Application Security Engineer
Charles Schwab · Southlake, TX · 1 wk ago
HybridInformation TechnologyFull-time
About the role
The Schwab Application Security team is part of Cybersecurity Services and focuses on protecting Schwab's information assets. Key responsibilities include establishing and evolving Schwab's Secure Software Development Program, leading security policies and practices, conducting security assessments, and educating developers.
Responsibilities
- Lead the development and implementation of software security policies and best practices
- Provide security architecture guidance and conduct software security scanning and penetration testing
- Partner with development teams to integrate security requirements with innovation
- Conduct code reviews and threat modeling to identify and mitigate vulnerabilities
- Develop and maintain application security tools and integrations
- Support the adoption of secure coding practices and industry best practices
Requirements
- Prior engineering experience in Software Security Assurance or Application Security
- Proven ability to balance security requirements with development goals
- Experience with application security tools like SCA, SAST, and secrets management
- Knowledge of secure software design principles and industry frameworks (OWASP, CIS, NIST)
- Minimum 2 years of experience with static analysis or threat modeling tools
- Experience with GitHub Advanced Security, CI/CD pipelines, SARIF output analysis, and enterprise Git workflows
- Understanding of common software weaknesses and vulnerability engineering
- Experience with package registries and dependency governance
Qualifications
- Strong analytical skills, including interpretation of large data sets
- Proficiency in Python-based automation for REST API integrations
- Advanced skills in CodeQL query development
- Familiarity with GitHub Advanced Security capabilities
- Expertise in CI/CD pipeline architecture using GitHub Actions
- Knowledge of SARIF specification and its use in static analysis
- Experience with enterprise Git workflows and release management
- Understanding of common software weaknesses and vulnerability engineering
- Experience with multi-repository architecture and configuration delivery
- Excellent written communication skills for technical documentation
Skills
- Python automation and API integration
- CodeQL query development
- GitHub Advanced Security platform engineering
- CI/CD pipeline architecture (GitHub Actions)
- SARIF output analysis and interpretation
- Enterprise Git workflow and release management
- Application security vulnerability engineering
- Technical documentation and architecture decision records
Benefits
At Schwab, we offer a comprehensive benefits package including:
- 401(k) with company match and Employee stock purchase plan
- Paid time off, volunteer days, and 28-day sabbatical
- Tuition reimbursement
- Health, dental, and vision insurance
Pay
Competitive salary based on experience and qualifications.
Schedule
Hybrid work schedule balancing flexibility and in-person collaboration.