Senior Security Design Architect
Schwab Cybersecurity Services (SCS) is a centralized First Line of Defense Center of Excellence (COE) that provides security services to advance Schwab's security posture and enhance the protection of Schwab's critical assets. The Security Design team handles the firm’s security strategy and security architecture vision and development, driving and synchronizing security strategies aligned with technology and business priorities while validating future directions through security research and innovation.
About the role
As a Senior Security Design Review Architect, you will provide security solutions, designs, architecture guidance, reviews, and support across the entire organization. This role requires balancing security, business objectives, innovation, operational resilience, regulatory obligations, and risk management. You will collaborate with business leaders, product teams, engineering organizations, cloud teams, AI teams, infrastructure teams, and cybersecurity partners to ensure solutions are designed, deployed, and operated securely. Every security decision must consider both direct and indirect impacts to ensure the confidentiality, integrity, availability, resilience, and trustworthiness of systems entrusted with sensitive business and client information.
Responsibilities
- Conduct secure design reviews, architecture assessments, threat modeling, and security risk evaluations for cloud, on-premises, hybrid, SaaS, AI, and application-based solutions supporting internal and external business initiatives.
- Work with Domain Architects, Product Managers, Product Owners, Engineering Teams, and Technology Leaders to define security requirements, non-functional requirements, secure deployment patterns, and security controls.
- Describe solution intent and operating environments while identifying primary systems, trust boundaries, integration points, data flows, security dependencies, and architectural risks.
- Review, assess, approve, and sign off on projects with respect to risk, security controls, architectural decisions, compliance expectations, and adherence to security policies, standards, and industry best practices.
- Perform architecture risk assessments and threat modeling activities to identify security vulnerabilities, attack paths, misuse scenarios, and control gaps.
- Develop and maintain security reference architectures, secure design standards, reusable architecture patterns, security control frameworks, and deployment models.
- Evaluate technology solutions against industry frameworks and standards including:
- NIST Cybersecurity Framework
- NIST Special Publication 800-53
- NIST AI Risk Management Framework (AI RMF)
- OWASP Top 10
- OWASP LLM Top 10
- CIS Benchmarks
- Zero Trust Architecture Principles
- Secure Software Development Lifecycle (SSDLC)
- Experience with security architecture reviews and security controls across:
- Identity and Access Management (IAM)
- Customer Identity and Access Management (CIAM)
- Present recommendations to executive leadership.
- Develop security requirements, non-functional requirements, architecture standards, and secure deployment models.
- Demonstrate strong collaboration, communication, stakeholder management, and influencing skills.
- Balance security requirements with business priorities and technology innovation.
Requirements
- 4-year college/university degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related discipline.
- Minimum 10+ years of experience designing, implementing, assessing, and governing enterprise security architectures, security controls, and security solutions.
- Deep expertise across multiple cybersecurity domains including AI Security, CIAM, IAM, Cloud Security, Application Security, Data Protection, Security Architecture, and Risk Management.
- Demonstrated experience conducting:
- Security Design & Architecture Reviews
- Threat Modeling
- Security Control Assessments
- Security Governance Activities
- Detailed understanding of security architecture principles and the ability to:
- Document architecture security risks
- Evaluate remediation options
- Define compensating controls
- Support risk-based decisions
- Present findings to technical stakeholders
Qualifications
Preferred:
- Experience securing AI/ML, Agentic AI solutions.
- CISSP certification.
- CSSLP certification.
- CCSP, CISM, TOGAF, Cloud Security, AI Security, and other Information Security certifications.
Benefits
- 401(k) with company match and Employee stock purchase plan
- Paid time for vacation, volunteering, and 28-day sabbatical after every 5 years of service for eligible positions
- Paid parental leave and family building benefits
- Tuition reimbursement
- Health, dental, and vision insurance
Schedule
Hybrid work and flexibility approach balancing workplace flexibility, serving clients, and in-person collaboration.