The Schwab Application Security Team, under the leadership of the Chief Information Security Officer (CISO), is tasked to protect information assets in support of Schwab business objectives and in conformity with Schwab policies. The Application Security Team is a core function of Schwab Cybersecurity Services and is primarily responsible for establishing and guiding the Secure Software Development Program within Schwab. These activities include creation and rollout of software security policies and best practices, software security architecture, software security scanning, penetration testing, and the education of Schwab software developers and testers in security best practices. The Software Security Engineer ensures the control and protection of software, improves the software development process, and minimizes defects and vulnerabilities in software production.
Well qualified candidates for this position will demonstrate the following key traits:
Prior engineering experience on a Software Security Assurance team Experience partnering with development teams to balance innovation and security concerns. Capable of analyzing large amounts of disparate data to produce easily understandable content. Experience with various application security tools including Software Composition Analysis (SCA), Static Application Security Testing (SAST), secrets management, and Dynamic Application Security Testing (DAST).
Well qualified candidates will also demonstrate expertise in the following technical areas:
Application engineering experience in software development Solid knowledge in application vulnerability types, attack vectors and remediation approaches Industry best practices for secure software development include software security design requirements. Application penetration testing and vulnerability scanning tools such as Fortify and how to integrate with agile SDLC. Proficiency with IP protocols and associated security mechanisms: TCP/IP, HTTP, SSL/TLS, PKI. Familiarity with well-known application security sources and standards such as OWASP, WASC and NIST. Experience with solutions for WAF/RASP technology for runtime application monitoring and protection. 2 years of experience with static and dynamic analysis and/or threat modeling tools Experience implementing enterprise deployment of application security tools, services, and controls. Solid understanding of a variety of software security practices, secure code reviews, threat modeling, security requirements analysis and architectural risk analysis
Key Accountabilities:
Desired certifications: