Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details
Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

Charles Schwab

Penetration Test Program Manager

Career Insights for Vulnerability Analyst / Penetration Tester

See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.

Scorecard

Based on Texas data

Review key factors to help you decide if this role fits your goals. How is this calculated?

Were these scores useful?

What they do

A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.

$116,062 / year median in Texas

+6% projected growth

Explore Career

Job Description

Your opportunity At Schwab, you're empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us "challenge the status quo" and transform the finance industry together. We believe in the importance of in-office collaboration and fully intend for the selected candidate for this role to work on site in the specified location. As Schwab continues to expand its technology footprint across cloud, artificial intelligence, digital platforms, applications & APIs, and infrastructure services, the Technology Risk Management (TRM) team plays a critical role in helping ensure the company maintains a strong risk posture through independent oversight and risk-informed assurance activities. Within TRM, the Penetration Testing team provides independent penetration testing and challenge of security controls through a combination of internal and vendor-led penetration testing activities designed to identify vulnerabilities, validate defensive capabilities, and strengthen the firm's overall risk posture. In this highly visible individual contributor role, you will serve as a central coordinator and risk management partner supporting the administration, execution, governance, reporting, and continuous improvement of the penetration testing program. You will work closely with penetration testers, technology teams, cybersecurity partners, application developers, risk managers, and external vendors to ensure testing activities are planned, executed, documented, and reported effectively. You will help facilitate testing engagements across applications & APIs, infrastructure & cloud environments, AI solutions, and emerging technologies while ensuring alignment with Schwab policies, standards, regulatory requirements, and industry best practices. Success in this role comes from balancing strong program management, analytical thinking, communication skills, and risk management expertise. You will help identify systemic risks, recurring vulnerabilities, and control weaknesses across testing activities while providing leadership with meaningful insights to understand the broader risk implications and trends impacting the organization. Through thematic analysis, executive reporting, stakeholder engagement, and continuous process improvement, your expertise will help strengthen governance, improve risk visibility, and enhance the overall maturity and effectiveness of the penetration testing program. Your work will directly contribute to informed decision-making, stronger control environments, improved remediation outcomes, and the ongoing evolution of Schwab's risk capabilities. What you have To ensure that we have fulfilled our promise of 'challenging the status quo,' this role has specific qualifications that successful candidates should have. Required Qualifications Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, Business, Risk Management, or a related field 5+ years of experience in Cybersecurity, Technology Risk Management, Information Security, Governance, Risk and Compliance, Program Management, or related disciplines Experience supporting, coordinating, facilitating, or managing complex initiatives, penetration testing programs, or security assurance initiatives Strong analytical skills with the ability to identify trends, systemic issues, emerging risks, and control weaknesses Strong communication skills with the ability to present technical and risk information to both technical and non-technical audiences Experience developing reports, dashboards, metrics, presentations, and executive briefings Ability to manage multiple priorities and coordinate activities across numerous stakeholders and teams Experience working in highly regulated environments with strong governance and documentation requirements Ability to develop collaborative relationships across cybersecurity, technology, risk management, and business organizations Preferred Qualifications Experience reviewing security findings, vulnerability assessments, penetration testing results, or technology risk assessments Knowledge of cybersecurity and risk management frameworks including NIST Cybersecurity Framework (CSF), NIST 800-53, NIST 800-115, FFIEC guidance, PCI DSS, or similar standards Professional certifications such as CISSP, CISM, CRISC, CISA, Security+, CCSK, CGRC, PMP, or similar credentials Experience supporting penetration testing, vulnerability management, red team, application security, cloud security, or security operations programs Familiarity with penetration testing methodologies, attack simulation techniques, vulnerability assessment tools, and risk reporting practices Experience performing thematic analysis and identifying recurring risk trends across multiple assessments or testing activities Experience managing vendor relationships and coordinating third-party security testing activities Experience developing executive-level reporting, risk metrics, and program health dashboards Knowledge of regulatory expectations related to cybersecurity testing and technology risk management within the financial services industry In addition to the salary range, this role is also eligible for bonus or incentive opportunities What's in it for you At Schwab, you're empowered to shape your future. We champion your growth through meaningful work, continuous learning, and a culture of trust and collaboration—so you can build the skills to make a lasting impact. Our Hybrid Work and Flexibility approach balances our ongoing commitment to workplace flexibility, serving our clients, and our strong belief in the value of being together in person on a regular basis. We offer a competitive benefits package that takes care of the whole you - both today and in the future: 401(k) with company match and Employee stock purchase plan Paid time for vacation, volunteering, and 28-day sabbatical after every 5 years of service for eligible positions Paid parental leave and family building benefits Tuition reimbursement Health, dental, and vision insurance
Qualifications:
To ensure that we have fulfilled our promise of 'challenging the status quo,' this role has specific qualifications that successful candidates should have. Required Qualifications Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, Business, Risk Management, or a related field 5+ years of experience in Cybersecurity, Technology Risk Management, Information Security, Governance, Risk and Compliance, Program Management, or related disciplines Experience supporting, coordinating, facilitating, or managing complex initiatives, penetration testing programs, or security assurance initiatives Strong analytical skills with the ability to identify trends, systemic issues, emerging risks, and control weaknesses Strong communication skills with the ability to present technical and risk information to both technical and non-technical audiences Experience developing reports, dashboards, metrics, presentations, and executive briefings Ability to manage multiple priorities and coordinate activities across numerous stakeholders and teams Experience working in highly regulated environments with strong governance and documentation requirements Ability to develop collaborative relationships across cybersecurity, technology, risk management, and business organizations Preferred Qualifications Experience reviewing security findings, vulnerability assessments, penetration testing results, or technology risk assessments Knowledge of cybersecurity and risk management frameworks including NIST Cybersecurity Framework (CSF), NIST 800-53, NIST 800-115, FFIEC guidance, PCI DSS, or similar standards Professional certifications such as CISSP, CISM, CRISC, CISA, Security+, CCSK, CGRC, PMP, or similar credentials Experience supporting penetration testing, vulnerability management, red team, application security, cloud security, or security operations programs Familiarity with penetration testing methodologies, attack simulation techniques, vulnerability assessment tools, and risk reporting practices Experience performing thematic analysis and identifying recurring risk trends across multiple assessments or testing activities Experience managing vendor relationships and coordinating third-party security testing activities Experience developing executive-level reporting, risk metrics, and program health dashboards Knowledge of regulatory expectations related to cybersecurity testing and technology risk management within the financial services industry In addition to the salary range, this role is also eligible for bonus or incentive opportunities