- Career Center Home
- Search Jobs
- Application Security Analyst
Results
Job Details
Explore Location
Schwab
Southlake, Texas, United States
(on-site)
Posted
21 hours ago
Schwab
Southlake, Texas, United States
(on-site)
Job Type
Full-Time
Application Security Analyst
The insights provided are generated by AI and may contain inaccuracies. Please independently verify any critical information before relying on it.
Application Security Analyst
The insights provided are generated by AI and may contain inaccuracies. Please independently verify any critical information before relying on it.
Description
Your OpportunityAt Schwab, you're empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us "challenge the status quo" and transform the finance industry together.
We believe in the importance of in-office collaboration and fully intend for the selected candidate for this role to work on site in the specified location(s).
As an entry-level Application Security Engineer, you'll help build security into our software from design through delivery. You'll partner with developers and product teams to identify and remediate vulnerabilities, support dynamic application security testing (DAST), and strengthen API security controls. You'll use foundational programming knowledge in Java and .NET to understand how issues appear in code and how to fix them efficiently.
You'll operate within Schwab's Secure Application Development Standard and leverage our AppSec services to "shift left" and continuously improve our security posture.
Key Responsibilities
- Perform and support DAST (e.g., running scans, triaging findings, and retesting after fixes) for web and API-based services; collaborate with engineering to prioritize and remediate issues.
- Apply OWASP Top 10 knowledge to identify common vulnerability categories (e.g., broken access control, injection, SSRF) and advise teams on secure patterns
- Strengthen API security by participating in inventory, vulnerability triage, and testing activities aligned to our program approach.
- Partner with developers to reproduce findings, review fixes, and validate remediation-using your understanding of Java/.NET code paths, frameworks, and typical anti-patterns.
- Support "shift-left" practices by integrating AppSec tooling into build pipelines and promoting developer experience best practices (e.g., automation, workflow orchestration).
- Document vulnerabilities, remediation steps, and residual risk; contribute to secure coding guides and internal knowledge bases.
- Monitor and follow up on open issues; help coordinate cross-team actions during security test cycles and release gating
- Maintain accurate documentation of security findings, remediation status, and communications with stakeholders.
- Contribute to continuous improvement of application security processes and tooling.
What you have
Required Qualifications
- Exposure to OWASP Top 10 concepts and practical examples (web & API).
- Hands-on familiarity with DAST workflows and tools (running scans, reading reports, working with developers to fix).
- API Security fundamentals (authentication/authorization, rate limiting, schema validation, common API risk scenarios, common API technologies; REST, SOAP, GraphQL).
- Programming fundamentals in Java and .NET (e.g., HTTP request/response, input validation, authN/authZ, secure configuration).
- Understanding of SDLC and DevSecOps basics (version control, CI/CD, unit/integration testing).
- Clear written and verbal communication; ability to explain findings to non-security stakeholders.
Preferred Qualifications
- Coursework, projects, or internships involving secure coding, code review, or vulnerability remediation in Java/.NET.
- Familiarity with AppSec tooling including common DAST capabilities, BURP Suite, and development tools.
- Exposure to API security testing approaches (linting, governed specs/OpenAPI, risk profiling, and CI integration).
- Participation in security labs or events (e.g., OWASP workshops, cyber ranges).
- Bachelor's Degree in a relevant field, (Computer Science, MIS, Cyber Security).
- Certifications including CEH, Security+, OSCP
Requisition #: 2026-118168
r1d4rh5eu
Requirements
2026-118168
Job ID: 82011891

Schwab
United States
Schwab is a leader in financial services, helping millions of people make the most of their money. Most Schwab careers are based in one of our two main operating segments, Investor Services or Institutional Services. But across the entire Schwab organization, more than 12,000 employees share a passion for fulfilling our corporate purpose: to help everyone be financially fit.
View Full Profile
More Jobs from Schwab
Container Platform Engineer
Austin, Texas, United States
21 hours ago
Senior Manager, Business Unit Risk - Premier Bank Digital Assets
Westlake, Texas, United States
21 hours ago
VP, Financial Consultant- Pleasanton, CA
Pleasanton, California, United States
21 hours ago
Jobs You May Like
Community Intel Unavailable
Details for Southlake, Texas, United States are unavailable at this time.
Loading...
