Charles Schwab
Senior Security Engineer – Public Key Infrastructure (PKI)
At Schwab, you’re empowered to make an impact on your career. Innovative thought meets creative problem solving here, helping us “challenge the status quo” and transform the finance industry together.
We believe in the importance of in‑office collaboration and fully intend for the selected candidate to work on site in the specified location(s).
The Senior Security Engineer of the Public Key Infrastructure (PKI) team will play a key role on a team of cyber‑security data‑protection subject‑matter experts and engineers to create, implement, and maintain PKI controls using on‑prem, SaaS, and IaaS cloud‑based solutions to reduce risk and enforce Schwab’s security policies and standards for data protection. You are a driven senior engineer with a deep passion to be an accelerator and change agent with the ability to build a security community and progressive Dev/SEC/Op’s culture.
Responsibilities
Perform senior engineering responsibilities as part of a team and work with partners to architect and deploy PKI infrastructure, including Certificate Authorities (CAs), Registration Authorities (RAs), and Hardware Security Modules (HSMs).
Implement and maintain the issuance and management of digital certificates for users, servers, and devices across the organization.
Define certificate lifecycle management policies (issuance, renewal, revocation).
Integrate PKI with other security systems like authentication and access control mechanisms.
Conduct regular security assessments and audits of PKI systems to identify vulnerabilities and potential risks.
Work with other IT teams to integrate PKI solutions into existing systems and applications.
Maintain close ties to various stakeholders, developers, and engineers across the company, ensuring the services we create meet their needs as products evolve.
Communicate extensively with Data Protection Product and engineering teams across the organization.
Drive complex technical initiatives to full delivery leveraging knowledge of cyber‑security practices, software engineering principles, agile frameworks, and customer engagement.
Design, build, and maintain infrastructure to meet the organization’s requirements and ensure high availability.
Apply adept understanding and experience with systems automation platforms and technologies.
Required Qualifications
5+ years of hands‑on experience in network security, data security, and/or other cyber‑security‑related controls and technologies.
Automation via Certificate Lifecycle Management tools using scripting and coding (Venafi, PowerShell, and Python knowledge required; GitHub and .Net knowledge highly desired).
Bachelor’s Degree in computer science or related field highly preferred.
Ability to foster collaborative, open, working relationships with technology groups and other stakeholders, including vendor relationships.
Clear communication skills and ability to interact effectively at multiple levels of an organization, and to influence leadership (including translating technical information based on specific audiences).
Experience implementing multiple high‑visibility and high‑impact enterprise cyber‑security projects with cross‑functional teams while maintaining superior results including planning, development and management of technical requirements, design, testing and deployment of security solutions.
Strong understanding of Public Key Infrastructure (PKI) principles.
Expertise in PKI technologies like Microsoft Active Directory Certificate Services (AD CS), Entrust, Venafi, or other commercial PKI solutions.
Experience with managing Hardware Security Modules (HSMs).
Preferred Qualifications
Multiple certifications in cyber‑security and data protection (CISSP, GIAC, CISM, CCSP, CISA, Security+, or other related certifications).
Benefits
401(k) with company match and Employee stock purchase plan
Paid time for vacation, volunteering, and 28‑day sabbatical after every 5 years of service for eligible positions
Paid parental leave and family building benefits
Tuition reimbursement
Health, dental, and vision insurance
#J-18808-Ljbffr
We believe in the importance of in‑office collaboration and fully intend for the selected candidate to work on site in the specified location(s).
The Senior Security Engineer of the Public Key Infrastructure (PKI) team will play a key role on a team of cyber‑security data‑protection subject‑matter experts and engineers to create, implement, and maintain PKI controls using on‑prem, SaaS, and IaaS cloud‑based solutions to reduce risk and enforce Schwab’s security policies and standards for data protection. You are a driven senior engineer with a deep passion to be an accelerator and change agent with the ability to build a security community and progressive Dev/SEC/Op’s culture.
Responsibilities
Perform senior engineering responsibilities as part of a team and work with partners to architect and deploy PKI infrastructure, including Certificate Authorities (CAs), Registration Authorities (RAs), and Hardware Security Modules (HSMs).
Implement and maintain the issuance and management of digital certificates for users, servers, and devices across the organization.
Define certificate lifecycle management policies (issuance, renewal, revocation).
Integrate PKI with other security systems like authentication and access control mechanisms.
Conduct regular security assessments and audits of PKI systems to identify vulnerabilities and potential risks.
Work with other IT teams to integrate PKI solutions into existing systems and applications.
Maintain close ties to various stakeholders, developers, and engineers across the company, ensuring the services we create meet their needs as products evolve.
Communicate extensively with Data Protection Product and engineering teams across the organization.
Drive complex technical initiatives to full delivery leveraging knowledge of cyber‑security practices, software engineering principles, agile frameworks, and customer engagement.
Design, build, and maintain infrastructure to meet the organization’s requirements and ensure high availability.
Apply adept understanding and experience with systems automation platforms and technologies.
Required Qualifications
5+ years of hands‑on experience in network security, data security, and/or other cyber‑security‑related controls and technologies.
Automation via Certificate Lifecycle Management tools using scripting and coding (Venafi, PowerShell, and Python knowledge required; GitHub and .Net knowledge highly desired).
Bachelor’s Degree in computer science or related field highly preferred.
Ability to foster collaborative, open, working relationships with technology groups and other stakeholders, including vendor relationships.
Clear communication skills and ability to interact effectively at multiple levels of an organization, and to influence leadership (including translating technical information based on specific audiences).
Experience implementing multiple high‑visibility and high‑impact enterprise cyber‑security projects with cross‑functional teams while maintaining superior results including planning, development and management of technical requirements, design, testing and deployment of security solutions.
Strong understanding of Public Key Infrastructure (PKI) principles.
Expertise in PKI technologies like Microsoft Active Directory Certificate Services (AD CS), Entrust, Venafi, or other commercial PKI solutions.
Experience with managing Hardware Security Modules (HSMs).
Preferred Qualifications
Multiple certifications in cyber‑security and data protection (CISSP, GIAC, CISM, CCSP, CISA, Security+, or other related certifications).
Benefits
401(k) with company match and Employee stock purchase plan
Paid time for vacation, volunteering, and 28‑day sabbatical after every 5 years of service for eligible positions
Paid parental leave and family building benefits
Tuition reimbursement
Health, dental, and vision insurance
#J-18808-Ljbffr