- Goldman Sachs
- New York, NY
- Full-Time
- 54 days ago
- $137,000–$183,000
Global Banking & Markets- New York - Associate, Security Engineering- 10442631.
Before you go
Before you leave us, sign up for our email alerts
We don't do job spam, just the best digital jobs delivered straight to your inbox.
Global Banking & Markets- New York - Associate, Security Engineering- 10442631: our view in 3 lines...
- The Role:This role is for an Associate in Security Engineering focused on security and technology risk within a banking and markets environment.
- The Person:The person will assess security and technology risks, review system designs and control gaps, advise engineering teams, test controls, and validate resiliency evidence across application, infrastructure, cloud, web and third-party environments.
- Requirements:The ideal candidate has a master’s or bachelor’s degree in Cyber Security, Computer Science or Computer Engineering, plus experience with application security standards, information security frameworks, IAM, RCSA, SOX evaluations and control testing.
About the role
Job Duties: Associate, Security Engineering with Goldman Sachs Services LLC in New York, New York. Perform security and technology risk assessments for business-initiated projects to identify risks and support adoption of appropriate controls. Evaluate system designs to ensure security requirements are incorporated, including review of control implementation and identification of control gaps. Advise engineering teams on risk considerations and support integration of security controls throughout the system development lifecycle. Assess risks across application and infrastructure environments, including cloud platforms, web services, and distributed systems, and recommend mitigation actions. Conduct risk reviews of third-party integrations to ensure compliance with firm standards and required control frameworks. Support execution of business-as-usual (BAU) and strategic initiatives aimed at reducing operational and technology risk exposure. Perform control testing activities, including Risk and Control Self Assessments (RCSA) and SOX evaluations, and validate supporting evidence to assess control effectiveness. Conduct resiliency validation reviews by analyzing evidence related to system recovery and operational continuity.
Job Requirements: Master’s degree (U.S. or foreign equivalent) in Cyber Security, Computer Science, Computer Engineering or a related field and one (1) year of experience in the job offered or a related role OR Bachelor’s degree (U.S. or foreign equivalent) in Cyber Security, Computer Science, Computer Engineering or a related field and three (3) years of experience in the job offered or a related role. Prior work experience must include one (1) year with Master’s OR three (3) years with Bachelor’s with the following: application security standards and information security frameworks; cybersecurity across the risk management lifecycle, including risk identification, assessment, mitigation, and monitoring; supporting mitigation of technology risks through development and implementation of control recommendations; supporting business-as-usual (BAU) and strategic initiatives to reduce operational and technology risk exposure; identity and Access Management (IAM) principles, including access lifecycle management and access control processes; segregation of Duties (SoD) and application in preventing conflicting access risks; conducting control testing and validation, including participation in Risk and Control Self Assessments (RCSA) and SOX evaluations; reviewing resiliency and control evidence to assess system resilience and operational risk; and data analysis and reporting techniques, including application of artificial intelligence or analytical models to support risk insights.
Salary Range: Annual base salary for this New York, New York -based position is $137,000 - $183,000.
The Goldman Sachs Group, Inc., 2026. All rights reserved. Goldman Sachs is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sex, national origin, age, veteran status, disability, or any other characteristic protected by applicable law.

