Sr Specialist Security Development & Engineering
Your Opportunity
Schwab remains committed to providing increased visibility to career growth opportunities and job requirements. This posting announcement is part of increased transparency and while all qualified applicants will be reviewed and considered, this organization has a preferred candidate identified for this role.
At Schwab, you’re empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us “challenge the status quo” and transform the finance industry together.
We believe in the importance of in-office collaboration and fully intend for the selected candidate for this role to work on site in the specified location.
As a Cloud Security Automation Engineer, you will design, build, and operate enterprise cloud security solutions across AWS, Azure, GCP, and SaaS environments.
This senior individual contributor role combines cloud-native software engineering, policy-as-code, platform modernization, and production ownership. You will lead complex technical efforts, influence architecture and engineering practices, and partner across security, infrastructure, and application teams to reduce risk and improve cloud security maturity.
Cloud Security Automation and Architecture
- Design, build, deploy, and operate fault-tolerant cloud security automation and cloud-native services across AWS, Azure, GCP, and SaaS environments.
- Modernize legacy or monolithic automations into scalable, maintainable architectures using APIs, event-driven patterns, serverless services, containers, and other cloud-native technologies.
- Develop and operationalize capabilities supporting CSPM, CWP, SSPM, CASB, CNAPP, IAM, and related cloud security programs.
- Engineer automated controls, workflows, integrations, compliance monitoring, remediation, metrics, and reporting that reduce risk and manual effort.
- Evaluate and implement security technologies that advance enterprise cloud security capabilities.
Fault-Tolerant Engineering and Production Operations
- Apply fault-tolerant coding practices, including automated testing, input validation, retries, graceful failure handling, idempotency, health checks, recovery controls, and secure error management.
- Build logging, monitoring, alerting, and observability that improve service health, issue detection, troubleshooting, and recovery.
- Own production reliability for assigned services and use operational data to improve resiliency, performance, and supportability.
- Participate in the on-call rotation and provide production support, including assigned after-hours response for cloud security services and automations.
- Lead troubleshooting, root-cause analysis, remediation, and preventive action for complex production incidents and automation failures.
- Maintain runbooks, support procedures, service documentation, and effective operational handoffs.
DevSecOps and Policy-as-Code
- Implement and maintain Policy-as-Code, Infrastructure-as-Code, and Security-as-Code controls throughout CI/CD pipelines and the software development lifecycle.
- Integrate cloud and infrastructure security scanning, automated validation, testing, and deployment guardrails into engineering workflows.
- Partner with platform and development teams to shift security left and provide timely, actionable remediation guidance.
- Promote secure software development, code review, release management, and engineering standards for cloud security automation.
Technical Leadership and Collaboration
- Lead complex engineering efforts from design through production operation and coordinate delivery across multiple teams.
- Influence technical direction through architecture reviews, design recommendations, engineering patterns, and operational feedback.
- Translate security and business requirements into scalable, supportable technical solutions.
- Mentor engineers, review technical work, and share practices that improve engineering quality and cloud security maturity.
- Communicate service health, risk, progress, and technical decisions through clear documentation, metrics, dashboards, and stakeholder updates.
What you have
To ensure that we have fulfilled our promise of "challenging the status quo," this role has specific qualifications that successful candidates should have.
Required Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related field, or equivalent practical experience.
- 5 or more years of experience in software engineering, security engineering, cloud engineering, or a comparable technical discipline.
- Strong development experience with Python, Java, or a comparable programming language.
- Experience designing, building, and operating enterprise automation or cloud-native applications in production.
- Hands-on experience with AWS, Azure, and/or GCP security controls and services.
- Experience with cloud security technologies such as CSPM, CWP, SSPM, CASB, CNAPP, CIEM, or related platforms.
- Experience with Infrastructure-as-Code, CI/CD pipelines, DevSecOps practices, source control, automated testing, and production observability.
- Strong understanding of fault-tolerant design, IAM, logging, monitoring, vulnerability management, incident response, and cloud security controls.
- Ability and willingness to participate in an on-call rotation.
- Proven ability to troubleshoot complex issues, influence technical decisions, and communicate across teams.
Preferred Qualifications
- Experience with Cortex Cloud, Prisma Cloud, Wiz, Orca, Lacework, or comparable cloud security platforms.
- Experience implementing Policy-as-Code and infrastructure security scanning solutions.
- Experience designing event-driven, serverless, containerized, or Kubernetes-based applications.
- Experience modernizing production security platforms or automation services.
- Experience in a highly regulated industry, preferably financial services.
- Relevant certification such as CISSP, CCSP, CCSK, AWS Security Specialty, Azure Security Engineer, or GCP Professional Cloud Security Engineer.
- Demonstrated success mentoring engineers and influencing architecture or engineering direction.
In addition to the salary range, this role is also eligible for bonus or incentive opportunities
What’s in it for you
At Schwab, you’re empowered to shape your future. We champion your growth through meaningful work, continuous learning, and a culture of trust and collaboration—so you can build the skills to make a lasting impact. Our Hybrid Work and Flexibility approach balances our ongoing commitment to workplace flexibility, serving our clients, and our strong belief in the value of being together in person on a regular basis.
We offer a competitive benefits package that takes care of the whole you – both today and in the future:
- 401(k) with company match and Employee stock purchase plan
- Paid time for vacation, volunteering, and 28-day sabbatical after every 5 years of service for eligible positions
- Paid parental leave and family building benefits
- Tuition reimbursement
- Health, dental, and vision insurance