Global Banking & Markets-New York- Associate, Security Engineering- 9172847
![]() | |
![]() The Goldman Sachs Group, Inc., 2025 | |
![]() United States, New York, New York | |
![]() 200 West Street (Show on map) | |
![]() | |
Job Duties: Associate, Security Engineering with Goldman Sachs Services LLC in New York, New York. Responsible for performing security assessments of business-initiated projects helping to drive adoption of application and infrastructure security controls and best practices. Ensure security and privacy by design, including design process improvements, assessment of controls, data models, cryptographic implementation, and compliance and regulatory needs. Collaborate with technical teams on major technology initiatives to ensure security exists at the outset of a design or project. Advise on leading edge engineering to protect the firm's network from security risks related to client/server architectures, Cloud architectures, web services and mobile applications. Conduct risk reviews of 3rd party system integrations against firm policies and standards. Drive implementation of security controls in various platforms by working with technology infrastructure teams. Collaborate with the global team to continually operate and improve a world-class cyber program by providing input into the uplift of sensory tools, detection tuning, and access to data sources to increase detection effectiveness. Convey complicated technical analyses via comprehensive presentations. Communicate status and risks in a succinct, direct and open manner for proper issue management life cycle tracking. Review security controls and how they apply to different designs and systems in order to identify security gaps. Highlight and articulate risk to developers or engineers. Perform application vulnerability assessment and penetration testing of web applications. Perform code review of web application programming languages such as Java. Perform assessments of technologies leveraging common web stack technologies such as Java. Perform architecture review of web applications. Job Requirements: Master's degree (U.S. or foreign equivalent) in Cyber Security, Computer Science, Computer Engineering or a related field and one (1) year of experience in the job offered or a related Security Engineering role OR Bachelor's degree (U.S. or foreign equivalent) in Cyber Security, Computer Science, Computer Engineering or a related field and three (3) years of experience in the job offered or a related Security Engineering role. Prior work experience must include one (1) year of experience (with a Master's degree) or three (3) years of experience (with a Bachelor's degree) with each of the following: technical understanding of both application and infrastructure architecture and security (on premise and Cloud); working with application security best practices including OWASP and CWE; working with application security vulnerabilities and controls to remediate risks; assessing and mitigating software security threat vectors, threat modeling, attack surface analysis, security design reviews, source code reviews, penetration testing or vulnerability assessments; working in shift left environment to help embed security in Design phase to implement security controls within system architecture; and conducting infrastructure or application security risk assessments. Salary Range: Annual base salary for this New York, New York -based position is $134,000 - $139,000. The Goldman Sachs Group, Inc., 2025. All rights reserved. Goldman Sachs is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sex, national origin, age, veteran status, disability, or any other characteristic protected by applicable law. |