: Contract (12 months) Location: Charlotte, NC Hybrid... more
  • 24 Days Ago

  • Truist Bank Charlotte, NC
  • Language Fluency: English (Required) Work Shift: 1st shift (United States of America) Job Grade: 113 Please review the following job description: ***This r... more
  • 14 Days Ago

AI Assistant is available now!

Feel free to start your new journey!