Charles Schwabposted 4 days ago
Phoenix, AZ
Securities, Commodity Contracts, and Other Financial Investments and Related Activities

About the position

At Schwab, you're empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us 'challenge the status quo' and transform the finance industry together. We are seeking a motivated Analyst to assist the Schwab Red Team by managing the firm's red team findings and vulnerability mitigation efforts. As a Cybersecurity Findings Analyst, you will be responsible for working with penetration testers to document vulnerabilities, recommendations and observations found during test efforts, work with finding owners to manage and document the progression of any mitigating controls or actions, and assist with validating the effectiveness of any mitigating controls and actions. This position offers an opportunity to actively manage and mitigate risk to the firm by ensuring the prioritization and timely mitigation of vulnerabilities and security risks. The role would be ideally suited to an individual with experience managing tasks and small projects with an interest in offensive security and includes opportunities to participate in red team exercises and penetration tests.

Responsibilities

  • Reviewing penetration test results: Thoroughly examining the data gathered by penetration testers, including identified vulnerabilities, exploitability levels, and potential attack vectors.
  • Assist with assigning severity and criticality for each vulnerability or finding, identifying recommendations and appropriate observations.
  • Work with penetration testers on documenting findings identified during test efforts.
  • Ensure findings are sufficiently detailed, clearly communicate risk, can be reproduced by stakeholders, and have appropriate evidence of exploits and recommended next steps.
  • Work with penetration testers on documenting and managing finding creation in JIRA.
  • Assist with presenting findings to stakeholders, including technical and non-technical audiences and explaining the risks in understandable terms.
  • Work with stakeholders to identify finding owners, obtain regular updates on necessary fixes and progress, and document finding mitigation efforts.
  • Document all finding management efforts in JIRA.
  • Actively monitor & document finding progress with stakeholders.
  • Work either independently or with penetration testers to reproduce penetration test findings, validate the effectiveness of mitigating controls, and document evidence of closed findings.
  • Participate in penetration tests, control tests and red team exercises.

Requirements

  • Broad familiarity with network protocols, operating systems, web application security, databases, and common vulnerabilities (OWASP/CVE).
  • Familiarity with Cybersecurity industry standards and best practices for secure system design and configuration.
  • Ability to analyze complex data, identify patterns, and draw logical conclusions about potential threats.
  • Familiarity with common approaches to risk rating such as CVE, CVSS and DREAD.
  • Clear and concise communication of technical information in a way that is easily understood by non-technical audiences.
  • Experience managing small projects, tasks, bugs or issues.
  • Identifying practical solutions to mitigate vulnerabilities and implement effective security controls.

Nice-to-haves

  • Experience in a bug, findings or vulnerability management role.
  • Relevant certifications such as CISSP, GPEN or OSCP.
  • Experience managing projects, tasks & Issues in JIRA.
  • Bachelor's degree in cybersecurity, information technology, or a related field preferred.
  • Experience with scripting and automation (e.g. Python, PowerShell, JIRA Simple Issue Language) a plus.

Benefits

  • This role is also eligible for bonus or incentive opportunities.
Hard Skills
JIRA
4
Red Teaming
3
Candidate Key
1
Information Technology
1
Python
1
3p6IeFnP9rK2 nv312MgB
0
6uGF9KnATC2J qQAkNr92
0
7kL1MDUI09 aF75Ht91s
0
80xRLs6XPy THK2yIcFa8hsvt
0
BOENRDi EHrl6ZWs
0
BtSfQ GXt5Q7PW
0
ETnUx NPd6eytiJ9K
0
Hs5SphentrYw nc1kgA3l
0
IKR7qa46cLnCG0 5T82VcWNInboEgC
0
KgLZx 5nyx4zJtmTH
0
NVx7LzZn hXuOpIs1GeL
0
Nn6rH2Bay 07Exqmcvu
0
S3NTsvkq SuaCyn7qfOQ
0
ZV72BeOwJ 7XFkmPh6zNq
0
a1QhIqol7dV R9dFNg4f
0
dSBFOpGMN ki3UJtBq
0
fsPMVd8m PsYczxt
0
k4dHeJEXSlCcxG kfsyptwdEv5
0
lKCtWH4Qs 7s1HVgixCyX
0
qAuF31vjZ 5exu7XCrhv
0
qLpfTYKB SfkXVbEtgh
0
rhvyG3xnF 6gYfSjTZ3h0
0
sD56WHn9l3F8 TMXKHwx7
0
sQtnWUzhEML LZNADWTeKnj
0
Soft Skills
ARBySp9h nJVzNrFR
0
ElXLO9yPdh2 p0QbFJL
0
VaoQq02sM c5ZGg4uHP
0
Ya6mjsvF FQMNHwJ3
0
tP8on 4RpLCWeFBvf
0
uS8faJM Xni1v4Wyr
0
Unlock 30 more keywords by signing up for Teal+Sign Up
Build your resume with AI

A Smarter and Faster Way to Build Your Resume

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service