Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Wells Fargo

Senior Lead Technology Risk Officer – Application Domain, SDLC, DevOps, AI

Wells Fargo

. Provide expert second-line oversight of modern engineering practices, including application architecture patterns, secure SDLC, CI/CD, DevSecOps, platform engineering, infrastructure as code, containerized workloads, and production release controls .

Posted 9/17/2026full-timeCharlotte • North Carolina • United StatesSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive expertise in Technology Risk, with a strong focus on modern SDLC, DevSecOps, and application security. Capable of leading complex technical risk assessments and translating technical risks into actionable business insights.

Highest-signal resume keywords
Technology Risk ExperienceDevSecOps ExpertiseApplication Security TestingGitHub or GitLab ProficiencyCloud Platforms Knowledge

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Modern SDLCCI/CDAutomated TestingDeployment AutomationInfrastructure as CodeSecrets ManagementRisk AssessmentControl Effectiveness EvaluationTechnical Standards EvaluationSoftware Supply Chain Security
Soft Skills
Exceptional JudgmentExecutive CommunicationInfluencing Skills
Tools & Technologies
JenkinsAzure DevOpsTerraformKubernetesObservability Tools
Certifications & Qualifications
NISTSSDFCOBITFFIEC GuidanceISO 27001
Industry Keywords
Financial ServicesRegulated IndustryTechnical RiskApplication ArchitectureAI Engineering Risks

Tech Stack

Tools & technologies
AzureCloudJenkinsKubernetesSDLCTerraform

About the role

Key responsibilities & impact
  • Provide expert second-line oversight of modern engineering practices, including application architecture patterns, secure SDLC, CI/CD, DevSecOps, platform engineering, infrastructure as code, containerized workloads, and production release controls
  • Own second-line technology risk coverage and provide thought leadership across the application risk domain
  • Partner with first-line engineering, controls, and technology teams to drive consistent oversight of application architecture, development practices, deployment pipelines, and engineering controls
  • Assess source control workflows, branching strategies, build systems, test automation, artifact repositories, package dependencies, deployment orchestration, and runtime platform configurations
  • Evaluate software delivery pipelines end to end, including code provenance, pipeline trust boundaries, secrets handling, approval models, environment segregation, artifact immutability, and rollback or recovery capabilities
  • Lead deep-dive technical risk reviews of complex delivery environments and modernization programs
  • Convert architecture, pipeline, and operational observations into risk statements, root causes, and targeted remediation expectations
  • Analyze developer ecosystems and engineering tool chains, including repositories, CI runners, build agents, package managers, IaC frameworks, containers, Kubernetes, cloud services, and observability stacks
  • Evaluate AI-enabled engineering capabilities, including code assistants, prompt-based development workflows, automated test generation, agentic tooling, and model-integrated developer platforms
  • Review application and platform control patterns, including policy-as-code, secrets management, service identity, environment hardening, logging, monitoring, drift detection, and release gating
  • Develop risk indicators and challenge metrics for SDLC, DevSecOps, and AI-enabled engineering
  • Serve as a trusted technical risk partner to engineering, security, architecture, and control teams
  • Translate technical risks into business impact, actionable remediation, and decision-ready reporting for senior management, risk committees, and regulatory stakeholders

Requirements

What you’ll need
  • 7+ years of Technology Risk experience, or equivalent demonstrated through work experience, training, military experience, or education
  • 7+ years of progressive experience in software engineering, DevSecOps, platform or cloud engineering, application security, technology controls, or technology risk preferred
  • Front-line experience leading or operating technology capabilities strongly preferred
  • Technical depth across modern SDLC and DevSecOps, including source control, CI/CD, automated testing, deployment automation, production change controls, and software supply chain security
  • Ability to lead complex technical risk assessments, evaluate control effectiveness, identify systemic risk, and provide credible challenge across SDLC, DevSecOps, cloud, software supply chain, and AI-enabled engineering environments
  • Ability to evaluate application architectures, deployment models, engineering evidence, technical standards, and control implementations
  • Strong command of GitHub or GitLab, Jenkins or Azure DevOps, Terraform, containers, Kubernetes, cloud platforms, application security testing, and observability tools
  • Experience implementing or assessing engineering controls across secure build and release processes, code provenance, secrets management, privileged automation, infrastructure as code, environment segregation, and runtime security
  • Understanding of AI engineering risks and controls, including AI coding assistants, automated code generation, agentic workflows, data exposure, traceability, and human oversight
  • Exceptional judgment, executive communication, and influencing skills
  • Knowledge of NIST, SSDF, COBIT, FFIEC guidance, or ISO 27001 preferred
  • Financial services or regulated-industry experience and relevant security, risk, cloud, or software lifecycle certifications preferred
  • Position does not offer sponsorship

Benefits

Comp & perks
  • Equal opportunity employment
  • Medical accommodation available upon request during the recruitment or interview process
  • Drug-free workplace