Jobs · Information Technology · Texas

Secure SDLC Associate - Dallas - Technology Risk

Goldman Sachs · Dallas, TX · 3 wk ago
Information TechnologyFull-time

Responsibilities

  • Lead and support the implementation of static and dynamic analysis, as well as security awareness initiatives across all stages of the Secure Software Development Lifecycle (Secure SDLC).
  • Support the evaluation and adoption of AI-augmented capabilities within Secure SDLC services, including static and dynamic analysis tooling (SAST, DAST, IaC, Control Gating, etc.).
  • Drive the integration and adoption of embedded application security controls within the SDLC ecosystem.
  • Interface with Business Units to help build secure applications and remediate issues identified by automated tools.
  • Develop, enhance, support, and maintain the Firm's Secure SDLC solutions in support of its global businesses.
  • Design and implement high-quality, scalable, and thoughtful technology solutions leveraging both internal and open-source services.
  • Assist in requirements gathering, user experience refinement, development, testing (unit, integration, and regression), User Acceptance Testing (UAT), Deployment, and Quality Assurance (QA).
  • Work with internal teams to help develop secure solution designs.
  • Identify new external technologies that can be used to transform financial businesses and internal platforms in innovative and disruptive ways.
  • Work in all phases of the Secure SDLC to meet internal and regulatory requirements.
  • Design, implement, and maintain robust testing suites to enable secure, complete, and scalable solutions across business lines.
  • Maintain awareness of emerging technologies (including but not limited to agentic AI workflows) and their potential application to Secure SDLC processes.

Requirements

  • Master's degree (U.S. or foreign equivalent) in Computer Science, Computer Engineering, Information Security, or a related field and one (1) year of experience in the job offered or a related role.
  • OR Bachelor's degree (U.S. or foreign equivalent) in Computer Science, Computer Engineering, Information Security, or a related field and three (3) years of experience in the job offered or a related role.

Skills

Prior experience should include one (1) year (with a Master's degree) or three (3) years (with a Bachelor's degree) with:

  • Application and infrastructure architecture and security (on-premise and Cloud).
  • Application security best practices including OWASP Top 10, OWASP LLM Top 10, and CWE.
  • Application security vulnerabilities and controls to remediate risks.
  • Assessing and mitigating software security threat vectors, threat modeling, attack surface analysis, security design reviews, source code reviews, penetration testing, or vulnerability assessments.
  • Working in a shift-left environment to help embed security in the Design phase to implement security controls within system architecture.
  • Conducting infrastructure or application security risk assessments.
  • Foundational understanding of Large Language Model (LLM) behaviors, including common strengths and weaknesses (e.g., hallucination, behavior inconsistency, context limitations, reproducibility, and verification).
  • General familiarity with agentic AI workflows and their role in software development and security tooling.

Similar jobs