Job Description
The Asset and Wealth Management Division includes Goldman Sachs Asset Management (AM), Private Wealth Management (PWM, Ayco) and our Consumer business (Marcus by Goldman Sachs). We provide asset management, wealth management and banking expertise to consumers and institutions around the world. AWM partners with various teams across the firm to help individuals and institutions navigate changing markets and take control of their financial lives.
The AWM Technology Risk function is an information security group embedded within AWM responsible for the oversight of Information Security and Cybersecurity risks across AWM business and technology as well as supplements the firm’s Technology Risk programs to meet the additional unique needs of the AWM business. Our mission is to enable the business needs while balancing security controls
HOW YOU WILL FULFILL YOUR POTENTIAL
- Partner with business units to understand design proposal and evaluate architectural flaws for various on-prem/cloud deployments
- Closely collaborate with Product Management, Engineering, Dev Ops and Firmwide Tech Risk teams to evaluate the design and implementation of security controls related to Authentication, Authorization, Input Validations etc. and enhance firm’s security posture
- Evaluate the effectiveness of existing key controls, identify gaps, and recommend improvements to mitigate risks and enhance firm’s security posture
- Acts as an Application security liaison for developers and architects in the respective Business Unit to build security software
- Interface with business, engineering and leadership teams to articulate and evaluate risk and recommend a mitigation strategy.
- Drive adoption of embedded application security controls as part of the Software Development Life Cycle (SDLC) in Agile methodology
- Provide clear and concise verbal and written recommendations and guidance to both business and technology leaders on matters of Technology Risk Management
- Promote and assist in training & awareness of information security within the region
- Strong passion and desire to grow in the Information Security area
- Collaborate with Firmwide Tech Risk and other relevant teams to develop security patterns and best practices based on engineering usecase
SKILLS AND EXPERIENCE WE ARE LOOKING FOR:
- 3 – 5 years of technology experience in one or more of the following areas: Information Security, Product/Application Security, Threat Modelling/Secure Design Reviews, Penetration testing etc.
- Knowledge of most common Application Security vulnerabilities – e.g., OWASP Top 10 Web and API risks, cloud security gaps.
- Familiarity with Security standards such as OWASP, NIST, PCI and CIS/SANS security controls
- Ability to analyze internal and external processes and integration to understand risk
- Understanding of security core cryptography concepts (Encryption, Hashing, HMAC, digital signatures), its implementation, how they are applied and attacked in web applications
- Assessing and mitigating software security threat vectors, with experience in threat modeling framework, attack surface analysis, security design reviews, source code reviews, penetration testing or vulnerability assessments.
- Good written and oral communication to be able to articulate risks to both technical and management stakeholders
- Strong program and project management skills and technology expertise
- Ability to assess and evaluate corporate risk tolerance and translate into goals and new processes including software engineering, IT teams, and engineering and business stakeholders
- Experience collaborating with a team of security experts in a diverse set of security topics including, but not limited to, security architecture, financial controls and regulatory compliance, identity and access management, penetration testing, data loss prevention, network security, security monitoring, white box testing/static code analysis, and building secure systems
DESIRED SKILLS
- Experience in Financial Services/Fintech
- Knowledge of secure coding language - Python, Java, Go
- Experience in AWS or Cloud technologies

0 applies
6 views
Other Jobs from Goldman Sachs
Software Engineering - Analyst/Associate - Global Banking & Markets
Similar Jobs
Platform Engineer III - Middleware
Software Development Engineer II, Brand Innovation Lab
System Development Engineer, eero Business Systems
Senior Backend Software Engineer
Software Engineer III, Software Delivery Platform
Senior Software Engineer, Reliability
There are more than 50,000 engineering jobs:
Subscribe to membership and unlock all jobs
Engineering Jobs
60,000+ jobs from 4,500+ well-funded companies
Updated Daily
New jobs are added every day as companies post them
Refined Search
Use filters like skill, location, etc to narrow results
Become a member
🥳🥳🥳 452 happy customers and counting...
Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.
To try it out
For active job seekers
For those who are passive looking
Cancel anytime
Frequently Asked Questions
- We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
- We've got about 70,000 jobs from 5,000 vetted companies. No fake or sleazy jobs here!
- We aggregate jobs from 5,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
- We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
- Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
- Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
- Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅
What Fellow Engineers Say