Charles Schwab Sr. Staff, Information Security Testing in Lone Tree, Colorado
We believe that , when done right, investing liberates people to create their own destiny. We are driven by our purpose to champion every client’s goals with passion and integrity. We respect and appreciate the diversity of our employees, our clients, and the communities we serve. We challenge conventions strategically to create value for our clients, our firm and the world. We live and bring to life the concept of ‘own your tomorrow’ every day. We champion our employee strengths, guide their development, and invest in their long-term success. We hire optimistic, results-oriented, curious, innovative, and adaptable people with the desire to help our clients and one another succeed.
As a company, we were established by Chuck over 40 years ago to champion Main Street over Wall Street, and to help Americans transform themselves from earners to owners. Through advocacy and innovation, we work to make investing more affordable, accessible and understandable for all. As we enter our fifth decade, we are looking for talented, innovative and driven people who believe they can help themselves, and our clients, create a better future.
In Corporate Risk Management, we provide an integrated risk management strategy that supports the delivery of predictable financial and operational performance in order to produce successful client and shareholder outcomes. We are organized around six primary functions: Bank Risk, Enterprise Risk, Information Security Risk, Market and Investment Risk, Model Risk and Operational Risk. Within each of these areas, we develop a framework for how much risk we are willing to accept as a firm and establish processes for identifying, evaluating, measuring, monitoring and reporting against that framework. In Information Security Risk Management (ISRM), we apply this framework to the use of information and technology by setting and monitoring the implementation of risk-based policies and enhancing the firm’s controls and security countermeasures. Within ISRM, our Strategy team defines the policies, processes, and procedures to govern our Information Security (IS) function; conducts our annual Risk Assessment (RA) and ensures compliance with Policy across the organization.
What you’ll do:
Assist the team in performing Information Security Risk Assessments
Enter assessment reports and associated findings into Archer (eGRC tool)
Create and execute on findings from assessments using the DREAD Risk Assessment Model
Write testing procedures for the defined control framework for compliance control testing
Gather relevant information related to the operational status of security controls through various methods including interviewing staff members, and gathering of evidence of controls in place
Test compliance controls in place in order to determine effectiveness and compliance toward meeting regulatory compliance;
Analyze resulting data of compliance testing
Monitor, update and provide consultation on information security risk findings, exceptions and risk acceptances for all information security technology assets
Partner with a variety of Technology organization teams, as well as risk-mitigation groups such as Corporate Security, Global Security Organization, the Online Security Team, and Security Technology and Operations
Assist with additional projects and tasks related to Information Security based on business needs and the regulatory environment
What you have:
At least 5 years of experience as an Information Security practitioner and a BA/BS degree.
A depth of knowledge of IS Risk Assessment methodologies such as ISO 27005, DREAD and IS control frameworks such as ISO 27001/27002, PCI DSS, and/or NIST 800-53.
Prior implementation of IS best practices for key areas such as network controls, including IS concepts in all phases of the software development life cycle, logical access controls and data protection.
Exposure to IS Risk Assessment technologies including Archer GRC and OpenPages.
Knowledge of content sharing tools including SharePoint.
Preferably: Prior experience interacting with regulators to evaluate audit reports, network penetration test results, application security assessments and regulatoryexams to determine remediation priorities and CISSP, CISA, CISM, SANS GIAC or equivalent certifications.
What you’ll get:
Everyday Wellness: Healthy Rewards, Onsite Fitness Classes, Healthy Choices, Wellness Champions
Financial Fitness: 401k Match, Employee Discounts, Personalized advice, Brokerage discounts
Work/Life Balance: Sabbatical, New Mothers returning to work Program, Tuition Reimbursement Programs, Time off to volunteer
Inclusion: Employee Resource Groups, Commitment to diversity, Strategic partnerships
Not just a job, but a career, with an opportunity to do the best work of your life
Learn more about Life@Schwab at http://www.aboutschwab.com/careers/lifeatschwab/" .
Charles Schwab & Co., Inc. is an equal opportunity and affirmative action employer committed to diversifying its workforce. It is Schwab's policy to provide equal employment opportunities to all employees and applicants without regard to race, color, religion, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), gender identity or expression, national origin, ancestry, age, disability, legally protected medical condition, genetic information, marital status, sexual orientation, protected veteran status, military status, citizenship status or any other status that is protected by law.
Position Located In: CO - Lone Tree