Cybersecurity Findings Analyst Job at Charles Schwab, Phoenix, AZ

ZkFHSHhnUjRxZlNBU3l5MDByZlc4Z3pLL2c9PQ==
  • Charles Schwab
  • Phoenix, AZ

Job Description

**Your opportunity** At Schwab, you're empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us "challenge the status quo" and transform the finance industry together. We are seeking a motivated Analyst to assist the Schwab Red Team by managing the firm's red team findings and vulnerability mitigation efforts. As a Cybersecurity Findings Analyst, you will be responsible for working with penetration testers to document vulnerabilities, recommendations and observations found during test efforts, work with finding owners to manage and document the progression of any mitigating controls or actions, and assist with validating the effectiveness of any mitigating controls and actions. This position offers an opportunity to actively manage and mitigate risk to the firm by ensuring the prioritization and timely mitigation of vulnerabilities and security risks. The role would be ideally suited to an individual with experience managing tasks and small projects with an interest in offensive security and includes opportunities to participate in red team exercises and penetration tests. What you'll do: **Reviewing penetration test results:** Thoroughly examining the data gathered by penetration testers, including identified vulnerabilities, exploitability levels, and potential attack vectors. Assist with assigning severity and criticality for each vulnerability or finding, identifying recommendations and appropriate observations, **Reporting & Deliverables:** Work with penetration testers on documenting findings identified during test efforts. Ensure findings are sufficiently detailed, clearly communicate risk, can be reproduced by stakeholders, and have appropriate evidence of exploits and recommended next steps. Work with penetration testers on documenting and managing finding creation in JIRA. **Communication and collaboration:** Assist with presenting findings to stakeholders, including technical and non-technical audiences and explaining the risks in understandable terms. Work with stakeholders to identify finding owners, obtain regular updates on necessary fixes and progress, and document finding mitigation efforts. Work with peer teams to refer, manage and escalate findings as appropriate. **Finding Management:** Document all finding management efforts in JIRA. Work to maintain finding quality and reporting. Actively monitor & document finding progress with stakeholders. **Testing & Validation:** Work either independently or with penetration testers to reproduce penetration test findings, validate the effectiveness of mitigating controls, and document evidence of closed findings. Participate in penetration tests, control tests and red team exercises. **What you have** To ensure that we have fulfilled our promise of "challenging the status quo," this role has specific qualifications that successful candidates should have. **Key Competencies:** + Strong communication skills. + Strong analytical and critical thinking skills. + Detail-oriented, self-driven, and capable of working independently in a fast-paced environment. **Required Qualifications:** Technical expertise: Broad familiarity with network protocols, operating systems, web application security, databases, and common vulnerabilities (OWASP/CVE). Familiarity with Cybersecurity industry standards and best practices for secure system design and configuration. Analytical skills: Ability to analyze complex data, identify patterns, and draw logical conclusions about potential threats. Familiarity with common approaches to risk rating such as CVE, CVSS and DREAD. Report writing Skills: Clear and concise communication of technical information in a way that is easily understood by non-technical audiences. Project Management Skills: Experience managing small projects, tasks, bugs or issues. Problem-solving skills: Identifying practical solutions to mitigate vulnerabilities and implement effective security controls. **Preferred** + Experience in a bug, findings or vulnerability management role. + Relevant certifications such as CISSP, GPEN or OSCP. + Experience managing projects, tasks & Issues in JIRA. + Bachelor's degree in cybersecurity, information technology, or a related field preferred. + Experience with scripting and automation (e.g. Python, PowerShell, JIRA Simple Issue Language) a plus. In addition to the salary range, this role is also eligible for bonus or incentive opportunities **What's in it for you** At Schwab, we're committed to empowering our employees' personal and professional success. Our purpose-driven, supportive culture, and focus on your development means you'll get the tools you need to make a positive difference in the finance industry. Our Hybrid Work and Flexibility approach balances our ongoing commitment to workplace flexibility, serving our clients, and our strong belief in the value of being together in person on a regular basis. We offer a competitive benefits package that takes care of the whole you - both today and in the future: + 401(k) with company match and Employee stock purchase plan + Paid time for vacation, volunteering, and 28-day sabbatical after every 5 years of service for eligible positions + Paid parental leave and family building benefits + Tuition reimbursement + Health, dental, and vision insurance What's in it for you: At Schwab, we're committed to empowering our employees' personal and professional success. Our purpose-driven, supportive culture, and focus on your development means you'll get the tools you need to make a positive difference in the finance industry. Our Hybrid Work and Flexibility approach balances our ongoing commitment to workplace flexibility, serving our clients, and our strong belief in the value of being together in person on a regular basis. We offer a competitive benefits package that takes care of the whole you - both today and in the future: 401(k) with company match and Employee stock purchase plan Paid time for vacation, volunteering, and 28-day sabbatical after every 5 years of service for eligible positions Paid parental leave and family building benefits Tuition reimbursement Health, dental, and vision insurance Schwab is an affirmative action employer, focused on employing and advancing in employment, qualified women, racial and ethnic minorities, protected veterans, and individuals with disabilities in the workplace. If you have a disability and require reasonable accommodations in the application process, contact Human Resources at applicantaccessibility@schwab.com or call 800-275-1281.

Job Tags

Similar Jobs

Mahway

Virtual Assistant - Bench Job at Mahway

 ...were not hiring just yet, were on the lookout for amazing virtual assistants to join our talent pool and support our future founders, CEOs...  ...our upcoming ventures! Required At least 3+ years of experience supporting executives Ability to work on a North American... 

Patient Funding Alternatives

Patient Advocate - Las Vegas, NV Job at Patient Funding Alternatives

 ...Patient Advocate Valley Health System Spring Valley & Henderson Campuses, Las Vegas, NV ChasmTeam is partnering with a growing national company, to build a team that provides real benefits to patients! We are seeking hard working, self starters who enjoy a... 

Xcell Biosciences

OFFICE MANAGER Job at Xcell Biosciences

Xcellbio is a venture-backed immuno-oncology focused biotechnology company based in San Francisco, CA. Backed by industry-leading investors and strategic partners, our mission is focused on pushing forward the leading edge of cancer therapy with the goal of not just delaying...

Well & Being Spa - The Hythe Vail

Hair Stylist Job at Well & Being Spa - The Hythe Vail

 ...comprehensive and professional hair services and treatments, adhering to company SOPs and brand standards. Performs hair services offered on salon menu, using proper techniques, while maintaining the highest level of professionalism. Effectively communicates with guests to... 

CDC Small Business Finance

Loan Officer (LA Market) Job at CDC Small Business Finance

 ...knowledge, and social capita l , we offer a comprehensive package of loan products, impact investment opportunities, training and business...  ... and our country thrive. Position Summary The Loan Officer is responsible for developing loan prospects within a defined...