Manager, Technology Risk
At Schwab, you’re empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us challenge the status quo and transform the finance industry together. We believe in the importance of in-office collaboration and fully intend for the selected candidate for this role to work on site in the specified location(s).
About the role
As a Technology Risk Manager focused on application security, you will help strengthen Schwab’s ability to identify, assess, monitor, and manage technology risk across critical security and software development practices. This role sits at the intersection of cybersecurity, risk oversight, and business partnership, giving you the opportunity to influence how application security and penetration testing risks are understood, prioritized, and reduced across the firm.
In this individual contributor role, you will partner with technology, security, risk, audit, and business teams to evaluate risk management practices, assess alignment with policies and standards, and provide independent oversight of application security and software development life cycle processes. Your work will help protect client assets, client information, and firm assets by bringing structure, sound judgment, and clear reporting to complex risk topics. You will use analytical thinking, effective communication, and practical problem-solving to translate technical risk into actionable insight for stakeholders at varying levels of expertise.
Success in this role requires the ability to build trust, influence sustainable change, and adapt in a fast-moving environment where strong decisions, collaborative partnership, and risk-based prioritization directly support Schwab’s commitment to integrity, resilience, and client trust.
Responsibilities
- Identify, assess, and prioritize technology and cybersecurity risks using established risk assessment methodologies.
- Evaluate processes for alignment with published policies, standards, controls, regulatory expectations, and industry best practices.
- Communicate complex technical and risk concepts clearly to both technical and executive audiences.
- Develop and report cybersecurity metrics to quantify risk reduction and program effectiveness.
- Collaborate across functional teams to drive risk-informed outcomes.
- Support oversight of application security, penetration testing, software development life cycle, or cybersecurity risk management programs.
- Review and assess compliance against technology policies, standards, and controls.
- Develop, analyze, and report metrics to measure risk reduction, control effectiveness, or program performance.
- Work with internal auditors, regulators, or senior stakeholders to explain technology risk frameworks, issues, progress, and mitigation strategies.
Requirements
- 3+ years of demonstrated experience in cybersecurity, information technology, technology audit, or technology risk management.
- Understanding of application security and software development life cycle practices, including how related risks are identified, assessed, and managed.
- Strong analytical thinking, problem-solving, decision-making, prioritization, influencing, and conflict resolution skills.
- Demonstrated ability to collaborate across functional teams and bring diverse points of view together to drive risk-informed outcomes.
- Ability to adapt in an evolving environment while meeting critical commitments under pressure.
Qualifications
- Bachelor’s degree in Business Risk Management, Computer Science, Information Systems, Business Administration, or a related field; equivalent work experience may be considered.
- Hands-on risk management or oversight experience in a financial services or highly regulated environment.
- Professional certification such as CISSP, CISA, CISM, CRISC, CPCB, or a related credential.
- Knowledge of data analysis, reporting, or visualization tools such as Tableau or Power BI.
Benefits
- 401(k) with company match and Employee stock purchase plan.
- Paid time for vacation, volunteering, and 28-day sabbatical after every 5 years of service for eligible positions.
- Paid parental leave and family building benefits.
- Tuition reimbursement.
- Health, dental, and vision insurance.
Pay
In addition to the salary range, this role is eligible for bonus or incentive opportunities.
Schedule
Hybrid work and flexibility approach balancing in-office collaboration with workplace flexibility.