Secure SDLC Associate - Dallas - Technology Risk

Reposted 12 Days Ago
Be an Early Applicant
Dallas, TX, USA
In-Office
Junior
Fintech • Financial Services
The Role
Support and lead Secure SDLC initiatives: implement SAST/DAST and security controls, integrate AI-augmented tooling, coordinate with business units for remediation, design secure solutions, run testing/UAT/QA, and maintain Secure SDLC processes and tooling.
Summary Generated by Built In

Goldman Sachs Technology Risk leads threat and risk management initiatives that help protect the firm and our clients from information and cyber security risks. Our team equips the firm with the knowledge and tools to measure risk, identify and mitigate threats and potential risks, and prevent the introduction of antipatterns into the firm's technology stack.

Specifically, the Technology Risk Secure SDLC team is accountable for enabling developers across the firm to build secure technology solutions and platforms that hold up to the highest development security practices and standards. You will join a progressive team that continues to push the development of security controls within engineering functions and across the business, interact with all parts of the firm, and gain experience and knowledge that will facilitate your career growth and make an impact on various initiatives across the firm.

We are looking for a self-motivated candidate with a strong technical background in information security and risk management, and the adaptability to thrive with emerging technologies in a fast-paced development environment, to join a team focused on implementing security-by design.

Job Duties

  • Lead and support the implementation of static and dynamic analysis, as well as security awareness initiatives across all stages of the Secure Software Development Lifecycle (Secure SDLC).
  • Support the evaluation and adoption of AI-augmented capabilities within Secure SDLC services, including static and dynamic analysis tooling (SAST, DAST, IaC, Control Gating, etc.).
  • Drive the integration and adoption of embedded application security controls within SDLC ecosystem.
  • Interface with Business Units to help build secure applications and remediate issues identified by automated tools.
  • Develop, enhance, support and maintain the Firm's Secure SDLC solutions in support of its global businesses.
  • Design and implement high-quality, scalable and thoughtful technology solutions leveraging both internal and open-source services.
  • Assist in requirements gathering, user experience refinement, development, testing (unit, integration and regression), User Acceptance Testing (UAT), Deployment, and Quality Assurance (QA).
  • Work with internal teams to help develop secure solution designs.
  • Identify new external technologies that can be used to transform our financial businesses and internal platforms in innovative and disruptive ways.
  • Work in all phases of the Secure SDLC to meet internal and regulatory requirements.
  • Design, implement and maintain robust testing suites to enable secure, complete, and scalable solutions across our business lines.
  • Maintain awareness of emerging technologies (including but not limited to) agentic AI workflows and their potential application to Secure SDLC processes.

 

Minimum Education Requirements

  • Master's degree (U.S. or foreign equivalent) in Computer Science, Computer Engineering, Information Security, or a related field and one (1) year of experience in the job offered or a related role.

OR

  • Bachelor's degree (U.S. or foreign equivalent) in Computer Science, Computer Engineering, Information Security, or a related field and three (3) years of experience in the job offered or a related role.

 

Special Skills and/or Licenses Required to Perform the Job

Prior experience should include one (1) year (with a Master's degree) or three (3) years (with a Bachelor's degree) with:

  • Application and infrastructure architecture and security (on premise and Cloud).
  • Application security best practices including OWASP Top 10, OWASP LLM Top 10, and CWE.
  • Application security vulnerabilities and controls to remediate risks.
  • Assessing and mitigating software security threat vectors, threat modeling, attack surface analysis, security design reviews, source code reviews, penetration testing or vulnerability assessments.
  • Working in shift left environment to help embed security in Design phase to implement security controls within system architecture.
  • Conducting infrastructure or application security risk assessments.
  • Foundational understanding of Large Language Model (LLM) behaviors, including common strengths and weaknesses (e.g., hallucination, behavior inconsistency, context limitations, reproducibility and verification, etc.).
  • General familiarity with agentic AI workflows and their role in software development and security tooling.

Skills Required

  • Master's degree in Computer Science, Computer Engineering, Information Security, or related field plus 1 year relevant experience OR Bachelor's degree in same fields plus 3 years relevant experience
  • Experience implementing static and dynamic analysis tooling (SAST, DAST) and related testing suites
  • Experience with Infrastructure as Code (IaC) security and control gating
  • Knowledge of application and infrastructure architecture and security (on-premise and cloud)
  • Familiarity with application security best practices including OWASP Top 10, OWASP LLM Top 10, and CWE
  • Experience identifying application security vulnerabilities and implementing remediation controls
  • Experience assessing and mitigating software security threat vectors, threat modeling, attack surface analysis, security design reviews, source code reviews, penetration testing or vulnerability assessments
  • Experience working in a shift-left environment to embed security in the design phase
  • Experience conducting infrastructure or application security risk assessments
  • Foundational understanding of Large Language Model (LLM) behaviors (hallucination, context limits, reproducibility, verification)
  • General familiarity with agentic AI workflows and their role in software development and security tooling

Goldman Sachs Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Goldman Sachs and has not been reviewed or approved by Goldman Sachs.

  • Healthcare Strength Coverage includes medical, dental, vision, disability, life and accident insurance, with multiple plan options and most premiums subsidized; coverage often starts on day one. Wellness resources, on-site health centers in some locations, and EAP access reinforce the depth of health support.
  • Parental & Family Support Family care includes on-site childcare in some offices, expectant parent resources, and transitional programs for returning parents. Feedback suggests parental leave is very generous, with reports of around 20 weeks paid leave and stipends for adoption, surrogacy, and fertility-related services.
  • Retirement Support The firm provides a 401(k) plan with employer matching contributions and broad financial education to help employees plan for retirement. Resources also support saving for education and preparing for unexpected events.

Goldman Sachs Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
67,118 Employees

What We Do

At Goldman Sachs, we believe progress is everyone’s business. That’s why we commit our people, capital and ideas to help our clients, shareholders and the communities we serve to grow. Founded in 1869, Goldman Sachs is a leading global investment banking, securities and investment management firm. Headquartered in New York, we maintain offices in all major financial centers around the world. More about our company can be found at www.goldmansachs.com

Similar Jobs

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Senior Analyst, Advanced Analytics: Auto Physical Damage (APD)

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
7 Locations
40000 Employees
83K-157K Annually

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Inside Sales Representative

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
11 Locations
40000 Employees
45K-85K Annually

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Director I, Product Research

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
6 Locations
40000 Employees
120K-225K Annually

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Inside Sales Representative

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
11 Locations
40000 Employees
45K-85K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account