Global Banking & Markets- New York - Associate, Security Engineering - 10442640

Goldman SachsNew York, NY
$137,000 - $183,000Onsite

About The Position

The Associate, Security Engineering role at Goldman Sachs Services LLC in New York, New York involves performing security assessments for business-initiated projects, promoting the adoption of application and infrastructure security controls and best practices. This includes ensuring security and privacy by design, improving design processes, assessing controls, data models, cryptographic implementations, and meeting compliance and regulatory needs. The role requires advising on cutting-edge engineering to safeguard the firm's network against security risks associated with client/server architectures, Cloud architectures, web services, and mobile applications. Responsibilities also include conducting risk reviews of third-party system integrations against firm policies, driving the implementation of security controls across various platforms by collaborating with technology teams, and utilizing data analytics and machine learning to enhance risk monitoring and control effectiveness. The position involves collaborating with a global team, coordinating stakeholders across engineering and business leadership to continuously operate and improve the cyber program. This includes providing input for the uplift of sensory tools, detection tuning, and ensuring access to data sources to increase detection effectiveness while aligning risk mitigation objectives with organizational goals. The role also requires highlighting risks to developers or engineers, performing application vulnerability assessments and penetration testing of web applications, conducting code reviews of web application programming languages, assessing technologies using common web stack technologies, and performing architecture reviews of web applications. A key aspect is building intuitive dashboards for divisional executive leadership to track progress and facilitate informed decision-making for the security engineering's annual work plan.

Requirements

  • Master’s degree (U.S. or foreign equivalent) in Cyber Security, Computer Science, Computer Engineering or a related field and one (1) year of experience in the job offered or a related role OR Bachelor’s degree (U.S. or foreign equivalent) in Cyber Security, Computer Science, Computer Engineering or a related field and three (3) years of experience in the job offered or a related role
  • Prior work experience must include one (1) year with Master’s OR three (3) years with Bachelor’s with the following: application and infrastructure architecture and security (on premise and Cloud)
  • Working with application security vulnerabilities and controls to remediate risks including OWASP and CWE
  • Assessing and mitigating software security threat vectors, threat modeling, attack surface analysis, security design reviews, source code reviews, penetration testing or vulnerability assessments
  • Working in shift left environment to help embed security in design phase to implement security controls within system architecture
  • Conducting infrastructure or application security risk assessments
  • Supporting cross-functional tech risk programs by coordinating stakeholders across engineering, business leadership and regulatory teams and applying operations management principles to optimize delivery while ensuring alignment between risk mitigation objective and organizational goals
  • Collaborating in high-level architectural and engineering discussions to assess security risks and strengthen application, infrastructure and cloud security strategies
  • Developing secure software delivery proposals to improve security controls, reduce vulnerability remediation costs, and mitigate operational risk

Responsibilities

  • Performing security assessments of business-initiated projects
  • Driving adoption of application and infrastructure security controls and best practices
  • Ensuring security and privacy by design, including design process improvements, assessment of controls, data models, cryptographic implementation, and compliance and regulatory needs
  • Advising on leading edge engineering to protect the firm’s network from security risks related to client/server architectures, Cloud architectures, web services and mobile applications
  • Conducting risk reviews of 3rd party system integrations against firm policies and standards
  • Driving implementation of security controls in various platforms by working with technology teams
  • Leveraging data analytics and machine learning techniques to enhance risk monitoring and inform control effectiveness
  • Collaborating with the global team and coordinating stakeholders across engineering and business leadership to continually operate and improve cyber program
  • Providing input into uplift of sensory tools, detection tuning, and access to data sources to increase detection effectiveness while ensuring alignment between risk mitigation objectives and organizational goals
  • Highlighting risk to developers or engineers
  • Performing application vulnerability assessment and penetration testing of web applications
  • Performing code review of web application programming languages
  • Performing assessments of technologies leveraging common web stack technologies
  • Performing architecture review of web applications
  • Building user-friendly and best-in-class intuitive dashboards for divisional executive leadership to track progress and make informed decisions for the security engineering's year-over-year book of work
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service