Global Banking & Markets- New York - Associate, Security Engineering- 10442631

Goldman SachsNew York, NY
$137,000 - $183,000Onsite

About The Position

Perform security and technology risk assessments for business-initiated projects to identify risks and support adoption of appropriate controls. Evaluate system designs to ensure security requirements are incorporated, including review of control implementation and identification of control gaps. Advise engineering teams on risk considerations and support integration of security controls throughout the system development lifecycle. Assess risks across application and infrastructure environments, including cloud platforms, web services, and distributed systems, and recommend mitigation actions. Conduct risk reviews of third-party integrations to ensure compliance with firm standards and required control frameworks. Support execution of business-as-usual (BAU) and strategic initiatives aimed at reducing operational and technology risk exposure. Perform control testing activities, including Risk and Control Self Assessments (RCSA) and SOX evaluations, and validate supporting evidence to assess control effectiveness. Conduct resiliency validation reviews by analyzing evidence related to system recovery and operational continuity.

Requirements

  • Master’s degree (U.S. or foreign equivalent) in Cyber Security, Computer Science, Computer Engineering or a related field and one (1) year of experience in the job offered or a related role OR Bachelor’s degree (U.S. or foreign equivalent) in Cyber Security, Computer Science, Computer Engineering or a related field and three (3) years of experience in the job offered or a related role.
  • Application security standards and information security frameworks.
  • Cybersecurity across the risk management lifecycle, including risk identification, assessment, mitigation, and monitoring.
  • Supporting mitigation of technology risks through development and implementation of control recommendations.
  • Supporting business-as-usual (BAU) and strategic initiatives to reduce operational and technology risk exposure.
  • Identity and Access Management (IAM) principles, including access lifecycle management and access control processes.
  • Segregation of Duties (SoD) and application in preventing conflicting access risks.
  • Conducting control testing and validation, including participation in Risk and Control Self Assessments (RCSA) and SOX evaluations.
  • Reviewing resiliency and control evidence to assess system resilience and operational risk.
  • Data analysis and reporting techniques, including application of artificial intelligence or analytical models to support risk insights.

Responsibilities

  • Perform security and technology risk assessments for business-initiated projects to identify risks and support adoption of appropriate controls.
  • Evaluate system designs to ensure security requirements are incorporated, including review of control implementation and identification of control gaps.
  • Advise engineering teams on risk considerations and support integration of security controls throughout the system development lifecycle.
  • Assess risks across application and infrastructure environments, including cloud platforms, web services, and distributed systems, and recommend mitigation actions.
  • Conduct risk reviews of third-party integrations to ensure compliance with firm standards and required control frameworks.
  • Support execution of business-as-usual (BAU) and strategic initiatives aimed at reducing operational and technology risk exposure.
  • Perform control testing activities, including Risk and Control Self Assessments (RCSA) and SOX evaluations, and validate supporting evidence to assess control effectiveness.
  • Conduct resiliency validation reviews by analyzing evidence related to system recovery and operational continuity.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service