SWBC is a diversified financial services company headquartered in San Antonio, Texas, serving clients across all 50 states and internationally. The firm's portfolio spans mortgages, payroll and HR services, and insurance and investment products for businesses, families, and financial institutions. With over 2,200 employees, SWBC operates at a scale where the attack surface is real: PII at rest and in transit across mortgage origination pipelines, payroll systems processing W-2s and direct deposit data, and insurance underwriting workflows touching sensitive financial records.
Founded in 1976, the company has grown from $1,500 in startup capital into a multi-vertical operation that touches some of the most regulated data domains in U.S. financial services. That means PCI-DSS, SOX, and GLBA compliance aren't abstract - they're architectural constraints on how systems are designed, deployed, and monitored. The threat model here isn't hypothetical: credential stuffing against client portals, business email compromise targeting payroll disbursement, and supply-chain risk from third-party integrations are the daily operational realities.
For security practitioners, the draw is breadth. You're not defending a single product - you're securing an environment where mortgage servicing platforms, HR SaaS tooling, and investment product infrastructure coexist under one corporate umbrella. That means identity and access management, network segmentation, and incident response all have to work across distinct business lines with different regulatory postures and data classifications.






