Specialist - Security Development & Engineering

The Charles Schwab Corporation

Jersey City (NJ)

On-site

USD 110,000 - 170,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

The Charles Schwab Corporation is seeking a Cloud Security Automation Engineer to design and operate scalable automation across AWS, Azure, and GCP. You will join a team delivering policy-as-code, cloud-native controls, and secure DevSecOps integrations in collaboration with Cloud Security Engineering, Cyber Operations, and platform teams.

Responsibilities include building fault-tolerant automation, implementing logging and monitoring, and automating remediation across cloud environments.

Qualifications

  • Bachelor's degree or equivalent practical experience in a related field.
  • 2–5 years of cybersecurity engineering, cloud engineering, software development, or security automation.
  • Hands-on with major cloud platforms: AWS, Azure, or GCP.
  • Experience developing automation with Python, PowerShell, Bash or similar.
  • Experience with source control, CI/CD, DevSecOps, and IaC (Terraform, Bicep, CloudFormation, Pulumi).
  • Understanding of fault-tolerant coding, automated testing, logging, monitoring, and incident response.

Responsibilities

  • Design, develop, test, deploy, and maintain cloud security automation across CSPM, CWP, IAM, SSPM, CASB, CIEM, and related tools.
  • Build resilient services using cloud-native APIs and best practices; implement logging, monitoring, retries, and recovery.
  • Automate compliance monitoring, remediation, reporting to reduce manual effort.
  • Support cloud security platform integrations, migrations, and modernization in AWS, Azure, GCP, and SaaS environments.
  • Design and maintain Policy-as-Code within CI/CD and SDLC; integrate scanning in pipelines.

Skills

Cloud security
Python
PowerShell
Bash
CI/CD
DevSecOps
Logging & monitoring
Incident response
Documentation

Education

Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or related field

Tools

Terraform
Bicep
CloudFormation
Pulumi

Job description

Your Opportunity

Schwab remains committed to providing increased visibility to career growth opportunities and job requirements. This posting announcement is part of increased transparency and while all qualified applicants will be reviewed and considered, this organization has a preferred candidate identified for this role.

At Schwab, you’re empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us “challenge the status quo” and transform the finance industry together.

We believe in the importance of in-office collaboration and fully intend for the selected candidate for this role to work on site in the specified location.

As a Cloud Security Automation Engineer, you will build and operate scalable security automation that strengthens Schwab's cybersecurity posture across AWS, Azure, GCP, and SaaS environments.

You will partner with Cloud Security Engineering, Cyber Operations, platform engineering, and development teams to deliver policy-as-code, cloud-native controls, operational monitoring, and reliable DevSecOps integrations. This hands-on role combines software engineering, security operations, and continuous improvement.

What You'll Do

Cloud Security Automation and Engineering

  • Design, develop, test, deploy, and maintain fault-tolerant cloud security automation for CSPM, CWP, IAM, SSPM, CASB, CIEM, and related capabilities.
  • Build resilient, maintainable services and integrations using cloud-native APIs, SDKs, event-driven patterns, and software engineering best practices.
  • Implement standardized logging, monitoring, alerting, health checks, retries, graceful failure handling, and recovery capabilities for production automations.
  • Automate compliance monitoring, remediation, reporting, and repetitive security processes to improve coverage and reduce manual effort.
  • Support cloud security platform integrations, migrations, and modernization initiatives across AWS, Azure, GCP, and SaaS environments.

DevSecOps and Policy-as-Code

  • Design and maintain Policy-as-Code and Security-as-Code controls within CI/CD pipelines and the software development lifecycle.
  • Integrate infrastructure and configuration scanning into cloud build pipelines using tools such as Checkov, OPA, Sentinel, or comparable frameworks.
  • Partner with development and infrastructure teams to shift security left through automated testing, actionable feedback, and deployment guardrails.
  • Improve automation reliability through code review, version control, testing, release controls, monitoring, and continuous improvement.

Operational Reliability and On-Call Support

  • Participate in the on-call rotation and provide production support for cloud security services and automations, including after-hours response when assigned.
  • Investigate and resolve automation failures, alerts, and service issues; document root cause, remediation, and preventive actions.
  • Support security incident response by improving event detection, classification, escalation, and remediation workflows.
  • Use on-call findings and service metrics to strengthen fault tolerance, observability, recoverability, and operational resilience.
  • Maintain runbooks and operational procedures that enable consistent support and effective handoffs.

Collaboration and Technical Contribution

  • Translate security requirements into practical, scalable engineering solutions aligned with business and risk objectives.
  • Collaborate with architects, engineers, developers, and operations teams on solution design and implementation.
  • Produce clear technical documentation, architecture artifacts, runbooks, metrics, and operational reporting.
  • Share knowledge, mentor less-experienced engineers, and recommend improvements to cloud security technologies and engineering practices.
What you have

To ensure that we have fulfilled our promise of 'challenging the status quo,' this role has specific qualifications that successful candidates should have.

Required Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field, or equivalent practical experience.
  • 2-5 years of experience in cybersecurity engineering, cloud engineering, software development, or security automation.
  • Hands-on experience with at least one major cloud platform: AWS, Azure, or GCP.
  • Experience developing automation with Python, PowerShell, Bash, or a comparable language.
  • Experience with source control, CI/CD pipelines, DevSecOps practices, and Infrastructure-as-Code technologies such as Terraform, Bicep, CloudFormation, or Pulumi.
  • Understanding of fault-tolerant coding, automated testing, logging, monitoring, incident response, vulnerability management, and cloud security principles.
  • Ability and willingness to participate in an on-call rotation.
  • Strong analytical, troubleshooting, documentation, and communication skills.

Preferred Qualifications

  • Experience with cloud security platforms such as Cortex Cloud, Prisma Cloud, Wiz, Orca, Lacework, or comparable solutions.
  • Knowledge of CSPM, CWP, CIEM, SSPM, CASB, CNAPP, IAM, and cloud security operations.
  • Experience implementing Policy-as-Code with Checkov, OPA, Sentinel, or similar technologies.
  • Experience building production monitoring, alerting, observability, and automated remediation capabilities.
  • Experience supporting production services through incident response and on-call operations.
  • Relevant certification such as ISC2 CC, Security+, CCSK, CCSP, AWS Security Specialty, Azure Security Engineer, or GCP Professional Cloud Security Engineer.
  • Experience in a highly regulated environment, preferably financial services.

In addition to the salary range, this role is also eligible for bonus or incentive opportunities


What’s in it for you

At Schwab, you’re empowered to shape your future. We champion your growth through meaningful work, continuous learning, and a culture of trust and collaboration—so you can build the skills to make a lasting impact. Our Hybrid Work and Flexibility approach balances our ongoing commitment to workplace flexibility, serving our clients, and our strong belief in the value of being together in person on a regular basis.

We offer a competitive benefits package that takes care of the whole you – both today and in the future:

  • 401(k) with company match and Employee stock purchase plan
  • Paid time for vacation, volunteering, and 28-day sabbatical after every 5 years of service for eligible positions
  • Paid parental leave and family building benefits
  • Tuition reimbursement
  • Health, dental, and vision insurance
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Specialist Security Development & Engineering
Sr Specialist Security Development & Engineering

The Charles Schwab Corporation • Phoenix (AZ)

On-site
USD 150,000 - 230,000
401(k) match
Employee stock purchase
Volunteer time off
+6
Sr Manager, Security Development & Engineering Lead
Sr Manager, Security Development & Engineering Lead

The Charles Schwab Corporation • Phoenix (AZ)

On-site
USD 180,000 - 240,000
401(k) with company match
Paid time off and sabbatical after 5+考
Parental leave and family benefits
+2
Sr. Cloud Engineer
Sr. Cloud Engineer

Charles Schwab • Austin (TX)

Hybrid
USD 140,000 - 190,000
401(k) match
Paid time off
Health insurance
Sr. Specialist - Security Analytics & Operations
Sr. Specialist - Security Analytics & Operations

The Charles Schwab Corporation • Lone Tree (CO)

Hybrid
USD 110,000 - 150,000
401(k) match
Vacation time
Parental leave
+2
Sr Specialist, Cloud Engineer
Sr Specialist, Cloud Engineer

The Charles Schwab Corporation • Austin (TX)

Hybrid
USD 120,000 - 170,000
Sr Specialist, Cloud Engineer
Sr Specialist, Cloud Engineer

Charles Schwab • Austin (TX)

Hybrid
USD 120,000 - 180,000
401(k) match
Stock purchase plan
Paid vacation & volunteering
+5
Specialist - Security Development & Engineering
Specialist - Security Development & Engineering

The Charles Schwab Corporation • Lone Tree (CO)

On-site
USD 120,000 - 180,000
401(k) match
Employee stock purchase plan
Paid time off & sabbatical
Manager, Cloud Engineer
Manager, Cloud Engineer

The Charles Schwab Corporation • Southlake (TX)

Hybrid
USD 130,000 - 170,000
401(k) with company match
Employee stock purchase plan
Paid vacation and volunteering time
+4
Specialist, Cloud Engineer
Specialist, Cloud Engineer

The Charles Schwab Corporation • Southlake (TX)

On-site
USD 90,000 - 140,000
Manager, Security Development & Engineering
Manager, Security Development & Engineering

The Charles Schwab Corporation • Phoenix (AZ)

On-site
USD 130,000 - 180,000