Full-Time

Engineering

Tech Risk Advisory, Associate

Confirmed live in the last 24 hours

Goldman Sachs

Goldman Sachs

Global investment banking and asset management firm

No salary listed

Junior, Mid

Company Historically Provides H1B Sponsorship

London, UK

Category
Cybersecurity
IT & Security
Required Skills
Agile
Python
Java
Go
Risk Management
Development Operations (DevOps)
Requirements
  • Strong technical, interpersonal, organizational, written, and verbal communication skills
  • Knowledge of Software Development Lifecycle (SDLC)
  • Application Security and Risk Management techniques and methodologies
  • Ability to explain common secure coding practices and application security vulnerabilities, based on guidance from industry recognised cybersecurity frameworks and standards e.g. NIST Cyber Security Framework and OWASP
  • Ability to engage technical client base of engineers and communicate security requirements, potential risks, and influence development practices
  • Ability to communicate security flaws in a clear and concise manner to a broad range of audience from engineers, SMEs to senior management and provide clear remediation guidance
  • Experience with software development methodologies e.g. Agile, DevOps etc.
  • Fluent in at least one major programming language (e.g. Java, Python, Go etc.)
  • Working knowledge of CI/CD platforms e.g. Gitlab, AWS Code Commit and Deploy (or similar)
  • Intermediate Knowledge of DevSecOps solutions i.e. ability to review identified findings, conduct analysis (e.g. impact, accuracy etc.), develop and customise detection capability of one or more of the following solutions: Static Application Security Testing (SAST), Dynamic/Interactive Application Security Testing (DAST/IAST), Software Composition Analysis (SCA), Infrastructure as Code (IaC), Container Security, Mobile Security
Responsibilities
  • Lead and/or support static, dynamic and security awareness services
  • Drive adoption of application security controls within Software Development Life Cycle (SDLC)
  • Review issues identified by S-SDLC tools, ensuring compliance to established review SLAs
  • Interface with Business Units, provide advice and consultation, to help remediate issues identified by S-SDLC tools
  • Develop, and customise rules, to improve detection capability of S-SDLC tools
  • Help engineer tools and solutions that facilitate the adoption of security controls
  • Develop Proof-of-Concepts (PoC), to be shown as solutions, and handover to Engineering for broader rollout
  • Work with engineers to develop customized security testing strategy to complement the existing security testing program managed by Technology Risk
  • Be responsible to communicate program to broader developers’ community for solutions that might impact Developer Experience (DevEx)
  • Be responsible for the awareness, training and guidance on security related issues
  • Conduct product evaluation of solutions that may benefit the S-SDLC program
Desired Qualifications
  • Project management skills
  • Knowledge of Cloud (AWS, GCP, Azure) and Cloud Security applications

Goldman Sachs provides a variety of financial services, including investment banking, asset management, and securities trading. The firm offers advisory services for mergers and acquisitions, helps clients with underwriting securities, and manages assets for a diverse range of clients, such as corporations, governments, and wealthy individuals. Revenue is earned through fees for these advisory services, trading commissions, and asset management fees. What sets Goldman Sachs apart from its competitors is its extensive experience and commitment to social responsibility, which includes initiatives to support small businesses and promote racial equity. The goal of Goldman Sachs is to deliver high-quality financial services while also making a positive impact on society.

Company Size

N/A

Company Stage

IPO

Headquarters

New York City, New York

Founded

1869

Simplify Jobs

Simplify's Take

What believers are saying

  • AI-driven platforms like 73 Strings offer growth in financial intelligence and data valuation.
  • Sustainable infrastructure investments align with social responsibility and offer long-term growth.
  • Expansion in digital health solutions like Fay indicates potential in health-focused financial products.

What critics are saying

  • Increased competition from firms like Tiger Global investing in tech platforms like Mews.
  • Internal competition may arise from AI-driven platforms like 73 Strings within Goldman Sachs.
  • Focus on social responsibility may divert resources from more profitable ventures.

What makes Goldman Sachs unique

  • Goldman Sachs excels in AI-driven financial intelligence with investments like 73 Strings.
  • The firm is a leader in sustainable infrastructure, funding projects like Milwaukee's stormwater system.
  • Goldman Sachs is expanding in digital nutritional therapy, investing in companies like Fay.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

Health Savings Account/Flexible Spending Account

Paid Vacation

Paid Sick Leave

Paid Holidays

Professional Development Budget

Company News

Investing.com
Mar 19th, 2025
DENTSPLY SIRONA secures $435 million bridge loan

DENTSPLY SIRONA secures $435 million bridge loan.

PR Newswire
Mar 4th, 2025
Mews Secures Major Investment to Cement Industry Leadership and Redefine Hospitality Management

/PRNewswire/ -- Mews, the leading hospitality technology platform, today announced it has raised $75 million, led by Tiger Global, a leading global investment...

Business Wire
Feb 20th, 2025
73 Strings Secures $55m Series B Led by Growth Equity at Goldman Sachs Alternatives

73 Strings, the financial intelligence platform using AI to revolutionize data extraction, monitoring, and valuation for the $17.6 Trillion AUM Altern

Business Wire
Feb 15th, 2025
Sarepta Therapeutics Announces Inaugural $600 Million Senior Secured Revolving Credit Facility

Sarepta Therapeutics, Inc. (NASDAQ:SRPT), the leader in precision genetic medicine for rare diseases, announced today that it has closed on a $600 mil

Business Wire
Feb 14th, 2025
Newleos Therapeutics Debuts with $93.5 Million Oversubscribed Series A Financing to Transform the Treatment of Neuropsychiatric Disorders through the Advancement of Novel Medicines

Newleos Therapeutics, Inc., a clinical stage neuroscience company co-founded by Longwood Fund and seasoned leaders in CNS drug development, today anno