Southlake, TX, US
14 days ago
Senior Software Security Analyst
Welcome page Returning Candidate? Log in Senior Software Security Analyst Job Locations US-TX-Southlake | US-NE-Omaha | US-AZ-Phoenix | US-TX-Austin | US-MI-Ann Arbor Requisition ID 2025-112800 Posted Date 18 hours ago(7/9/2025 5:37 PM) Category Engineering & Software Development Salary Range USD $145,000.00 - $180,000.00 / Year Application deadline 8/9/2025 Position Type Full time Your Opportunity

At Schwab, you’re empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us “challenge the status quo” and transform the finance industry together.

 

We believe in the importance of in-office collaboration and fully intend for the selected candidate for this role to work on site in the specified location(s).

 

Schwab Technology Services enables the future of how clients manage their money by providing innovative and reliable technology products and services as a part of our ongoing commitment to democratize access to investing and financial planning.

 

 

•          Serve as a trusted partner to developers, product owners, and stakeholders, translating company security policies into actionable, non-functional application security controls.
•          Be thought leader – drive secure code reviews, identify context-specific vulnerabilities, align teams with security objectives, and eliminate process inefficiencies.
•          Communicate emerging application security weaknesses, exploit patterns, and risk scenarios in clear, business-relevant terms.
•          Assist teams in mitigation and remediation efforts while operating within agile delivery environments.
•          Apply insight and initiative to raise the standard of secure development and streamline the path from policy to implementation.



What you have

Required Qualifications

 

o          Bachelor’s degree in computer engineering OR related engineering degree and/or practical experience
o          Ability to demonstrate knowledge of OWASP Top 10 and CWE Top 25
o          Knowledge of application-layer security controls, including authentication and authorization methods, input/output validation and sanitization, and defenses against injection attacks such as SQL or command injection
o          Understanding of secure cryptographic practices, including appropriate use of encryption algorithms, hashing functions, and protection of data at rest and in motion
o          Secure coding in Java or .NET web and service development, backed by 7+ years of practical, hands-on programming and IT experience
o          Experience participating as a member of a team in an agile environment
o          Experience with the Secure Development Lifecycle
o          Experience with security tools including SAST, DAST, IDE plugins, decompilers, and threat modeling platforms

 

Advanced people skills:
o          Ability to conceptualize an application security finding and the best tactical approach for a team to remediate
o          Excellent communication skills and proven ability to communicate threats and facilitate progress towards long-term remediation
o          Ability to effectively communicate complex security findings to both technical and non-technical audiences
o          Ability to demonstrate proven analytical and problem-solving skills, as well as desire to assist others
o          Effective relationship builder: ability to partner cross-functionally, cross-enterprise and work effectively with various levels of the organization

 

Preferred Qualifications

Experience with enterprise platforms such as Struts, Spring, J2EE/Jakarta EE (Java) or .NET, with awareness of how their structure impact authentication, authorization, and secure service designIntermediate understanding of web technologies and data formats, including XML, JSON, AJAX, with attention to the security implications of JavaScript-driven UIs and asynchronous communicationFamiliarity with service protocols and architectures such as SOAP and REST, with working knowledge of secure data handling and integration patternsExperience with source code repository tools such as BitBucket and GitHubMaster’s degree in Cybersecurity a plusWeb application penetration testing, ethical hacking, red/blue teaming, or capture-the-flag experience a plus

In addition to the salary range, this role is also eligible for bonus or incentive opportunities.

 

Options Apply for this jobApplyShareRefer a friendRefer Sorry the Share function is not working properly at this moment. Please refresh the page and try again later. Share on your newsfeed Why work for us?

Own Your Tomorrow embodies everything we do! We are committed to helping our employees ignite their potential and achieve their dreams. Our employees get to play a central role in reinventing a multi-trillion-dollar industry, creating a better, more modern way to build and manage wealth.

 

Benefits: A competitive and flexible package designed to empower you for today and tomorrow. We offer a competitive and flexible package designed to help you make the most of your life at work and at home—today and in the future.   Application FAQs

Software Powered by iCIMS
www.icims.com

Por favor confirme su dirección de correo electrónico: Send Email