Asset & Wealth Management – New York - Associate Security Engineering - 10415579

Goldman SachsNew York, NY
$132,000 - $184,400Onsite

About The Position

Perform security assessments of business-initiated projects to drive adoption of application and infrastructure security controls and best practices, ensuring security and privacy by design. Collaborate with technical and global teams on major technology initiatives to ensure security is embedded early and to enhance detection capabilities through improved tools, tuning, and data sources. Review system architectures, such as client/server, cloud, web, mobile, and security controls to identify gaps and ensure alignment with firm policies, standards, and regulatory requirements. Conduct application security risk assessments across the SDLC, including vulnerability assessments and penetration testing of internal and external applications in coordination with vulnerability management teams. Perform secure code reviews for applications using languages such as Java, React, and Python to identify vulnerabilities and strengthen security posture. Evaluate third-party system integrations and work with infrastructure teams to implement and validate security controls across platforms. Communicate technical findings, risks, and security gaps clearly to stakeholders, developers, and engineers through reporting and presentations to support issue tracking and remediation.

Requirements

  • Master’s degree (U.S. or foreign equivalent) in Cyber Security, Computer Science, Computer Engineering or a related field and one (1) year of experience in the job offered or a related Security Engineering role OR Bachelor’s degree (U.S. or foreign equivalent) in Cyber Security, Computer Science, Computer Engineering or a related field and three (3) years of experience in the job offered or a related Security Engineering role.
  • Working with both application and infrastructure architecture and security on premise and Cloud.
  • Working with application security best practices including OWASP and CWE.
  • Working with application security vulnerabilities and controls to remediate risks.
  • Assessing and mitigating software security threat vectors, threat modeling, attack surface analysis, security design reviews, source code reviews, penetration testing or vulnerability assessments.
  • Working in shift left environment to help embed security in Design phase to implement security controls within system architecture.
  • Conducting infrastructure or application security risk assessments.

Responsibilities

  • Perform security assessments of business-initiated projects to drive adoption of application and infrastructure security controls and best practices, ensuring security and privacy by design.
  • Collaborate with technical and global teams on major technology initiatives to ensure security is embedded early and to enhance detection capabilities through improved tools, tuning, and data sources.
  • Review system architectures, such as client/server, cloud, web, mobile, and security controls to identify gaps and ensure alignment with firm policies, standards, and regulatory requirements.
  • Conduct application security risk assessments across the SDLC, including vulnerability assessments and penetration testing of internal and external applications in coordination with vulnerability management teams.
  • Perform secure code reviews for applications using languages such as Java, React, and Python to identify vulnerabilities and strengthen security posture.
  • Evaluate third-party system integrations and work with infrastructure teams to implement and validate security controls across platforms.
  • Communicate technical findings, risks, and security gaps clearly to stakeholders, developers, and engineers through reporting and presentations to support issue tracking and remediation.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service