Wells Fargo is seeking a Cyber Behavioral Defense Lead (Lead Information Security Analyst), as part of the Technology Management and Strategy team.
Learn more about the career areas and lines of business at wellsfargojobs.com.
You will serve as the lead for Behavioral Defense within the Cyber Resiliency & Human Defense Team and will examine how threat actors exploit human judgment, trusted relationships, business processes, communication channels, and operational routines. You will translate those insights into targeted interventions that reduce human-enabled cyber risk. Interventions may include changes to business processes, controls, decision points, communications, campaigns, employee guidance, or targeted learning.
In this role, you will:
Provide advanced information security consultation for all aspects of information security compliance policy, risk management, and remediation
Directly assess risk, develop intervention strategies, create campaign briefs and priority content, coordinate delivery and evaluate whether the intervention changed behavior or reduced exposure
Analyze threat intelligence, insider threat insights, incidents, simulation results, and business processes to identify where attackers can exploit human judgment, trusted relationships, operational routines, or control gaps
Identify high-risk populations, processes, and decision points, then define the behavior or process change needed to reduce exposure
Partner closely with Cyber Threat Intelligence, Insider Threat, simulation teams, and business-process owners to convert threat insights into practical interventions
Determine whether risk should be addressed through a process or control change, targeted campaign, behavioral nudge, decision aid, role-based guidance, learning experience, or a combination of action
Create and own behavioral-risk assessments, intervention strategies, campaign briefs, messaging architecture, process-change recommendations, and priority content
Design threat-informed campaigns that help employees recognize manipulation, verify unusual requests, escalate concerns, and make safer decisions under pressure
Translate complex cyber threats into clear, relevant, and actionable guidance for employees, leaders, high-risk populations, and business partners
Define the intended behavioral or process outcome before launch and partner with measurement teams to establish baselines, target populations and success measures
Evaluate results and recommend whether interventions should continue, change, expand, be reinforced, or stop
Serve as the Behavioral Defense individual contributor under the Head of Behavioral Defense & Human Risk, influencing cybersecurity, fraud, control, technology, and business partners without direct reporting authority
Required Qualifications:
5+ years of Information Security Analysis experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
Desired Qualifications:
Demonstrated experience in information security, cyber risk, threat intelligence, fraud prevention, identity-related risk, insider threat, or adversary-focused security disciplines
Experience conducting red team exercises, adversary emulation, or offensive security assessments
Experience designing, leading, or evaluating social engineering assessments and adversary simulation activities
Demonstrated experience managing fraud, identity-related risks, account compromise, or trust and safety concerns
Proven ability to translate complex cyber threats and security risks into practical business actions and risk mitigation strategies
Experience leading complex, cross-functional security initiatives across business, technology, and risk management teams
Experience developing executive-level findings, briefings, and strategic recommendations for senior leadership
Experience identifying and assessing how threat actors exploit authority, urgency, trust, routine, fear, helpfulness, and other human decision-making behaviors
Experience reviewing business processes, workflows, and control environments to identify vulnerabilities related to fraud, social engineering, insider misuse, or unauthorized disclosure of information
Working knowledge of phishing, vishing, smishing, deepfakes, business email compromise (BEC), impersonation attacks, trusted-access abuse, and AI-enabled social engineering techniques
Job Expectations:
Position offers a hybrid work schedule
This position is not eligible for Visa sponsorship
Relocation assistance is not available for this position
Posting Locations:
1751 Pinnacle Dr. McLean, Virginia 22102
300 S Brevard Street. Charlotte, North Carolina 28202
Reflected is the base pay range offered for this position. Pay may vary depending on factors including but not limited to demonstrated examples of prior performance, skills, experience, or work location. Employees may also be eligible for incentive opportunities. $119,000.00 - $224,000.00 Benefits
Wells Fargo provides eligible employees with a comprehensive set of benefits, many of which are listed below. Visit Benefits - Wells Fargo Jobs for an overview of the following benefit plans and programs offered to employees.
Health benefits
401(k) Plan
Paid time off
Disability benefits
Life insurance, critical illness insurance, and accident insurance
Parental leave
Critical caregiving leave
Discounts and savings
Commuter benefits
Tuition reimbursement
Scholarships for dependent children
Adoption reimbursement
Posting End Date: 30 Aug 2026 * Job posting may come down early due to volume of applicants.
We Value Equal Opportunity
Wells Fargo is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other legally protected characteristic.
Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit's risk appetite and all risk and compliance program requirements.