1,126,894open jobs
64,937companies
197,948added this week
Browse all
Salary
$110k – $135k per year
Location
Hybrid (Omaha, United States)
Seniority
Junior · 2+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 3, 2026. First seen by Alion on Oct 3, 2026. Charles Schwab scores B on the Alion truth index.

Overview
Company
Impact
Profile match
Charles Schwab is a financial services company headquartered in Westlake, Texas, near Fort Worth, offering brokerage and retirement accounts, online trading through the thinkorswim platform, banking, wealth management, financial planning and custody services for independent investment advisors. Founded in 1971 and listed on the New York Stock Exchange, it serves retail investors through branches nationwide and runs large operations and technology centers in Austin, Southlake, Omaha, Phoenix, El Paso and Hyderabad. It hires software and DevOps engineers, data engineers, product managers, financial consultants, client service representatives, risk, audit and compliance professionals.

Your opportunity

The Schwab Application Security team, operating under the leadership of the Chief Information Security Officer (CISO), is responsible for protecting Schwab’s information assets in support of business objectives and in alignment with corporate policies. As a core function within Cybersecurity Services, the Application Security team leads the establishment and ongoing evolution of Schwab’s Secure Software Development Program. This includes the creation and implementation of software security policies and best practices, providing security architecture guidance, conducting software security scanning and penetration testing, and educating developers and testers on secure coding practices.

The Software Security Engineer plays a key role in safeguarding software assets by strengthening the development process, enhancing security controls, and reducing defects and vulnerabilities in production environments.

Successful candidates will have prior engineering experience within a Software Security Assurance or Application Security team and a proven ability to partner effectively with development teams to balance security requirements with innovation. They will demonstrate strong analytical skills, including the ability to interpret large volumes of distributed data and translate it into clear, actionable insights. Candidates should also have experience working with a range of application security tools, including Software Composition Analysis (SCA), Static Application Security Testing (SAST), and secrets management solutions.

In addition, candidates will bring solid application engineering experience and a strong understanding of common application vulnerabilities, attack vectors, and remediation strategies. They should be familiar with secure software design principles and industry best practices for integrating security into the software development lifecycle. Experience with application security testing tools, such as Fortify, and their integration into agile development environments is expected.

Candidates should have familiarity with recognized industry frameworks and standards such as OWASP, CIS, and NIST. A minimum of two years of experience working with static analysis or threat modeling tools is expected, along with experience implementing and scaling enterprise application security tools, services, and controls. Finally, candidates must demonstrate a strong understanding of secure coding practices, code review processes, threat modeling, security requirements analysis, and architectural risk assessment.

What you have

Preferred Qualifications

Python Automation & API Integration

  • Strong proficiency in designing Python-based automation for large-scale REST API integrations, including repository management, content discovery, workflow orchestration, and encoded file handling across enterprise source-control platforms.
  • Custom CodeQL Query Development
  • Strong understanding of CodeQL query authoring concepts, including QL pack management, database creation, dependency resolution via --search-path, and techniques for minimizing false positives through boundary analysis and source/sink filtering.
  • GitHub Advanced Security (GHAS) Platform Engineering
  • Deep familiarity with GitHub Advanced Security capabilities, including Code Scanning, Secret Scanning, Dependency Review, custom query configuration, and scalable alert triage and remediation workflows across multiple repositories.

CI/CD Pipeline Architecture (GitHub Actions)

  • Demonstrated expertise in architecting reusable and scalable CI/CD workflows using GitHub Actions, including callable workflows, matrix strategies, cross-repository authentication models, and centralized pipeline governance.

SARIF Output Analysis & Interpretation

  • Strong knowledge of the SARIF specification and its use in static analysis pipelines, including interpreting results, validating findings, identifying false positives, and enabling automated reporting across diverse codebases.

Enterprise Git Workflow & Release Management

  • Experience designing and governing enterprise Git workflows, including structured branching strategies, release coordination, branch protection rules, cross-organization pull requests, and versioning policy enforcement.

Application Security Vulnerability Engineering

  • Solid understanding of common software weakness classes and the intentional design of vulnerable code patterns to validate static analysis coverage, detection accuracy, and severity classification.

Multi-Repository Architecture & Configuration Delivery

  • Proven ability to architect centralized configuration and workflow distribution models for large repository ecosystems, including reusable workflows, configuration validation, and scalable authentication mechanisms.

Enterprise Package Registry & Dependency Governance

  • Strong knowledge of internal package ecosystems and dependency governance, including artifact repository configuration, registry enforcement and blocking strategies, and controlled use of vulnerable dependencies for security testing.

Technical Documentation & Architecture Decision Records

  • Excellent written communication skills with experience producing high-quality technical documentation, including Architecture Decision Records (ADRs), onboarding guides, and operational runbooks for cross-functional engineering teams.

What’s in it for you

At Schwab, you’re empowered to shape your future. We champion your growth through meaningful work, continuous learning, and a culture of trust and collaboration-so you can build the skills to make a lasting impact. Our Hybrid Work and Flexibility approach balances our ongoing commitment to workplace flexibility, serving our clients, and our strong belief in the value of being together in person on a regular basis.

We offer a competitive benefits package that takes care of the whole you - both today and in the future:

  • 401(k) with company match and Employee stock purchase plan
  • Paid time for vacation, volunteering, and 28-day sabbatical after every 5 years of service for eligible positions
  • Paid parental leave and family building benefits
  • Tuition reimbursement
  • Health, dental, and vision insurance
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,126,894 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Omaha
IT Security Analyst II 3 months ago
≈ $87k – $180k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Webster
DevOps
TCP/IP
Cybersecurity
SIEM
Apply
$107k – $156k per year • In office • Full-Time • 2+ years exp • Bachelor's Degree • Folsom
Java
C++
DevOps
Linux
Windows
Cybersecurity
GDPR
Threat Modeling
PKI
Apply
$124k – $186k per year • Equity • In office • Full-Time • 5+ years exp • Bachelor's Degree • Seattle
Java
PowerShell
AI/ML
AI Agents
Frontend
GraphQL
DevOps
Rest API
Azure
IAM
Cybersecurity
GDPR
Least Privilege
Microsoft Entra ID
Auth0
Active Directory
LDAP
Management
Agile
Apply
$65k – $85k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Chicago
Apply
≈ $71k – $153k per year (Estimated) • Hybrid • 1+ year exp • Lafayette
Cybersecurity
NIST CSF
SOC 2
HIPAA
FedRAMP
Microsoft Entra ID
Apply
Data Engineer 2 days ago
$125k – $140k per year • Equity • Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Austin
Python
Java
SQL
Java
Liquibase
Databases
Google BigQuery
BigQuery
DevOps
GCP
GitHub
Analytics
ETL/ELT
Informatica
Dimensional Modeling
Management
Jira
Agile
Apply
$151k – $205k per year • Equity • Hybrid • Full-Time • Bachelor's Degree • Austin
JavaScript
TypeScript
SQL
C#
C#
.NET
Frontend
Angular
Management
Agile
Scrum
Apply
Software Developer 2 days ago
$130k – $150k per year • Equity • Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Austin
Java
SQL
COBOL
Java
Spring Boot
COBOL
CICS
JCL
IBM MQ
Databases
Db2
RabbitMQ
Apache Kafka
AI/ML
Copilot
Claude Code
DevOps
Splunk
GCP
Dynatrace
Azure
CI/CD
Grafana
AppDynamics
Linux
Unix
Management
Agile
Apply
Java Developer 2 days ago
$126k – $140k per year • Equity • Hybrid • Full-Time • 3+ years exp • Austin
Java
C#
Java
Spring Framework
C#
.NET
Databases
PostgreSQL
Aerospike
RabbitMQ
AI/ML
Copilot
Claude Code
Prompt Engineering
Agentic Workflows
DevOps
Rest API
GCP
CI/CD
Git
AWS
Bamboo
Bitbucket
SOAP
Analytics
ETL/ELT
Management
Agile
Apply
$96k – $106k per year • Equity • Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Austin
JavaScript
Java
TypeScript
Java
Spring Boot
Databases
PostgreSQL
RabbitMQ
Apache Kafka
AI/ML
Copilot
Frontend
Angular
DevOps
Splunk
GitHub Actions
CI/CD
Git
Twelve-Factor App
AppDynamics
Bamboo
GitHub
SOAP
Management
Agile
Scrum
Apply
Security Engineer 2 days ago
$100k – $120k per year • Equity • Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Omaha
DevOps
Windows Server
Platform Engineering
Windows
Management
Confluence
Jira
Power Automate
ITIL
Apply
$63k – $70k per year • In office • Internship • Bachelor's Degree • Austin
Apply
$102k – $110k per year • Equity • Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Southlake
Databases
MS SQL
Management
Power Automate
Power Apps
Agile
Kanban
Apply
$125k – $160k per year • Equity • Hybrid • Full-Time • 5+ years exp • Austin
Python
JavaScript
C#
AI/ML
AI Agents
LLM Guardrails
NIST AI RMF
Machine Learning
DevOps
CI/CD
Platform Engineering
Cybersecurity
OWASP Top 10
Threat Modeling
Apply
$135k – $165k per year • Equity • Hybrid • Full-Time • Austin
Apply
≈ $34k – $71k per year (Estimated) • In office • Full-Time • 2+ years exp • Associate's Degree • Omaha
Apply
$41k – $66k per year • In office • Full-Time • 1+ year exp • High School Diploma • Omaha
Management
Microsoft Office
Apply
≈ $71k – $178k per year (Estimated) • In office • Bachelor's Degree • Omaha
Management
Outlook
Microsoft Office
Apply
≈ $32k – $64k per year (Estimated) • Equity • In office • Part-Time • 1+ year exp • High School Diploma • Omaha
Management
Microsoft Office
Apply
≈ $36k – $84k per year (Estimated) • In office • Full-Time • Omaha
Apply
See all jobs
This is one of many
1,126,894 more open roles from verified company boards, updated every day.