Lead Information Security Analyst - Contract Management at Wells Fargo
Chandler, Arizona, USA -
Full Time


Start Date

Immediate

Expiry Date

14 Nov, 25

Salary

206000.0

Posted On

14 Aug, 25

Experience

5 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Vendor Management, Risk, Training, Contract Management, Cissp

Industry

Financial Services

Description

PAY RANGE

Reflected is the base pay range offered for this position. Pay may vary depending on factors including but not limited to achievements, skills, experience, or work location. The range listed is just one component of the compensation package offered to candidates.
$119,000.00 - $206,000.00

APPLICANTS WITH DISABILITIES

To request a medical accommodation during the application or interview process, visit Disability Inclusion at Wells Fargo .

WELLS FARGO RECRUITMENT AND HIRING REQUIREMENTS:

a. Third-Party recordings are prohibited unless authorized by Wells Fargo.
b. Wells Fargo requires you to directly represent your own experiences during the recruiting and hiring process

Required Qualifications:

  • 5+ years of Information Security Analysis experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, educatio

Desired Qualifications:

  • Third-Party experience in either contract management or vendor management
  • Ability to influence stakeholders across the enterprise.
  • Ability to translate and explain information security concepts and risk in a simple manner in both written and verbal methods
  • Information Security Certifications such as CISSP, CISM, CRISC
Responsibilities

Wells Fargo is seeking a Lead Information Security Analyst to
support the Cybersecurity Contract Management process, which involves active participation in contract negotiations with third-party vendors providing services and products to Wells Fargo. As part of these negotiations, the analyst is responsible for assessing and mitigating technology risks associated with proposed changes to Information Security requirements in Master Services Agreements (MSAs). This ensures the protection of Wells Fargo’s information systems, effective cyber risk management, and compliance with internal policies and external regulatory frameworks.
The position works closely with Technology and Cybersecurity Domain Owners to define and integrate Information Security and Technology requirements into MSAs for all third-party service and product providers. Additionally, the analyst serves as a cybersecurity advisor to Lines of Business and Sourcing teams during the negotiation of cybersecurity-related contractual terms and Information Risk Questionnaire (IRQ) consultations.

In this role, you will:

  • Act as cybersecurity partner to Line of Business and Sourcing when negotiating cybersecurity contractual term with Third Parties, to promote security best practices.
  • Partner with Technology and Cybersecurity Domain Owners to access potential risk, impact, and resolution of alternation request to technology sections submitted by Third Parties during contract negotiations.
  • Identify opportunities for Cybersecurity Contract Management process improvement and risk control development by overseeing strategy and execution of all activities.
  • Annually collaborate with Technology and Cybersecurity Domain Owners, Sourcing and Legal to review and establish cybersecurity requirements for Third Parties, that align with Wells Fargo requirements, regulatory guidance, and industry standards.
  • Support development of presentations to senior leadership and executives, to facilitate conversation on strategic business priorities, decision, and approach.
  • Support ad-hoc specialty projects, including assessment, planning and execution.

Required Qualifications:

  • 5+ years of Information Security Analysis experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education

Desired Qualifications:

  • Third-Party experience in either contract management or vendor management
  • Ability to influence stakeholders across the enterprise.
  • Ability to translate and explain information security concepts and risk in a simple manner in both written and verbal methods
  • Information Security Certifications such as CISSP, CISM, CRISC.

Job Expectations:

  • Ability to work on-site in a hybrid model in one of the locations listed on the job posting.
Loading...