Application Security Penetration Tester
Location: Schiller Park
Posted on: June 23, 2025
|
|
Job Description:
At Schwab, you’re empowered to make an impact on your career.
Here, innovative thought meets creative problem solving, helping us
“challenge the status quo” and transform the finance industry
together. We believe in the importance of in-office collaboration
and fully intend for the selected candidate for this role to work
on site in the specified location(s). The Schwab Cybersecurity
Services team is seeking an Application Penetration Tester. This is
an excellent opportunity to work with a growing team of Application
Security professionals who strive to deliver solutions that exceed
the expectations of our clients and measurably improve Schwab’s
risk management practices. You will work closely with application
development teams other teams within application security, and
other cyber security teams to foster the development of secure,
resilient, and reliable software for external users and Schwab’s
internal workforce. Lead testing efforts on web and mobile
applications and supporting systems. • Replicate the actual
techniques and tools used by malicious attackers in an effort to
model potential external threats. • Upon completion of the
assessment, you will prepare reports and present the results to
application owners, developers, and business unit information
security teams. • Analyze test results, draw conclusions from
results, and develop targeted exploit examples. • Consult with
operations and software development teams to ensure potential
weaknesses are addressed. • Contribute to the research or
development of tools to assist in the vulnerability discovery
process. • Collaborate with other teams within Enterprise
Cybersecurity to improve the overall security of applications and
infrastructure. • Stay current on security best practices and
vulnerabilities. What you have Required Qualifications: •
Bachelor’s degree • 5 years of IT experience • Preferred 3 years of
hands-on web application penetration testing / ethical hacking
experience • Preferred: OSCP, GWAPT, GXPN, GPEN, LPT, CEH, CISSP or
other industry security certifications. • Ability to demonstrate
manual testing experience including all of OWASP Top 10 •
Intermediate knowledge of application security mechanisms such as
authentication and authorization techniques, data validation, and
the proper use of encryption • Technical knowledge of, and the
ability to recognize, various types of application security
vulnerabilities. • Demonstrated experience with common penetration
testing and vulnerability assessment tools such as nmap, Wireshark,
Nessus, NeXpose, BackTrack, Metasploit, AppScan, WebInspect, Burp
Suite Professional, Acunetix, Arachni, w3af, NTOSpider •
Intermediate knowledge of a programming or scripting language such
a C, C#, Python, Objective C, Java, Javascript, SQL, • Intermediate
knowledge of Web Services technologies such as XML, JSON, SOAP,
REST, and AJAX • Intermediate knowledge of web frameworks,
including XML, SOAP, J2EE, JSON and Ajax • Experience with
Enterprise Java or .NET web application frameworks, including
Struts and Spring • Proven analytical and problem-solving skills,
as well as the desire to assist others in solving issues •
Excellent interpersonal skills with a strong interest in the
application security domain • Excellent communication and
presentation skills and a proven ability to communicate threats and
facilitate progress towards long-term remediation. • Highly
motivated with the willingness to take ownership / responsibility
for their work and the ability to work alone or as part of a team.
In addition to the salary range, this role is also eligible for
bonus or incentive opportunities. What’s in it for you At Schwab,
we’re committed to empowering our employees’ personal and
professional success. Our purpose-driven, supportive culture, and
focus on your development means you’ll get the tools you need to
make a positive difference in the finance industry. Our Hybrid Work
and Flexibility approach balances our ongoing commitment to
workplace flexibility, serving our clients, and our strong belief
in the value of being together in person on a regular basis. We
offer a competitive benefits package that takes care of the whole
you – both today and in the future: • 401(k) with company match and
Employee stock purchase plan • Paid time for vacation,
volunteering, and 28-day sabbatical after every 5 years of service
for eligible positions • Paid parental leave and family building
benefits • Tuition reimbursement • Health, dental, and vision
insurance
Keywords: , Buffalo Grove , Application Security Penetration Tester, IT / Software / Systems , Schiller Park, Illinois