Sr Specialist Security Development & Engineering

The Charles Schwab Corporation

Phoenix (AZ)

On-site

USD 150,000 - 230,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

401(k) match
Employee stock purchase
Volunteer time off
Sabbatical every 5 years
Parental leave
Tuition reimbursement
Health insurance
Dental insurance
Vision insurance

Job summary

The Charles Schwab Corporation in Phoenix is seeking a senior Cloud Security Automation Engineer to design, build, and operate enterprise cloud security solutions across AWS, Azure, GCP, and SaaS environments. This on-site role combines cloud-native software engineering, policy-as-code, and production ownership to reduce risk and improve security maturity.

You will lead complex engineering efforts, own production reliability, and mentor engineers while advancing cloud security maturity across

Qualifications

  • Bachelor's degree in CS, Cybersecurity, Engineering, or related field.
  • 5+ years of software/security/cloud engineering experience.
  • Strong development with Python or Java.
  • Experience building enterprise automation or cloud-native apps in production.
  • Hands-on with AWS, Azure, or GCP security controls.
  • Experience with CSPM, CWP, SSPM, CASB, CNAPP, CIEM.
  • Experience with Infrastructure-as-Code and CI/CD pipelines.
  • Knowledge of fault-tolerant design, IAM, logging, and incident response.
  • Willingness to participate in on-call rotations.
  • Ability to influence decisions and communicate across teams.

Responsibilities

  • Design, build, deploy, and operate cloud security automation across multiple cloud providers.
  • Modernize legacy automations into scalable architectures.
  • Develop capabilities for CSPM, CWP, SSPM, CASB, CNAPP, IAM.
  • Create automated controls, workflows, and reporting to reduce risk.
  • Evaluate security technologies to advance cloud security maturity.
  • Own production reliability and on-call responsibilities.
  • Lead troubleshooting and provide remediation for incidents.
  • Mentor engineers and share best practices.

Skills

Python
Java
Cloud security
DevSecOps
Infrastructure as Code
On-call rotation
Troubleshooting

Education

Bachelor's degree in CS/Engineering or related field

Tools

AWS
Azure
GCP
CSPM
CWP
SSPM
CASB
CNAPP
CIEM
IaC

Job description

Your Opportunity

Schwab remains committed to providing increased visibility to career growth opportunities and job requirements. This posting announcement is part of increased transparency and while all qualified applicants will be reviewed and considered, this organization has a preferred candidate identified for this role.

At Schwab, you’re empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us "challenge the status quo" and transform the finance industry together.

We believe in the importance of in-office collaboration and fully intend for the selected candidate for this role to work on site in the specified location.

As a Cloud Security Automation Engineer, you will design, build, and operate enterprise cloud security solutions across AWS, Azure, GCP, and SaaS environments.

This senior individual contributor role combines cloud-native software engineering, policy-as-code, platform modernization, and production ownership. You will lead complex technical efforts, influence architecture and engineering practices, and partner across security, infrastructure, and application teams to reduce risk and improve cloud security maturity.

Cloud Security Automation and Architecture

  • Design, build, deploy, and operate fault-tolerant cloud security automation and cloud-native services across AWS, Azure, GCP, and SaaS environments.
  • Modernize legacy or monolithic automations into scalable, maintainable architectures using APIs, event-driven patterns, serverless services, containers, and other cloud-native technologies.
  • Develop and operationalize capabilities supporting CSPM, CWP, SSPM, CASB, CNAPP, IAM, and related cloud security programs.
  • Engineer automated controls, workflows, integrations, compliance monitoring, remediation, metrics, and reporting that reduce risk and manual effort.
  • Evaluate and implement security technologies that advance enterprise cloud security capabilities.

Fault-Tolerant Engineering and Production Operations

  • Apply fault-tolerant coding practices, including automated testing, input validation, retries, graceful failure handling, idempotency, health checks, recovery controls, and secure error management.
  • Build logging, monitoring, alerting, and observability that improve service health, issue detection, troubleshooting, and recovery.
  • Own production reliability for assigned services and use operational data to improve resiliency, performance, and supportability.
  • Participate in the on-call rotation and provide production support, including assigned after-hours response for cloud security services and automations.
  • Lead troubleshooting, root-cause analysis, remediation, and preventive action for complex production incidents and automation failures.
  • Maintain runbooks, support procedures, service documentation, and effective operational handoffs.

DevSecOps and Policy-as-Code

  • Implement and maintain Policy-as-Code, Infrastructure-as-Code, and Security-as-Code controls throughout CI/CD pipelines and the software development lifecycle.
  • Integrate cloud and infrastructure security scanning, automated validation, testing, and deployment guardrails into engineering workflows.
  • Partner with platform and development teams to shift security left and provide timely, actionable remediation guidance.
  • Promote secure software development, code review, release management, and engineering standards for cloud security automation.

Technical Leadership and Collaboration

  • Lead complex engineering efforts from design through production operation and coordinate delivery across multiple teams.
  • Influence technical direction through architecture reviews, design recommendations, engineering patterns, and operational feedback.
  • Translate security and business requirements into scalable, supportable technical solutions.
  • Mentor engineers, review technical work, and share practices that improve engineering quality and cloud security maturity.
  • Communicate service health, risk, progress, and technical decisions through clear documentation, metrics, dashboards, and stakeholder updates.
What you have

To ensure that we have fulfilled our promise of 'challenging the status quo,' this role has specific qualifications that successful candidates should have.

Required Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related field, or equivalent practical experience.
  • 5 or more years of experience in software engineering, security engineering, cloud engineering, or a comparable technical discipline.
  • Strong development experience with Python, Java, or a comparable programming language.
  • Experience designing, building, and operating enterprise automation or cloud-native applications in production.
  • Hands-on experience with AWS, Azure, and/or GCP security controls and services.
  • Experience with cloud security technologies such as CSPM, CWP, SSPM, CASB, CNAPP, CIEM, or related platforms.
  • Experience with Infrastructure-as-Code, CI/CD pipelines, DevSecOps practices, source control, automated testing, and production observability.
  • Strong understanding of fault-tolerant design, IAM, logging, monitoring, vulnerability management, incident response, and cloud security controls.
  • Ability and willingness to participate in an on-call rotation.
  • Proven ability to troubleshoot complex issues, influence technical decisions, and communicate across teams.

Preferred Qualifications

  • Experience with Cortex Cloud, Prisma Cloud, Wiz, Orca, Lacework, or comparable cloud security platforms.
  • Experience implementing Policy-as-Code and infrastructure security scanning solutions.
  • Experience designing event-driven, serverless, containerized, or Kubernetes-based applications.
  • Experience modernizing production security platforms or automation services.
  • Experience in a highly regulated industry, preferably financial services.
  • Relevant certification such as CISSP, CCSP, CCSK, AWS Security Specialty, Azure Security Engineer, or GCP Professional Cloud Security Engineer.
  • Demonstrated success mentoring engineers and influencing architecture or engineering direction.

In addition to the salary range, this role is also eligible for bonus or incentive opportunities


What’s in it for you

At Schwab, you’re empowered to shape your future. We champion your growth through meaningful work, continuous learning, and a culture of trust and collaboration—so you can build the skills to make a lasting impact. Our Hybrid Work and Flexibility approach balances our ongoing commitment to workplace flexibility, serving our clients, and our strong belief in the value of being together in person on a regular basis.

We offer a competitive benefits package that takes care of the whole you – both today and in the future:

  • 401(k) with company match and Employee stock purchase plan
  • Paid time for vacation, volunteering, and 28-day sabbatical after every 5 years of service for eligible positions
  • Paid parental leave and family building benefits
  • Tuition reimbursement
  • Health, dental, and vision insurance
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Specialist - Security Development & Engineering
Specialist - Security Development & Engineering

The Charles Schwab Corporation • Jersey City (NJ)

On-site
USD 110,000 - 170,000
Sr Manager, Security Development & Engineering Lead
Sr Manager, Security Development & Engineering Lead

The Charles Schwab Corporation • Phoenix (AZ)

On-site
USD 180,000 - 240,000
401(k) with company match
Paid time off and sabbatical after 5+考
Parental leave and family benefits
+2
Specialist, Cloud Engineer
Specialist, Cloud Engineer

The Charles Schwab Corporation • Southlake (TX)

On-site
USD 90,000 - 140,000
Specialist - Security Development & Engineering
Specialist - Security Development & Engineering

The Charles Schwab Corporation • Lone Tree (CO)

On-site
USD 120,000 - 180,000
401(k) match
Employee stock purchase plan
Paid time off & sabbatical
Manager, Security Development & Engineering
Manager, Security Development & Engineering

The Charles Schwab Corporation • Phoenix (AZ)

On-site
USD 130,000 - 180,000
Sr. Cloud Engineer
Sr. Cloud Engineer

Charles Schwab • Austin (TX)

Hybrid
USD 140,000 - 190,000
401(k) match
Paid time off
Health insurance
Sr Specialist, Cloud Engineer
Sr Specialist, Cloud Engineer

The Charles Schwab Corporation • Austin (TX)

Hybrid
USD 120,000 - 170,000
Sr. Site Reliability Engineer
Sr. Site Reliability Engineer

Charles Schwab • Southlake (TX)

Hybrid
USD 140,000 - 180,000
401(k) with company match
Employee stock purchase plan
Paid time off + sabbatical after 5 yrs
+3
Sr Specialist, Cloud Engineer
Sr Specialist, Cloud Engineer

Charles Schwab • Austin (TX)

Hybrid
USD 120,000 - 180,000
401(k) match
Stock purchase plan
Paid vacation & volunteering
+5
Sr Specialist, Cloud Engineer
Sr Specialist, Cloud Engineer

Charles Schwab Corporation • Austin (TX)

Hybrid
USD 110,000 - 170,000
401(k) with company match
Employee stock purchase plan
Paid vacation and sabbatical after 5 y
+4