FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior Lead Technology Risk Officer – Application Domain, SDLC, DevOps, AI
Wells Fargo. Provide expert second-line oversight of modern engineering practices, including application architecture patterns, secure SDLC, CI/CD, DevSecOps, platform engineering, infrastructure as code, containerized workloads, and production release controls .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive expertise in Technology Risk, with a strong focus on modern SDLC, DevSecOps, and application security. Capable of leading complex technical risk assessments and translating technical risks into actionable business insights.
Highest-signal resume keywords
Technology Risk ExperienceDevSecOps ExpertiseApplication Security TestingGitHub or GitLab ProficiencyCloud Platforms Knowledge
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Modern SDLCCI/CDAutomated TestingDeployment AutomationInfrastructure as CodeSecrets ManagementRisk AssessmentControl Effectiveness EvaluationTechnical Standards EvaluationSoftware Supply Chain Security
Soft Skills
Exceptional JudgmentExecutive CommunicationInfluencing Skills
Tools & Technologies
JenkinsAzure DevOpsTerraformKubernetesObservability Tools
Certifications & Qualifications
NISTSSDFCOBITFFIEC GuidanceISO 27001
Industry Keywords
Financial ServicesRegulated IndustryTechnical RiskApplication ArchitectureAI Engineering Risks
Tech Stack
Tools & technologiesAzureCloudJenkinsKubernetesSDLCTerraform
About the role
Key responsibilities & impact- Provide expert second-line oversight of modern engineering practices, including application architecture patterns, secure SDLC, CI/CD, DevSecOps, platform engineering, infrastructure as code, containerized workloads, and production release controls
- Own second-line technology risk coverage and provide thought leadership across the application risk domain
- Partner with first-line engineering, controls, and technology teams to drive consistent oversight of application architecture, development practices, deployment pipelines, and engineering controls
- Assess source control workflows, branching strategies, build systems, test automation, artifact repositories, package dependencies, deployment orchestration, and runtime platform configurations
- Evaluate software delivery pipelines end to end, including code provenance, pipeline trust boundaries, secrets handling, approval models, environment segregation, artifact immutability, and rollback or recovery capabilities
- Lead deep-dive technical risk reviews of complex delivery environments and modernization programs
- Convert architecture, pipeline, and operational observations into risk statements, root causes, and targeted remediation expectations
- Analyze developer ecosystems and engineering tool chains, including repositories, CI runners, build agents, package managers, IaC frameworks, containers, Kubernetes, cloud services, and observability stacks
- Evaluate AI-enabled engineering capabilities, including code assistants, prompt-based development workflows, automated test generation, agentic tooling, and model-integrated developer platforms
- Review application and platform control patterns, including policy-as-code, secrets management, service identity, environment hardening, logging, monitoring, drift detection, and release gating
- Develop risk indicators and challenge metrics for SDLC, DevSecOps, and AI-enabled engineering
- Serve as a trusted technical risk partner to engineering, security, architecture, and control teams
- Translate technical risks into business impact, actionable remediation, and decision-ready reporting for senior management, risk committees, and regulatory stakeholders
Requirements
What you’ll need- 7+ years of Technology Risk experience, or equivalent demonstrated through work experience, training, military experience, or education
- 7+ years of progressive experience in software engineering, DevSecOps, platform or cloud engineering, application security, technology controls, or technology risk preferred
- Front-line experience leading or operating technology capabilities strongly preferred
- Technical depth across modern SDLC and DevSecOps, including source control, CI/CD, automated testing, deployment automation, production change controls, and software supply chain security
- Ability to lead complex technical risk assessments, evaluate control effectiveness, identify systemic risk, and provide credible challenge across SDLC, DevSecOps, cloud, software supply chain, and AI-enabled engineering environments
- Ability to evaluate application architectures, deployment models, engineering evidence, technical standards, and control implementations
- Strong command of GitHub or GitLab, Jenkins or Azure DevOps, Terraform, containers, Kubernetes, cloud platforms, application security testing, and observability tools
- Experience implementing or assessing engineering controls across secure build and release processes, code provenance, secrets management, privileged automation, infrastructure as code, environment segregation, and runtime security
- Understanding of AI engineering risks and controls, including AI coding assistants, automated code generation, agentic workflows, data exposure, traceability, and human oversight
- Exceptional judgment, executive communication, and influencing skills
- Knowledge of NIST, SSDF, COBIT, FFIEC guidance, or ISO 27001 preferred
- Financial services or regulated-industry experience and relevant security, risk, cloud, or software lifecycle certifications preferred
- Position does not offer sponsorship
Benefits
Comp & perks- Equal opportunity employment
- Medical accommodation available upon request during the recruitment or interview process
- Drug-free workplace