Application Security Engineer

Charles Schwab

Orlando (FL)

Hybrid

USD 120,000 - 170,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Hybrid work model

Job summary

The Schwab Application Security team safeguards Schwab’s software and data through a secure SDLC, policy creation, and architecture guidance. You will work with developers to balance security with innovation, using tools like Fortify, SCA/SAST, and CodeQL to reduce vulnerabilities and improve secure coding practices across projects.

Success requires collaboration with Agile teams, strong analytical skills, and a track record in application security tooling and threat modeling within enterprise

Qualifications

  • 2+ years in static analysis or threat modeling tools.
  • Experience with SCA, SAST and secrets management in apps.
  • Familiar with OWASP, CIS, NIST security standards.
  • Ability to partner with development teams to balance security and innovation.
  • Solid understanding of secure coding practices and SDLC integration.

Responsibilities

  • Protect Schwab software assets by strengthening development processes and controls.
  • Lead integration of security testing into Agile development environments.
  • Interpret large volumes of security data into actionable insights.
  • Educate developers and testers on secure coding practices.
  • Develop security policies, tooling, and architecture guidance.

Skills

Software security
Application security
Threat modeling
Data interpretation
Secure SDLC
Analytical skills
Agile collaboration

Tools

Fortify
CodeQL
SAST tools
SCA tools
Secrets management
GitHub Advanced Security
GitHub Actions

Job description

Your opportunity

The Schwab Application Security team, operating under the leadership of the Chief Information Security Officer (CISO), is responsible for protecting Schwab’s information assets in support of business objectives and in alignment with corporate policies. As a core function within Cybersecurity Services, the Application Security team leads the establishment and ongoing evolution of Schwab’s Secure Software Development Program. This includes the creation and implementation of software security policies and best practices, providing security architecture guidance, conducting software security scanning and penetration testing, and educating developers and testers on secure coding practices.

The Software Security Engineer plays a key role in safeguarding software assets by strengthening the development process, enhancing security controls, and reducing defects and vulnerabilities in production environments.

Successful candidates will have prior engineering experience within a Software Security Assurance or Application Security team and a proven ability to partner effectively with development teams to balance security requirements with innovation. They will demonstrate strong analytical skills, including the ability to interpret large volumes of distributed data and translate it into clear, actionable insights. Candidates should also have experience working with a range of application security tools, including Software Composition Analysis (SCA), Static Application Security Testing (SAST), and secrets management solutions.

In addition, candidates will bring solid application engineering experience and a strong understanding of common application vulnerabilities, attack vectors, and remediation strategies. They should be familiar with secure software design principles and industry best practices for integrating security into the software development lifecycle. Experience with application security testing tools, such as Fortify, and their integration into agile development environments is expected.

Candidates should have familiarity with recognized industry frameworks and standards such as OWASP, CIS, and NIST. A minimum of two years of experience working with static analysis or threat modeling tools is expected, along with experience implementing and scaling enterprise application security tools, services, and controls. Finally, candidates must demonstrate a strong understanding of secure coding practices, code review processes, threat modeling, security requirements analysis, and architectural risk assessment.

Preferred Qualifications
Python Automation & API Integration
  • Strong proficiency in designing Python‑based automation for large‑scale REST API integrations, including repository management, content discovery, workflow orchestration, and encoded file handling across enterprise source‑control platforms.
  • Custom CodeQL Query Development
  • Strong understanding of CodeQL query authoring concepts, including QL pack management, database creation, dependency resolution via --search-path, and techniques for minimizing false positives through boundary analysis and source/sink filtering.
  • GitHub Advanced Security (GHAS) Platform Engineering
  • Deep familiarity with GitHub Advanced Security capabilities, including Code Scanning, Secret Scanning, Dependency Review, custom query configuration, and scalable alert triage and remediation workflows across multiple repositories.
CI/CD Pipeline Architecture (GitHub Actions)
  • Demonstrated expertise in architecting reusable and scalable CI/CD workflows using GitHub Actions, including callable workflows, matrix strategies, cross‑repository authentication models, and centralized pipeline governance.
SARIF Output Analysis & Interpretation
  • Strong knowledge of the SARIF specification and its use in static analysis pipelines, including interpreting results, validating findings, identifying false positives, and enabling automated reporting across diverse codebases.
Enterprise Git Workflow & Release Management
  • Experience designing and governing enterprise Git workflows, including structured branching strategies, release coordination, branch protection rules, cross‑organization pull requests, and versioning policy enforcement.
Application Security Vulnerability Engineering
  • Solid understanding of common software weakness classes and the intentional design of vulnerable code patterns to validate static analysis coverage, detection accuracy, and severity classification.
Multi‑Repository Architecture & Configuration Delivery
  • Proven ability to architect centralized configuration and workflow distribution models for large repository ecosystems, including reusable workflows, configuration validation, and scalable authentication mechanisms.
Enterprise Package Registry & Dependency Governance
  • Strong knowledge of internal package ecosystems and dependency governance, including artifact repository configuration, registry enforcement and blocking strategies, and controlled use of vulnerable dependencies for security testing.
Technical Documentation & Architecture Decision Records
  • Excellent written communication skills with experience producing high‑quality technical documentation, including Architecture Decision Records (ADRs), onboarding guides, and operational runbooks for cross‑functional engineering teams.
What’s in it for you

At Schwab, you’re empowered to shape your future. We champion your growth through meaningful work, continuous learning, and a culture of trust and collaboration—so you can build the skills to make a lasting impact. Our Hybrid Work and Flexibility approach balances our ongoing commitment to workplace flexibility, serving our clients, and our strong belief in the value of being together in person on a regular basis.

We offer a competitive benefits package that takes care of the whole you – both today and in the future:

  • 401(k) with company match and Employee stock purchase plan
  • Paid time for vacation, volunteering, and 28-day sabbatical after every 5 years of service for eligible positions
  • Paid parental leave and family building benefits
  • Tuition reimbursement
  • Health, dental, and vision insurance
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Charles Schwab Corporation • Southlake (TX)

On-site
USD 120,000 - 160,000
Application Security Analyst
Application Security Analyst

Charles Schwab • Omaha (NE)

On-site
USD 70,000 - 90,000
401(k) with company match
Paid vacation and volunteering time
Paid parental leave
+2
Senior Dev Ops Engineer
Senior Dev Ops Engineer

Charles Schwab • Austin (TX)

On-site
USD 140,000 - 190,000
401(k) with company match
Employee stock purchase plan
Paid vacation and volunteering
+4
Sr Manager, Software Development & Engineering Lead
Sr Manager, Software Development & Engineering Lead

Charles Schwab • San Francisco (CA)

On-site
USD 150,000 - 210,000
401(k) with company match
Sabbatical after 5 years of service
Paid parental leave
+3
.NET Software Developer - Sr Specialist
.NET Software Developer - Sr Specialist

Charles Schwab • Austin (TX)

On-site
USD 120,000 - 180,000
401(k) with company match
Employee stock purchase plan
Paid time for vacation, volunteering,
+4
Senior Software and Platform Engineer
Senior Software and Platform Engineer

Charles Schwab • Austin (TX)

On-site
USD 190,000 - 250,000
401(k) with company match
Paid time off & sabbatical
Parental leave and family building
+2
Manager, Software Development & Engineering
Manager, Software Development & Engineering

Charles Schwab • Southlake (TX)

On-site
USD 120,000 - 180,000
Bonus opportunities
Manager, Software Development & Engineering
Manager, Software Development & Engineering

Charles Schwab • Austin (TX)

On-site
USD 90,000 - 120,000
401(k) with company match
Paid time for vacation and volunteering
Tuition reimbursement
Sr. Specialist - Security Analytics & Operations
Sr. Specialist - Security Analytics & Operations

Charles Schwab • Phoenix (AZ)

On-site
USD 110,000 - 160,000
401(k) with company match
Employee stock purchase plan
Paid time for vacation
+4
Application Security Engineer - AI Engineer
Application Security Engineer - AI Engineer

Cybersecurity Jobs • Southlake (TX), Austin (TX)

On-site
USD 125,000 - 160,000
401(k) with company match and Employee
Sabbatical after 5 years
Health, dental, and vision insurance
+2