Application Security Analyst

Charles Schwab

Omaha (NE)

On-site

USD 70,000 - 90,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401(k) with company match
Paid vacation and volunteering time
Paid parental leave
Tuition reimbursement
Health, dental, and vision insurance

Job summary

A major financial services firm is seeking an entry-level Application Security Analyst in Omaha, Nebraska. In this role, you will build security controls into software, support dynamic application security testing, and collaborate with developers to address vulnerabilities. Key qualifications include familiarity with OWASP Top 10, DAST workflows, and programming knowledge in Java and .NET. The firm promotes a hybrid work model and offers a competitive benefits package.

Qualifications

  • Exposure to OWASP Top 10 concepts and examples.
  • Hands-on familiarity with DAST workflows and tools.
  • Understanding of API Security fundamentals and technologies.
  • Programming knowledge in Java and .NET.
  • Basic understanding of SDLC and DevSecOps.
  • Ability to explain security findings clearly.

Responsibilities

  • Perform and support DAST for web and API services.
  • Identify common vulnerability categories and advise on secure patterns.
  • Strengthen API security.
  • Collaborate with developers to validate remediation.
  • Integrate AppSec tooling into build pipelines.
  • Document vulnerabilities and remediation steps.
  • Monitor and coordinate actions during security test cycles.
  • Contribute to continuous improvement of security processes.

Skills

OWASP Top 10 concepts
DAST workflows
API Security fundamentals
Java programming
C# programming
DevSecOps basics
Clear communication

Education

Bachelor’s Degree in Computer Science
Certifications (CEH, Security+, OSCP)

Tools

BURP Suite

Job description

Join to apply for the Application Security Analyst role at Charles Schwab.

At Schwab, you’re empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us “challenge the status quo” and transform the finance industry together.

We believe in the importance of in-office collaboration and fully intend for the selected candidate for this role to work on site in the specified location(s).

As an entry-level Application Security Engineer, you’ll help build security into our software from design through delivery. You’ll partner with developers and product teams to identify and remediate vulnerabilities, support dynamic application security testing (DAST), and strengthen API security controls. You’ll use foundational programming knowledge in Java and .NET to understand how issues appear in code and how to fix them efficiently.

You’ll operate within Schwab’s Secure Application Development Standard and leverage our AppSec services to “shift left” and continuously improve our security posture.

Key Responsibilities
  • Perform and support DAST (e.g., running scans, triaging findings, and retesting after fixes) for web and API-based services; collaborate with engineering to prioritize and remediate issues.
  • Apply OWASP Top 10 knowledge to identify common vulnerability categories (e.g., broken access control, injection, SSRF) and advise teams on secure patterns.
  • Strengthen API security by participating in inventory, vulnerability triage, and testing activities aligned to our program approach.
  • Partner with developers to reproduce findings, review fixes, and validate remediation—using your understanding of Java/.NET code paths, frameworks, and typical anti-patterns.
  • Support “shift-left” practices by integrating AppSec tooling into build pipelines and promoting developer experience best practices (e.g., automation, workflow orchestration).
  • Document vulnerabilities, remediation steps, and residual risk; contribute to secure coding guides and internal knowledge bases.
  • Monitor and follow up on open issues; help coordinate cross-team actions during security test cycles and release gating.
  • Maintain accurate documentation of security findings bhí, remediation status, and communications with stakeholders.
  • Contribute to continuous improvement of application security processes and tooling.
Required Qualifications
  • Exposure to OWASP Top 10 concepts and practical examples (web & API).
  • Hands‑on familiarity with DAST workflows and tools (running scans, reading reports, working with developers to fix).
  • API Security fundamentals (authentication/authorization, rate limiting, schema validation, common API risk scenarios, common API technologies; REST, SOAP, GraphQL).
  • Programming fundamentals in Java and .NET (e.g., HTTP request/response, input validation, authN/authZ, secure configuration).
  • Understanding of SDLC and DevSecOps basics (version control, CI/CD, unit/integration testing).
  • Clear written and verbal communication; ability to explain findings to non‑security stakeholders.
Preferred Qualifications
  • Coursework, projects, or internships involving secure coding, code review, or vulnerability remediation in Java/.NET.
  • Familiarity with AppSec tooling including common DAST capabilities, BURP Suite, and development tools.
  • Exposure to API security testing approaches (linting, governed specs/OpenAPI, risk profiling, and CI integration).
  • Participation in security labs or events (e.g., OWASP workshops, cyber ranges).
  • Bachelor’s Degree in a relevant field (Computer Science, MIS, Cyber Security).
  • Certifications including CEH, Security+, OSCP.
What's in it for you

At Schwab, you’re empowered to shape your future. We champion your growth through meaningful work, continuous learning, and a culture of trust and collaboration—so you can build the skills to make a lasting impact. Our Hybrid Work and Flexibility approach balances our ongoing commitment to workplace flexibility, serving our clients, and our strong belief in the value of being together in person on a regular basis.

We offer a competitive benefits package that takes care of the whole you – both today and in the future:

    Hubbard
  • 401(k) with company match and Employee stock purchase plan
  • Paid time for vacation, volunteering, and 28‑day sabbatical after every 5 years of service for eligible positions
  • Paid parental leave and family building benefits
  • Tuition reimbursement
  • Health, dental, and vision insurance
Seniority Level

Entry level

Employment Type

Full-time

Job Function

Information Technology

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Application Security Architect
Staff Application Security Architect

Rocket Homes Real Estate LLC • Seattle (WA)

On-site
USD 149,000 - 318,000
Senior Application Security Engineer
Senior Application Security Engineer

Clear Capital | CubiCasa • Reno (NV)

On-site
USD 111,000 - 144,400
Medical, dental, and vision insurance
401(k) with employer match
Paid time off and holidays
+3
Senior Specialist - Software Development & Engineering
Senior Specialist - Software Development & Engineering

Charles Schwab • Southlake (TX)

On-site
USD 90,000 - 130,000
401(k) with company match
Paid time off
Tuition reimbursement
+1
Manager, Software Development & Engineering
Manager, Software Development & Engineering

Fairygodboss • Austin (TX)

On-site
USD 90,000 - 120,000
401(k) with company match
Paid time for vacation and volunteering
Tuition reimbursement
Senior Software Engineer – Full Stack
Senior Software Engineer – Full Stack

Charles Schwab • Austin (TX)

On-site
USD 120,000 - 150,000
401(k) with company match
Employee stock purchase plan
Paid parental leave
+2
Application Security Analyst
Application Security Analyst

Myconsumers • Lake Forest (IL)

Hybrid
USD 67,000 - 109,000
Medical insurance
Dental insurance
Vision insurance
+2
Java Developer
Java Developer

Charles Schwab Corporation • Austin (TX)

On-site
USD 170,000 - 230,000
Application Security Engineer
Application Security Engineer

Method, Inc. • Washington

On-site
USD 135,000 - 155,000
Medical Coverage
Dental Coverage
Vision Coverage
+4
Sr. Java Developer/Data Engineer
Sr. Java Developer/Data Engineer

Charles Schwab • Southlake (TX)

On-site
USD 90,000 - 130,000
401(k) with company match
Paid time for vacation
Tuition reimbursement
+1
Application Security Engineer - Chandler, AZ
Application Security Engineer - Chandler, AZ

Motion Recruitment • Chandler (AZ)

On-site
USD 110,000 - 160,000
Medical Insurance
Dental Benefits
Vision Benefits
+2