Demo

Application Security Analyst

Charles Schwab
Lone Tree, CO Other
POSTED ON 4/21/2025
AVAILABLE BEFORE 6/21/2025

Your opportunity


The Schwab Application Security Team, under the leadership of the Chief Information Security Officer (CISO), is tasked to protect information assets in support of Schwab business objectives and in conformity with Schwab policies.  The Application Security Team is a core function of Schwab Cybersecurity Services and is primarily responsible for establishing and guiding the Secure Software Development Program within Schwab.  These activities include creation and rollout of software security policies and best practices, software security architecture, software security scanning, penetration testing, and the education of Schwab software developers and testers in security best practices.  The Software Security Engineer ensures the control and protection of software, improves the software development process, and minimizes defects and vulnerabilities in software production.

 

Well qualified candidates for this position will demonstrate the following key traits:

Prior engineering experience on a Software Security Assurance team Experience partnering with development teams to balance innovation and security concerns. Capable of analyzing large amounts of disparate data to produce easily understandable content. Experience with various application security tools including Software Composition Analysis (SCA), Static Application Security Testing (SAST), secrets management, and Dynamic Application Security Testing (DAST).

 

Well qualified candidates will also demonstrate expertise in the following technical areas:

Application engineering experience in software development Solid knowledge in application vulnerability types, attack vectors and remediation approaches Industry best practices for secure software development include software security design requirements. Application penetration testing and vulnerability scanning tools such as Fortify and how to integrate with agile SDLC. Proficiency with IP protocols and associated security mechanisms: TCP/IP, HTTP, SSL/TLS, PKI. Familiarity with well-known application security sources and standards such as OWASP, WASC and NIST. Experience with solutions for WAF/RASP technology for runtime application monitoring and protection. 2 years of experience with static and dynamic analysis and/or threat modeling tools Experience implementing enterprise deployment of application security tools, services, and controls. Solid understanding of a variety of software security practices, secure code reviews, threat modeling, security requirements analysis and architectural risk analysis

What you have


Key Accountabilities:

 

  • Ability to positively influence the behavior of peers and build relationships with other teams without direct authority over those teams.
  • Assess current practices and recommend changes to relevant policies to ensure state of the art development practices as they relate to security.
  • Review security of software and identify and remediate vulnerabilities.
  • Provide necessary input to philosophy and practices around software development.
  • Help ensure security of software produced or procured by SCHWAB to prevent loss, inaccuracy, alteration, unavailability, or misuse of data.
  • Recommend security requirements for the software development process.
  • Support tools to help enable security requirements as part of application development process.
  • Integrate software security scanning and testing into SCHWAB’s software development, build and testing programs.
  • Work with application developers in security best practices and secure coding.
  • Conduct software security testing, including penetration testing, to verify that the software complies with security requirements.
  • Review, inspect and walk through source code to help developers understand vulnerabilities and provide advice to developers on remediation.
  • Develop automated application specific threat models to identify security design flaws and provide guidance on application specific risks and controls.
  • Identify security vulnerabilities as a result of security bugs, coding errors, omissions, and defects.

 

Desired certifications:

 

  • Information Security and control certifications a plus (CISSP, CSSLP, GWEB, CISA, CISM, CEH, CRISC, etc.)

What’s in it for you

At Schwab, we’re committed to empowering our employees’ personal and professional success. Our purpose-driven, supportive culture, and focus on your development means you’ll get the tools you need to make a positive difference in the finance industry. Our Hybrid Work and Flexibility approach balances our ongoing commitment to workplace flexibility, serving our clients, and our strong belief in the value of being together in person on a regular basis.

We offer a competitive benefits package that takes care of the whole you – both today and in the future:

  • 401(k) with company match and Employee stock purchase plan
  • Paid time for vacation, volunteering, and 28-day sabbatical after every 5 years of service for eligible positions
  • Paid parental leave and family building benefits
  • Tuition reimbursement
  • Health, dental, and vision insurance

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Application Security Analyst?

Sign up to receive alerts about other jobs on the Application Security Analyst career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$88,984 - $115,784
Income Estimation: 
$111,369 - $141,168
Income Estimation: 
$117,871 - $153,580
Income Estimation: 
$109,939 - $144,341
Income Estimation: 
$114,500 - $144,633
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$70,239 - $89,209
Income Estimation: 
$88,984 - $115,784
Income Estimation: 
$92,017 - $124,111
Income Estimation: 
$90,707 - $120,959
Income Estimation: 
$91,486 - $118,193
Income Estimation: 
$70,462 - $84,818
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Charles Schwab

Charles Schwab
Hired Organization Address Lone Tree, CO Full Time
Your opportunity At Schwab, you are empowered to make an impact on your career. Here, innovative thought meets creative ...
Charles Schwab
Hired Organization Address Northbridge, MA Full Time
Position Type : RegularYour opportunity At Schwab, you’re empowered to make an impact on your career. Here, innovative t...
Charles Schwab
Hired Organization Address Roanoke, TX Full Time
Your opportunity At Schwab, you’re empowered to make an impact on your career. Here, innovative thought meets creative p...
Charles Schwab
Hired Organization Address Lone Tree, CO Full Time
Your Opportunity At Schwab, you’re empowered to make an impact on your career. Here, innovative thought meets creative p...

Not the job you're looking for? Here are some other Application Security Analyst jobs in the Lone Tree, CO area that may be a better fit.

Sr. Systems/Application Security Analyst

American Financing, Aurora, CO

AI Application Engineer L2-L3

acre security, Denver, CO

AI Assistant is available now!

Feel free to start your new journey!