Skip to content

Open nowPosted 4 days ago

Senior Lead Technology Risk Officer (Application Domain, SDLC, DevOps and AI)

WF66 open roles

Where
CHARLOTTE NC
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Lead Technology Risk Officer (Application Domain, SDLC, DevOps and AI)WF · CHARLOTTE NC
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on WF's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. WF postings stay open a median of 2 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 4 days ago

WF median: 2 days open

The posting

About this role:

The Application Risk Domain Officer operates within Technology Risk Management (TRM), part of Corporate Risk, providing independent second line oversight across application domains. The role is a member of the Application Risk Domain Team, which performs domain level evaluation and produces evidence-based views of how application conditions contribute to enterprise risk exposure. The role engages with Technology, including Tech Operations, CIO organizations, to provide challenge and inform risk-based decisions. Outputs from this role support enterprise risk views provided to senior management, risk committees, and regulators.

The Application Risk Domain Officer is responsible for defining and advancing domain-level risk assessment, monitoring, and reporting approaches. This includes evaluating application-related risk conditions, assessing the effectiveness of risk management practices and controls, and developing evidence-based views of how those conditions contribute to enterprise technology risk exposure.

The role requires strong technical understanding of modern application engineering practices, including SDLC, CI/CD, infrastructure as code, cloud-native architectures, developer platforms, software supply chain processes, and AI-enabled engineering workflows. Due to the breadth and complexity of the domain, preference will be given to candidates who have operated, managed, or led one or more technology capabilities for which they will provide independent risk oversight. The successful candidate must be capable of engaging engineering teams with technical credibility, providing effective challenge on complex technology matters, and translating technical observations into clear, decision-ready insights for senior management, risk committees, and regulatory stakeholders.

In this role, you will:

  • Provide expert second-line oversight of modern engineering practices, including application architecture patterns, secure SDLC, CI/CD, DevSecOps, platform engineering, infrastructure as code, containerized workloads, and production release controls.
  • Own second-line technology risk coverage and provide thought leadership across the application risk domain, partnering closely with first-line engineering, controls and technology teams to drive consistent oversight of application architecture, development practices, deployment pipelines, and supporting engineering controls.
  • Perform technically rigorous assessments of source control workflows, branching strategies, build systems, test automation, artifact repositories, package dependencies, deployment orchestration, and runtime platform configurations to identify control weaknesses and systemic risk.
  • Evaluate the integrity of software delivery pipelines end to end, including code provenance, pipeline trust boundaries, secrets handling, approval models, environment segregation, artifact immutability, and rollback or recovery capabilities.
  • Lead deep-dive technical risk reviews of complex delivery environments and modernization programs, converting architecture, pipeline, and operational observations into clear risk statements, root causes, and targeted remediation expectations.
  • Analyze developer ecosystems and engineering tool chains at a practitioner level, including repositories, CI runners, build agents, package managers, IaC frameworks, containers, Kubernetes, cloud services, and observability stacks.
  • Evaluate AI-enabled engineering capabilities, including code assistants, prompt-based development workflows, automated test generation, agentic tooling, and model-integrated developer platforms, with emphasis on data exposure, unsafe code generation, traceability, and human review requirements.
  • Review design and implementation patterns for application and platform controls, such as policy-as-code, secrets management, service identity, environment hardening, logging, monitoring, drift detection, and release gating.
  • Develop technically meaningful risk indicators and challenge metrics for SDLC, DevSecOps, and AI-enabled engineering, such as deployment control exceptions, pipeline bypasses, privileged access patterns, dependency exposure, control coverage gaps, and remediation aging.
  • Serve as a trusted technical risk partner to engineering, security, architecture, and control teams by applying expert discipline knowledge to high-impact decisions and shaping resilient engineering practices across the enterprise.

Required Qualifications:

  • 7+ years of Technology Risk experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education.

Desired Qualifications:

  • 7+ years of progressive experience in software engineering, DevSecOps, platform or cloud engineering, application security, technology controls, or technology risk. Front-line experience leading or operating technology capabilities is strongly preferred
  • Proven technical depth across modern SDLC and DevSecOps, including source control, CI/CD, automated testing, deployment automation, production change controls, and software supply chain security.
  • Demonstrated ability to lead complex technical risk assessments, evaluate control effectiveness, identify systemic risk, and provide credible challenge across SDLC, DevSecOps, cloud, software supply chain, and AI-enabled engineering environments.
  • Ability to challenge complex technical decisions with credibility by evaluating application architectures, deployment models, engineering evidence, technical standards, and control implementations.
  • Strong command of modern engineering platforms and security toolchains, including GitHub or GitLab, Jenkins or Azure DevOps, Terraform, containers, Kubernetes, cloud platforms, application security testing, and observability tools.
  • Experience implementing or assessing critical engineering controls across secure build and release processes, code provenance, secrets management, privileged automation, infrastructure as code, environment segregation, and runtime security.
  • Understanding of emerging AI engineering risks and controls, including AI coding assistants, automated code generation, agentic workflows, data exposure, traceability, and human oversight.
  • Exceptional judgment, executive communication, and influencing skills, with the ability to translate complex technical risks into clear business impact, actionable remediation, and decision-ready reporting.
  • Knowledge of NIST, SSDF, COBIT, FFIEC guidance, or ISO 27001. Financial services or regulated-industry experience and relevant security, risk, cloud, or software lifecycle certifications are preferred.

Job Expectations:

  • This position does not offer sponsorship

Posting End Date:

2 Oct 2026

*Job posting may come down early due to volume of applicants.

We Value Equal Opportunity

Wells Fargo is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other legally protected characteristic.

Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit’s risk appetite and all risk and compliance program requirements.

Candidates applying to job openings posted in Canada: Applications for employment are encouraged from all qualified candidates, including women, persons with disabilities, aboriginal peoples and visible minorities. Accommodation for applicants with disabilities is available upon request in connection with the recruitment process.

Applicants with Disabilities

To request a medical accommodation during the application or interview process, visit Disability Inclusion at Wells Fargo.

Drug and Alcohol Policy

Wells Fargo maintains a drug free workplace. Please see our Drug and Alcohol Policy to learn more.

Wells Fargo Recruitment and Hiring Requirements:

a. Third-Party recordings are prohibited unless authorized by Wells Fargo.

b. Wells Fargo requires you to directly represent your own experiences during the recruiting and hiring process.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against WF's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on WF's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    WF's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.