Secure SDLC Associate - Dallas - Technology Risk

The Goldman Sachs Group

Dallas (TX)

On-site

USD 140,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

The Goldman Sachs Group is seeking a lead for Secure SDLC security, guiding static and dynamic analysis and security awareness across all SDLC stages. The role supports AI-augmented capabilities and embedding security controls in embedded applications.

You will drive tooling adoption (SAST, DAST, IaC), collaborate with Business Units to remediate issues, and design scalable security solutions for global platforms.

Qualifications

  • Experience applying secure SDLC practices across multiple projects.
  • Experience with security testing: static, dynamic, and software composition.
  • Familiarity with LLM security concepts including hallucination and verification.

Responsibilities

  • Lead and support static and dynamic analysis implementations.
  • Evaluate and adopt AI-augmented capabilities within Secure SDLC services.
  • Drive integration of embedded application security controls.
  • Interface with Business Units to secure applications and remediate issues.
  • Develop and maintain Secure SDLC solutions for global businesses.
  • Design scalable technology solutions leveraging internal and open-source services.
  • Assist in requirements gathering, development, testing, deployment, and QA.
  • Work with internal teams to develop secure solution designs.

Skills

Security analysis
Threat modeling
Vulnerability assessment
Security in SDLC
Shift-left security

Education

Master's degree in Computer Science/Information Security/related field
Bachelor's degree in Computer Science/Computer Engineering/Information Security/related field

Tools

SAST
DAST
IaC security tools

Job description

Lead and support the implementation of static and dynamic analysis, as well as security awareness initiatives across all stages of the Secure Software Development Lifecycle (Secure SDLC).

Support the evaluation and adoption of AI-augmented capabilities within Secure SDLC services, including static and dynamic analysis tooling (SAST, DAST, IaC, Control Gating, etc.).

Drive the integration and adoption of embedded application security controls within SDLC ecosystem.

Interface with Business Units to help build secure applications and remediate issues identified by automated tools.

Develop, enhance, support and maintain the Firm's Secure SDLC solutions in support of its global businesses.

Design and implement high-quality, scalable and thoughtful technology solutions leveraging both internal and open-source services.

Assist in requirements gathering, user experience refinement, development, testing (unit, integration and regression), User Acceptance Testing (UAT), Deployment, and Quality Assurance (QA).

Work with internal teams to help develop secure solution designs.

Identify new external technologies that can be used to transform our financial businesses and internal platforms in innovative and disruptive ways.

Work in all phases of the Secure SDLC to meet internal and regulatory requirements.

Design, implement and maintain robust testing suites to enable secure, complete, and scalable solutions across our business lines.

Maintain awareness of emerging technologies (including but not limited to) agentic AI workflows and their potential application to Secure SDLC processes.

Master's degree (U.S. or foreign equivalent) in Computer Science, Computer Engineering, Information Security, or a related field and one (1) year of experience in the job offered or a related role.

OR

Bachelor's degree (U.S. or foreign equivalent) in Computer Science, Computer Engineering, Information Security, or a related field and three (3) years of experience in the job offered or a related role.

Special Skills and/or Licenses Required to Perform the Job

Prior experience should include one (1) year (with a Master's degree) or three (3) years (with a Bachelor's degree) with:

  • Application and infrastructure architecture and security (on premise and Cloud).
  • Application security best practices including OWASP Top 10, OWASP LLM Top 10, and CWE.
  • Application security vulnerabilities and controls to remediate risks.
  • Assessing and mitigating software security threat vectors, threat modeling, attack surface analysis, security design reviews, source code reviews, penetration testing or vulnerability assessments.
  • Working in shift left environment to help embed security in Design phase to implement security controls within system architecture.
  • Conducting infrastructure or application security risk assessments.
  • Foundational understanding of Large Language Model (LLM) behaviors, including common strengths and weaknesses (e.g., hallucination, behavior inconsistency, context limitations, reproducibility and verification, etc.).
  • General familiarity with agentic AI workflows and their role in software development and security tooling.

Helping all candidates find great careers is our goal. The information you provide here is secure and confidential.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Secure SDLC Associate - Dallas - Technology Risk
Secure SDLC Associate - Dallas - Technology Risk

Goldman Sachs • Dallas (TX)

On-site
USD 120,000 - 180,000
Secure SDLC Associate - Dallas - Technology Risk
Secure SDLC Associate - Dallas - Technology Risk

Goldman Sachs Group, Inc. • Dallas (TX)

On-site
USD 120,000 - 180,000
On-site health centers
Medical advocacy service
Employee Assistance Program (EAP)
Engineering Division - Dallas - Associate, Security Engineering - 10431284
Engineering Division - Dallas - Associate, Security Engineering - 10431284

The Goldman Sachs Group • Town of Texas (WI)

On-site
USD 120,000 - 150,000
Assoc, Security Engineering
Assoc, Security Engineering

Agupdate • Dallas (TX), Northern (KY)

Hybrid
USD 120,000 - 170,000
Security training
Secure SDLC Associate: Build Secure, Scalable Software
Secure SDLC Associate: Build Secure, Scalable Software

Goldman Sachs • Dallas (TX)

On-site
USD 120,000 - 180,000
Sr. Application Engineer, Cyber Security
Sr. Application Engineer, Cyber Security

inmar • Winston-Salem (NC)

On-site
USD 120,000 - 180,000
Senior Application Security Engineer
Senior Application Security Engineer

AgileEngine • United States

Hybrid
USD 120,000 - 180,000
Flextime
Professional growth
Competitive compensation
+2
Engineering Division - Dallas - Associate, Security Engineering - 10427737
Engineering Division - Dallas - Associate, Security Engineering - 10427737

The Goldman Sachs Group • Town of Texas (WI)

On-site
USD 140,000 - 180,000
Engineering Division - Dallas - Associate, Security Engineering - 10427737
Engineering Division - Dallas - Associate, Security Engineering - 10427737

Socket.dev • Dallas (TX)

On-site
USD 120,000 - 190,000
Application & Web Security Specialist
Application & Web Security Specialist

Dillards • Little Rock (AR)

On-site
USD 85,000 - 120,000