Associate, Security Engineering

Goldman Sachs

Confirmed live 2 days ago High trust

Quick summary

Work type
On-site
Location
New York, NY
Salary
$137,000–$183,000 / yr
Posted
31 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $177k
This role $160k
$119k most similar roles pay here $224k

This role pays less than 62% of similar roles. Most pay $149,500–$203,750 — the shaded band above. At the midpoint, this role pays about $160k versus about $177k for comparable roles.

Based on 240 similar postings.

Employer

About Goldman Sachs

Goldman Sachs is a leading global investment banking, securities, and investment management firm providing financial services to corporations, financial institutions, governments, and individuals.

Goldman Sachs currently has 134 open roles on FindRole.

Listed pay typically runs $137,000–$250,000 across 55 roles with salary data.

Most-posted roles

View all roles at Goldman Sachs

At a glance

TL;DR · Associate, Security Engineering

As an Associate, Security Engineering within the Global Banking & Markets division, you will perform security and technology risk assessments for business-initiated projects to identify risks and support the adoption of appropriate controls. You will evaluate system designs to ensure security requirements are integrated throughout the development lifecycle while advising engineering teams on risk considerations. Your daily work involves assessing application and infrastructure environments, including cloud platforms, web services, and distributed systems, alongside conducting risk reviews of third-party integrations. You will perform control testing activities such as Risk and Control Self Assessments and SOX evaluations to validate evidence for system resilience and operational continuity. Key competencies include knowledge of information security frameworks, identity and access management principles, segregation of duties, and data analysis techniques using artificial intelligence or analytical models to provide risk insights across the technology landscape.

What you'll do

  • Perform security and technology risk assessments for business-initiated projects to identify risks and support control adoption.
  • Evaluate system designs to ensure security requirements are integrated and identify potential control gaps.
  • Advise engineering teams on risk considerations and integrate security controls throughout the system development lifecycle.
  • Assess risks across application, infrastructure, cloud platforms, web services, and distributed systems to recommend mitigation actions.
  • Conduct risk reviews of third-party integrations to ensure compliance with firm standards and control frameworks.
  • Execute business-as-usual and strategic initiatives aimed at reducing operational and technology risk exposure.
  • Perform control testing activities including Risk and Control Self Assessments (RCSA) and SOX evaluations.
  • Conduct resiliency validation reviews by analyzing evidence related to system recovery and operational continuity.

What we're looking for

  • A Master’s degree in Cyber Security, Computer Science, Computer Engineering, or a related field and one year of relevant experience is required.
  • A Bachelor’s degree in Cyber Security, Computer Science, Computer Engineering, or a related field and three years of relevant experience is required.
  • Experience with application security standards and information security frameworks is required.
  • Experience with the cybersecurity risk management lifecycle, including identification, assessment, mitigation, and monitoring, is required.
  • Experience supporting the mitigation of technology risks through control recommendations and implementation is required.
  • Knowledge of Identity and Access Management (IAM) principles and Segregation of Duties (SoD) is required.
  • Experience conducting control testing, Risk and Control Self Assessments (RCSA), and SOX evaluations is required.
  • Proficiency in data analysis and reporting techniques, including the use of artificial intelligence or analytical models, is required.

More like this

Similar roles

Associate, Security Engineering

Goldman Sachs

New York, NY 31 days ago $137,000$183,000
Application Security Infrastructure Security Cloud Security OWASP CWE Penetration Testing Vulnerability Assessment Source Code Review Threat Modeling Data Analytics Machine Learning Web Services Mobile Applications Security Design Review Shift Left
3+ yrs exp

Associate Security Engineering

Goldman Sachs

New York, NY 31 days ago $132,000$184,400
Application Security Infrastructure Security Cloud Java React Python OWASP CWE SDLC Penetration Testing Vulnerability Assessment Threat Modeling Source Code Review Security Design Review Attack Surface Analysis Shift Left
3+ yrs exp

Associate, Quantitative Engineering

Goldman Sachs

New York, NY 30 days ago $150,000$189,000
Python C++ Java Stochastic Calculus Machine Learning Time Series Analysis Linear Regression Bayesian Analysis Quantitative Analysis Financial Mathematics Data Management Statistical Analysis Numerical Methods Optimization
2+ yrs exp

Associate, Security Engineering

Goldman Sachs

Richardson, TX 31 days ago
AWS Azure Splunk Excel Active Directory Windows Server Cyber Security SOC1 CCPA NIST Private Cloud Mobile Applications Web Services
3+ yrs exp

Vice President, Systems Engineering

Goldman Sachs

New York, NY 31 days ago $213,000$271,000
Oracle SQL Python UNIX Shell Scripting DB2 Sybase ASE Windows Microsoft Configuration Manager Machine Learning Data Mining SDLC Disaster Recovery Performance Tuning Automated Testing
5+ yrs exp

Associate Security Engineering Engineer

Goldman Sachs

Dallas, TX 31 days ago
Application Security Infrastructure Security Cloud Architecture OWASP CWE Threat Modeling Penetration Testing Vulnerability Assessment Security Design Review Shift Left Web Services Mobile Applications Risk Assessment
3+ yrs exp