Security Engineer - Dallas - Vice President

The Goldman Sachs Group

Dallas (TX)

On-site

USD 100,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

The Goldman Sachs Group in Dallas, Texas, is seeking an experienced Application Security Engineer to secure applications against cyber threats. You will perform software architecture design reviews, mentor team members, and work with cutting-edge security tools.

The ideal candidate has 3+ years in application security, knowledge of AWS, and strong communication skills. Join us to help protect our firm and develop secure applications.

Qualifications

  • 3+ years of experience in application and cloud security.
  • Knowledge of common application security vulnerabilities like OWASP Top 10.
  • Good written and oral communication skills.

Responsibilities

  • Perform software architecture design reviews for AWS deployments.
  • Mentor junior team members.
  • Develop secure architecture design patterns.

Skills

Application security
Cloud security
AWS
Threat Modeling
Secure Design Reviews
Pentesting
Communication skills

Education

MS in Computer Science or related field

Tools

Application security tools
AWS security services
Infrastructure-as-code tools

Job description

WHO WE ARE

Led by the Chief Information Security Officer (CISO), Technology Risk secures Goldman Sachs against hackers and other cyber threats. We are responsible for detecting and preventing attempted cyber intrusions against the firm, helping the firm develop more secure applications and infrastructure, developing software in support of our efforts, measuring cybersecurity risk, and designing and driving implementation of cybersecurity controls. The team has a global presence across the Americas, APAC, India, and EMEA.

HOW YOU WILL FULFILL YOUR POTENTIAL

Your responsibilities will include:

  • Perform software architecture design reviews for on-premise or cloud deployments, with a focus on AWS.
  • Serve as an Application security liaison for the developers and architects in the respective Business Unit.
  • Review security assessment reports from pentest and code review engagements.
  • Conduct Read-out Calls with the business to articulate risk and recommend a mitigation strategy.
  • Develop secure architecture design patterns, particularly for cloud-native applications on AWS.
  • Leverage and integrate AI/LLM-driven tools to streamline security review workflows
  • Mentor other junior members of the team.
BASIC QUALIFICATIONS
  • 3 or more years' experience in one or more technical roles (focusing on application security and cloud security).
  • Prior experience in performing Threat Modeling or Secure Design Reviews or Secure Architecture Reviews.
  • Knowledge of most common Application Security vulnerabilities - e.g., OWASP Top 10 and cloud security gaps.
  • Familiarity with Security standards such as OWASP Testing Guide, OWASP ASVS, NIST, and SANS Top 20.
  • Common security controls and how they apply to different designs and systems, including but not limited to secure authentication, access controls, encryption (at rest/in transit), IDS/IPS, DLP, malware, etc.
  • Experience in application vulnerability assessment and penetration testing of web, thick-client, or mobile applications.
  • Working knowledge of application security tools such as fuzzers, scanners, debuggers, decompilers, proxies, simulators, etc.
  • Familiarity with modern and common web stack technologies (e.g., HTTP, HTML5, AJAX, REST, etc.) and platforms (e.g., DropWizard, Spring Boot, AngularJS, React, Tomcat, .Net, Sybase, MS SQL, MongoDB, etc.).
  • Familiarity with common cloud services, recommended security best practices, and secure deployment patterns. AWS is preferred.
  • Understanding of core cryptography concepts (Encryption, Hashing, HMAC, digital signatures) and how they are applied and attacked in web applications (e.g., TLS attacks, CBC attacks).
  • Ability to analyze protocols (OAuth, SAML, OIDC), flows, and interactions in a system design to evaluate gaps.
  • Ability to identify threats, abuse cases, and gaps in the design before it is implemented.
  • Good written and oral communication to be able to articulate risks to both technical and management stakeholders.
PREFERRED QUALIFICATIONS
  • Experience in crafting custom proof-of-concept application exploits using testing tools/frameworks or scripting exploits in Python, Perl, JavaScript, Shell scripting, etc.
  • Knowledge of network, application, and operating system security risks.
  • MS. in Computer Science, System/Computer Engineering, Cyber-Security, or Information Security.
  • Experience or training in related disciplines, e.g., computer science, computer security, software development, system design, open-source frameworks, encryption schemes, etc.
  • Experience doing architecture review of Mobile applications.
  • Strong experience with AWS security services and best practices (e.g., IAM, Security Groups, KMS, CloudTrail, GuardDuty, Inspector).
  • Experience securing trading and payments platforms, including knowledge of relevant compliance requirements (e.g., PCI DSS).
  • Experience with infrastructure-as-code tools such as Terraform, CloudFormation or AWS CDK.
  • AWS certifications (e.g., AWS Certified Security - Specialty).
LEGAL & EQUITY STATEMENTS

We're committed to finding reasonable accommodations for candidates with special needs or disabilities during our recruiting process. https://www.goldmansachs.com/careers/footer/disability-statement.html

The Goldman Sachs Group, Inc., 2022. All rights reserved. Goldman Sachs is an equal employment/affirmative action employer Female/Minority/Disability/Veteran/Sexual Orientation/Gender Identity

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer - Dallas - Vice President
Security Engineer - Dallas - Vice President

Goldman Sachs • Dallas (WV)

On-site
USD 90,000 - 120,000
Diversity and inclusion programs
Professional development opportunities
Wellness and personal finance offerings
Security Engineer - Dallas - Vice President
Security Engineer - Dallas - Vice President

Goldman Sachs • Dallas (TX)

On-site
USD 140,000 - 200,000
Engineering Division – Dallas - Vice President, Security Engineering - 10427704
Engineering Division – Dallas - Vice President, Security Engineering - 10427704

Socket.dev • Dallas (TX)

On-site
USD 180,000 - 260,000
Tech Risk - Security Architecture- VP- Dallas
Tech Risk - Security Architecture- VP- Dallas

Goldman Sachs Group, Inc. • Dallas (TX)

On-site
USD 150,000 - 200,000
Generous vacation policy
On-site health centers
Child care assistance
AMD Public-Dallas-Associate-Security Engineering
AMD Public-Dallas-Associate-Security Engineering

The Goldman Sachs Group • Town of Texas (WI)

On-site
USD 90,000 - 120,000
Engineering Division - Dallas - Vice President, Security Engineering
Engineering Division - Dallas - Vice President, Security Engineering

Goldman Sachs • Dallas (WV)

On-site
USD 180,000 - 240,000
Engineering Division – Dallas - Vice President, Security Engineering - 10427704
Engineering Division – Dallas - Vice President, Security Engineering - 10427704

Goldman Sachs • Dallas (TX)

On-site
USD 180,000 - 240,000
Engineering Division - Dallas - Vice President, Security Engineering - 10427704
Engineering Division - Dallas - Vice President, Security Engineering - 10427704

The Goldman Sachs Group • Town of Texas (WI)

On-site
USD 180,000 - 260,000
Engineering Division – Dallas - Vice President, Security Engineering - 10427704
Engineering Division – Dallas - Vice President, Security Engineering - 10427704

Goldman Sachs Group, Inc. • Dallas (TX)

On-site
USD 140,000 - 210,000
Vice President - Dallas - Technology Risk - Cloud Security Architecture
Vice President - Dallas - Technology Risk - Cloud Security Architecture

The Goldman Sachs Group • Dallas (TX)

Hybrid
USD 140,000 - 210,000