Jobs · Florida

Application Security Engineer

Charles Schwab · Orlando, FL · 6 days ago
HybridFull-time

About the role

The Schwab Application Security team is part of Cybersecurity Services and focuses on protecting Schwab's information assets. Key responsibilities include establishing and evolving Schwab's Secure Software Development Program, leading security policies and practices, and collaborating with development teams to ensure security and innovation.

Responsibilities

  • Create and implement software security policies and best practices
  • Provide security architecture guidance
  • Conduct software security scanning and penetration testing
  • Develop and maintain secure coding practices
  • Partner with development teams to integrate security into the software development lifecycle
  • Work with application security tools like SCA, SAST, and secrets management solutions
  • Design and govern enterprise Git workflows, release management, and dependency governance
  • Engage in vulnerability engineering and deliver technical documentation

Requirements

  • Prior engineering experience in Software Security Assurance or Application Security
  • Proven ability to balance security requirements with innovation
  • Strong analytical skills, including interpretation of large volumes of distributed data
  • Experience with application security tools and industry frameworks (OWASP, CIS, NIST)
  • Minimum of two years of experience with static analysis or threat modeling tools
  • Experience with Python automation, API integration, CodeQL query development, GitHub Advanced Security, CI/CD pipeline architecture, SARIF output analysis, and enterprise package registry & dependency governance
  • Excellent written communication skills for technical documentation

Qualifications

  • Minimum of two years of experience with static analysis or threat modeling tools
  • Experience with application security testing tools like Fortify
  • Familiarity with secure software design principles and industry best practices
  • Understanding of common application vulnerabilities, attack vectors, and remediation strategies
  • Experience with GitHub Advanced Security capabilities, including Code Scanning, Secret Scanning, Dependency Review, and custom query configuration
  • Knowledge of secure coding practices, code review processes, threat modeling, security requirements analysis, and architectural risk assessment
  • Experience with reusable and scalable CI/CD workflows using GitHub Actions
  • Strong understanding of secure coding practices, code review processes, threat modeling, security requirements analysis, and architectural risk assessment
  • Experience with enterprise Git workflows, release management, and dependency governance
  • Experience with application security vulnerability engineering and delivering technical documentation
  • Excellent written communication skills for technical documentation

Skills

  • Python Automation & API Integration
  • CodeQL Query Development
  • GitHub Advanced Security (GHAS) Platform Engineering
  • CI/CD Pipeline Architecture (GitHub Actions)
  • SARIF Output Analysis & Interpretation
  • Enterprise Git Workflow & Release Management
  • Application Security Vulnerability Engineering
  • Technical Documentation & Architecture Decision Records

Benefits

At Schwab, we offer a competitive benefits package including:

  • 401(k) with company match and Employee stock purchase plan
  • Paid time off for vacation, volunteering, and 28-day sabbatical after every 5 years of service
  • Paid parental leave and family building benefits
  • Tuition reimbursement
  • Health, dental, and vision insurance

Pay

Competitive salary based on experience and qualifications.

Schedule

Hybrid work schedule balancing flexibility and regular in-person meetings.

Similar jobs