At Schwab, you’re empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us “challenge the status quo” and transform the finance industry together.
We believe in the importance of in-office collaboration and fully intend for the selected candidate for this role to work on site in the specified location(s).
The Schwab Application Security Team, under the leadership of the Chief Information Security Officer (CISO), is tasked to protect information assets in support of Schwab business objectives and in conformity with Schwab policies. The Application Security Team is a core function of Schwab Cybersecurity Services and is primarily responsible for establishing and guiding the Secure Software Development Program within Schwab. These activities include creation and rollout of software security policies and best practices, software security architecture, software security scanning, penetration testing, and the education of Schwab software developers and testers in security best practices. The Software Security Engineer ensures the control and protection of software, improves the software development process, and minimizes defects and vulnerabilities in software production.
Key Accountabilities:
Ability to positively influence the behavior of peers and build relationships with other teams independently.Thrives in dynamic and fast-paced environments, adjusting quickly to shifting priorities.Works on problems of diverse scope where analysis of data requires evaluating specific factors.Communicate emerging application security weaknesses, exploit patterns, and risk scenarios in clear, business-relevant terms.Assist teams in mitigation and remediation efforts while operating within agile delivery environments.Apply insight and initiative to raise the standard of secure development and streamline the path from policy to implementation. What you haveRequired Qualifications:
Bachelor’s degree in computer science or related field Ability to demonstrate knowledge of OWASP Top 10 and CWE Top 25Knowledge of application-layer security controls, including authentication and authorization methods, input/output validation and sanitization, and defenses against injection attacks such as SQL or command injectionUnderstanding of secure cryptographic practices, including appropriate use of encryption algorithms, hashing functions, and protection of data at rest and in motionSecure coding in Java or .NET web and service development, backed by hands-on programming and IT experienceExperience participating as a member of a team in an agile environmentExperience with the Secure Development LifecycleExperience with security tools including SAST, DAST, IDE plugins, decompilers, and threat modeling platformsExperience with source code repository tools such as BitBucket and GitHubWeb application penetration testing, ethical hacking, red/blue teaming, or capture-the-flag experience a plus
Desired certifications:
Information Security and control certifications a plus (CISSP, CSSLP, GWEB, CISA, CISM, CEH, CRISC, etc.)In addition to the salary range, this role is also eligible for bonus or incentive opportunities.
Options Apply for this jobApplyShareRefer a friendRefer Sorry the Share function is not working properly at this moment. Please refresh the page and try again later. Share on your newsfeed Why work for us?Own Your Tomorrow embodies everything we do! We are committed to helping our employees ignite their potential and achieve their dreams. Our employees get to play a central role in reinventing a multi-trillion-dollar industry, creating a better, more modern way to build and manage wealth.
Benefits: A competitive and flexible package designed to empower you for today and tomorrow. We offer a competitive and flexible package designed to help you make the most of your life at work and at home—today and in the future. Application FAQs
Software Powered by iCIMS
www.icims.com