Principal Systems Architect - Application Security
Wells Fargo
- Location
- CHARLOTTE, NC
- Employment
- Full Time
- Work model
- On-Site
- Level
- Principal
- Posted
- Sep 21, 2026
Skills
About this role
About this role: Wells Fargo is seeking a Principal Security Architect - Application Security to help shape the future of secure software development across one of the world's largest financial institutions. As a senior technical leader, you will influence enterprise security strategy, define architecture standards, and drive secure-by-design practices across modern application platforms, cloud-native technologies, software supply chains, and emerging technologies, including AI-enabled systems. This role is ideal for a security architect who combines deep technical expertise, strong engineering fundamentals, and strategic influence to solve complex security challenges at enterprise scale. In this role, you will: Advise senior technology and cybersecurity leaders on application security strategy, architecture, and risk management. Define and drive enterprise security standards, reference architectures, design patterns, and security requirements. Lead security architecture reviews, threat modeling, and risk assessments for strategic initiatives, enterprise platforms, and emerging technologies. Champion secure-by-design practices across application development, APIs, cloud-native platforms, DevSecOps pipelines, and software supply chain ecosystems. Lead enterprise initiatives related to secure software development, software supply chain security, developer security platforms, application security modernization, and secure AI adoption. Influence enterprise technology strategy, architectural direction, and investment decisions that advance secure software development and technology modernization. Evaluate technologies through architecture analysis, design reviews, prototyping, automation, and technical experimentation. Drive adoption of automation and AI-enabled capabilities that improve security outcomes, engineering productivity, and operational efficiency. Mentor architects and senior engineers while fostering technical excellence and innovation.
Required Qualifications
7+ years of architecture experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education 7+ years of Architecture, Application Security, Software Security, or related cybersecurity experience. Deep expertise in application security architecture, secure software development, software supply chain security, threat modeling, and modern application architectures. Experience establishing enterprise security standards, architecture patterns, governance frameworks, or strategic initiatives adopted across multiple organizations. Experience leading enterprise-scale transformation initiatives involving application security, secure software development, software supply chain security, developer security platforms, or secure adoption of emerging technologies. Strong technical and engineering background with the ability to evaluate architectures, review technical designs, assess application code, and validate solutions through prototyping or proof-of-concept development. Experience securing modern application ecosystems, including APIs, cloud-native platforms, software delivery pipelines, open-source software, and distributed architectures. Proven ability to influence senior technology leaders, architects, engineering organizations, and cybersecurity stakeholders.
Desired Qualifications
Expertise in cloud-native security, API security, DevSecOps, and software supply chain security. Experience with modern application security capabilities, including SAST, DAST, SCA, secrets detection, infrastructure-as-code security, container security, SBOM management, and CI/CD security controls. Experience developing secure software, automation, security tooling, reusable frameworks, prototypes, or proof-of-concepts. Demonstrated engineering depth sufficient to engage credibly with software engineers and evaluate application code, development practices, and emerging technologies. Knowledge of secure