About this role: Wells Fargo is seeking a Senior Security Information & Event Management (SIEM) Engineer to design, implement, and operate database security monitoring and logging solutions at enterprise scale. This role focuses on IBM Guardium for database activity monitoring and Splunk for centralized log ingestion, correlation, and detection across a diverse database ecosystem including MongoDB, PostgreSQL‑based platforms, Neo4J, and other distributed data stores. Strong information security fundamentals and deep Splunk engineering experience are essential. In this role, you will: Engineer and operate IBM Guardium for database activity monitoring and security telemetry Design and manage direct‑to‑Splunk database logging pipelines across multiple platforms Own and maintain hundreds to thousands of Splunk knowledge objects, including searches, macros, lookups, dashboards, and alerts Develop and improve SIEM detection use cases aligned to threat models, risk scenarios, and regulatory requirements Support security incident response, including log analysis, technical investigation, and post‑incident root cause analysis Develop and maintain relationships with product vendors and other team stakeholders Participate in on‑call rotation, deployment activities, and SDLC‑aligned change management Partner with infrastructure, database, application, and security teams to improve the bank’s overall security posture Provide security consulting and technical guidance for internal engineering teams on medium to large initiatives Review, correlate, and analyze security logs to identify threats, anomalies, and control gaps Identify security vulnerabilities, perform risk assessments, and recommend remediation strategies Design, document, test, and maintain security solutions spanning telemetry, authentication, cloud, and data protection domains Contribute to and maintain Jira and Confluence documentation Mentor peers and contribute to a culture of continuous improvement and knowledge sharing Manage hundreds to thousands of Splunk knowledge objects at scale Build automated logging and telemetry processes using configuration, scripting, AI‑assisted tooling, and vendor integrations Collaborate with domestic and international teams Hybrid onsite work model Maintain high‑quality operational and technical documentation Demonstrate a willingness to learn, teach, and continuously improve
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level