Offensive Security Engineer (Remote)

The Charles Schwab Corp

CA(remote)

JOB DETAILS
SKILLS
Apple Macs, Applications Security, Artificial Intelligence (AI), Cloud Computing, Communication Skills, Computer Science, Computer Security, Cryptocurrency, Emulators, Finance, Financial Planning, GPEN - GIAC Penetration Tester, Incident Response, Internet Security, Linux Operating System, Malware, Microsoft Windows Operating System, Operations Control, Penetration Testing, Problem Solving Skills, Risk, Risk Analysis, Risk Management, Security Analysis, Security Attacks, Software Testing, Web Programming
LOCATION
CA
POSTED
30+ days ago

Your Opportunity

At Schwab, you're empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us "challenge the status quo" and transform the finance industry together.

We believe in the importance of in-office collaboration and fully intend for the selected candidate for this role to work on site in the specified location(s).

Schwab Technology Services enables the future of how clients manage their money by providing innovative and reliable technology products and services as part of our ongoing commitment to democratize access to investing and financial planning.

The Offensive Security Engineer scopes, designs and executes controlled cybersecurity offensive operations, penetration tests and threat adversary emulation exercises to identify vulnerabilities and risks, evaluate the effectiveness of security controls and the incident response process. The Offensive Security Engineer documents any identified risks, translates technical findings into clear, actionable recommendations and works with stakeholders to identify appropriate mitigating controls to manage any outstanding risk. The Offensive Security Engineer works closely with counterparts in defensive teams to improve threat detection and response and engineering teams to mitigate risk before it''s introduced into the environment.

  • Scope, develop and execute penetration tests, purple team assessments and red team exercises.
  • Design and develop tools, infrastructure and exploits in support of red team operations.
  • Research and implement assessments based on emerging threats, threat intelligence, and vulnerabilities.
  • Identify gaps in threat detection, Prevention and response.
  • Work collaboratively with counterparts in Cyber Defense roles to enhance the firms security posture.
  • Effectively communicate vulnerabilities, risks and technical findings to stakeholders and work with stakeholders to recommend and validate mitigating controls.

What you have

Required Qualifications

  • 5+ years of experience in offensive security, penetration testing or red team role.
  • Experience with common red team adversary emulation tooling and C2 frameworks.
  • Advanced knowledge of the tools, tactics, procedures and counter measures.
  • Experience researching emerging threats and TTP''s, developing complementary assessments, and executing those assessments to understand and manage risk and develop appropriate counter measures.
  • Experience evaluating, reporting and communicating risk at both the technical level (ATT&CK/STRIDE/DREAD) and at an audience appropriate level with stakeholders across the firm.
  • Experience working with cross-discipline project teams to advance security within the firm.
  • In-depth experience with one or more of the following cybersecurity disciplines: Endpoint Penetration testing with a focus on bypassing modern EDR controls (across Windows, Mac and Linux), Exploit & Malware Development, Web Application Penetration Testing, Cloud Penetration Testing, AI Red Teaming, and Assessing digital assets and cryptocurrency solutions.

Preferred Qualifications

  • One or more of the following security certifications preferred: Offensive Security Certified Professional OSCP, GIAC Penetration Tester GPEN, GXPN Offensive Security Certified Professional or similar security certification(s).
  • BS in Computer Science or equivalent degree/experience desired.
  • Operational blue team experience.

About the Company

T

The Charles Schwab Corp

The Charles Schwab Corporation is a leading provider of financial services, with more than 300 offices. Through its operating subsidiaries, the company provides a full range of securities brokerage, banking, money management and financial advisory services to individual investors and independent investment advisors. Named "Highest in Investor Satisfaction with Self-Directed Services" by J.D. Power and Associates in 2009, its broker-dealer subsidiary, Charles Schwab & Co., Inc. (member SIPC) affiliates offer a complete range of investment services and products including an extensive selection of mutual funds; financial planning and investment advice; retirement plan and equity compensation plan services; referrals to independent fee-based investment advisors; and custodial, operational and trading support for independent, fee-based investment advisors through Schwab Advisor Services.

The Charles Schwab Bank (member FDIC) provides banking and mortgage services and products. To meet the needs of our clients, we are actively recruiting people with the desire, drive and creativity to find solutions that help meet our clients' needs; who want the chance to learn, grow with the company and explore their career opportunities; who will strive for excellence in achieving our clients' and our company's goals; who have the highest ethical standards - individuals who take pride in making a difference in people's lives.
COMPANY SIZE
1,000 to 1,499 employees
INDUSTRY
Security and Surveillance
FOUNDED
1971
WEBSITE
http://www.aboutschwab.com/careers