Specialist - Security Analytics & Operations
Your Opportunity
Schwab remains committed to providing increased visibility to career growth opportunities and job requirements. This posting announcement is part of increased transparency and while all qualified applicants will be reviewed and considered, this organization has a preferred candidate identified for this role.
At Schwab, you’re empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us “challenge the status quo” and transform the finance industry together.
We believe in the importance of in-office collaboration and fully intend for the selected candidate for this role to work on site in the specified location.
This Business Analyst supports the end-to-end onboarding of enterprise applications into SailPoint IdentityIQ (IIQ). The role partners with application owners, security teams, IAM engineering, operations, risk, and compliance stakeholders to research applications, gather and validate business and technical requirements, identify the appropriate integration method, and define roles, entitlements, approvals, ownership, provisioning, reconciliation, authentication, and certification needs. The analyst maintains complete, traceable requirements and project artifacts; coordinates peer review, development handoff, user acceptance testing, production readiness, and post-production validation; and ensures each integration is delivered in accordance with identity governance, security, audit, and operational standards.
- Lead multiple application onboarding efforts through business intake, technical intake, requirements approval, development, testing, production deployment, and post-production validation
- Research application architecture, business purpose, current access model, existing IGA integrations, user populations, and provisioning and reconciliation processes
- Facilitate discovery sessions, application demonstrations, and stakeholder workshops to capture complete business, security, and technical requirements
- Assess and document feasible integration methods, including Active Directory, LDAP, JDBC, REST or web services, flat file, SaaS connectors, and disconnected or IAM-managed patterns
- Define and document account schemas, identity correlation attributes, roles, entitlements, role-to-entitlement mappings, requestability, risk classifications, descriptions, ownership, approval workflows, and certification requirements
- Document authentication and authorization methods, SSO dependencies, custom forms, lifecycle events, single- versus multi-entitlement behavior, and provisioning and deprovisioning use cases
- Validate user and entitlement data, identify cleanup or migration needs, and define how account aggregation and reconciliation will be performed and evidenced
- Translate approved requirements into actionable Jira stories and acceptance criteria; maintain status, risks, decisions, dependencies, approvals, and audit evidence in designated repositories
- Partner with SailPoint engineers to resolve requirement gaps, validate connector configuration details, and support development across lower environments
- Plan and execute user acceptance testing for access requests, approvals, provisioning, modifications, revocation, aggregation, reconciliation, and entitlement metadata; document findings and coordinate defect resolution
- Obtain documented application-owner approval, coordinate production readiness and decommissioning activities, and validate production accounts, entitlements, metadata, and user data against approved requirements
- Identify opportunities to standardize, simplify, and automate onboarding activities while preserving security, compliance, and auditability
What you have
To ensure that we have fulfilled our promise of "challenging the status quo," this role has specific qualifications that successful candidates should have.
Required Qualifications
- Two or more years of experience in business analysis, identity and access management, cybersecurity, application integration, or a related discipline
- Demonstrated experience eliciting, analyzing, documenting, validating, and managing business and technical requirements through implementation
- Working knowledge of identity governance concepts, including access requests, roles, entitlements, approvals, provisioning, deprovisioning, aggregation, reconciliation, certifications, and least privilege
- Ability to analyze application access models and translate business needs into complete, testable requirements for SailPoint engineers
- Familiarity with common integration patterns such as Active Directory or LDAP, JDBC or SQL, REST or SOAP APIs, flat files, and SaaS connectors
- Experience developing test scenarios, coordinating UAT, documenting evidence, managing defects, and obtaining stakeholder signoff
- Strong written and verbal communication skills, with the ability to explain identity, security, and risk concepts to technical and non-technical audiences
- Strong analytical, organizational, problem-solving, facilitation, prioritization, and stakeholder-management skills
- Experience using Jira or a comparable work-management platform and Microsoft Office applications, particularly Excel, Word, PowerPoint, and Visio
- Ability to manage multiple onboarding efforts and maintain accurate, audit-ready documentation in a fast-paced, cross-functional environment
Preferred Qualifications
- Bachelor’s degree in business, information systems, cybersecurity, computer science, or a related field, or equivalent experience
- Experience with SailPoint IdentityIQ, SailPoint Identity Security Cloud, Oracle Identity Manager, or another enterprise IGA platform
- Experience onboarding applications, defining entitlement catalogs, supporting account correlation, or migrating integrations from a legacy IGA platform
- Working knowledge of SQL, directory services, APIs, authentication protocols, SSO, RBAC, and access certification processes
- Experience in financial services or another highly regulated industry
- Relevant credentials such as SailPoint training or certification, Security+, CBAP, PMI-PBA, CISA, or CISM
In addition to the salary range, this role is also eligible for bonus or incentive opportunities
What’s in it for you
At Schwab, you’re empowered to shape your future. We champion your growth through meaningful work, continuous learning, and a culture of trust and collaboration—so you can build the skills to make a lasting impact. Our Hybrid Work and Flexibility approach balances our ongoing commitment to workplace flexibility, serving our clients, and our strong belief in the value of being together in person on a regular basis.
We offer a competitive benefits package that takes care of the whole you – both today and in the future:
- 401(k) with company match and Employee stock purchase plan
- Paid time for vacation, volunteering, and 28-day sabbatical after every 5 years of service for eligible positions
- Paid parental leave and family building benefits
- Tuition reimbursement
- Health, dental, and vision insurance