Senior Cybersecurity Architect
Wells Fargo Bank | July 2022 – July 2023
Role Summary
Enterprise cybersecurity architecture work focused on unblocking standardized public-cloud adoption in a highly regulated financial environment. This role is most useful for evaluating cloud security governance, HYOK cryptography, reusable architecture patterns, executive technical influence, and high-volume security review acceleration.
- Led the Service Enablement Task Force that validated and approved secure architecture and infrastructure blueprints across 128 cloud resource provider types, creating a library of pre-approved patterns that allowed thousands of downstream business applications to adopt standardized designs and largely eliminated the need for custom infrastructure architecture.
- Led security review of 128 cloud resource provider types as a governed cloud control plane, converting bespoke infrastructure decisions into pre-approved patterns that let application teams adopt Azure services at scale while preserving cybersecurity and GRC approval gates.
- Accelerated security and infrastructure review cycles from an average of 3–12 application approvals per month to 40–50 completed reviews per week, unblocking the bank’s first successful large-scale public-cloud migration program after multiple prior failed attempts and enabling application teams to move into Azure architectures in volume for the first time in years.
- Designed and implemented multi-layered Hold-Your-Own-Key (HYOK) cryptography with external key providers that eliminated all third-party cryptographic dependencies and delivered 100% bank-controlled operations with zero exceptions; this removed an entire class of key-management risk, strengthened audit posture under high securities-regulation and FISA scrutiny, and served as a decisive requirement that finally unblocked enterprise cloud adoption.
- Developed SDLC policy-enforcement roadmaps that shifted the organization from an exception-driven culture to standardized architecture selection; application teams’ effort dropped from dozens of hours spread over weeks or months to roughly one to two hours of asynchronous work, while security and infrastructure teams achieved substantially higher output volume with near-universal consistency of results.
- Operated as a cross-functional cybersecurity resource influencing groups of 12 to 100+ engineers, GRC specialists, product teams, and cryptography experts; drove the senior-most executive decision to select the cloud provider and compel organization-wide adoption, eliminating longstanding resistance and entire categories of security and compliance risk across tens of thousands of endpoints and approximately 12,000 ATMs globally.
- Conducted comparative cybersecurity analysis of Azure and Google Cloud Platform services, identifying provider and platform gaps and converting the findings into closure plans that informed the bank’s cloud-security control model.
- Developed standardized compliance-scoring approaches for cloud services, making architecture and configuration review more consistent, repeatable, reliable, and quantifiable across teams that previously evaluated risk through bespoke review paths.
- Established repeatable compliance-scoring methods for cloud services and resource-provider gaps, giving cybersecurity, infrastructure, and GRC teams a shared evidence model for closure plans, audit defensibility, and provider selection decisions.
- Guided infrastructure teams toward ARM Templates and Azure Blueprints for deployment standardization, reducing configuration drift and making security requirements easier to enforce through repeatable infrastructure-as-code patterns.
- Provided endpoint-encryption subject matter expertise for the BitLocker cloud-management roadmap, extending cloud-governance decisions into endpoint data-protection strategy rather than leaving device encryption as a separate operational silo.
- Managed vendor integration and technical Q&A with cloud and security SMEs, using vendor evidence to strengthen design guides and preserve cybersecurity approval gates before application architecture review.