Skip to main content
Goldman Sachs

Associate Security Engineer - IAM

2d

Goldman Sachs

Warsaw, PL · Full-time · PLN 180,000 – PLN 280,000

About this role

Led by the Chief Information Security Officer, Technology Risk secures Goldman Sachs against cyber threats. The VIDM TechRisk team serves as the consultative subject matter expertise arm responsible for assessing new technology initiatives for risk and guiding secure product architecture across the firm.

In this role you will join the global Identity and Access Management pillar, specifically the IAM Security, Strategy, Architecture and Platforms sub-pillar. Daily work centers on identifying software security flaws and delivering security assurance advice to engineers managing application risks.

The IAM team collaborates with Engineering Teams, Operational Risk, and Internal Audit to establish robust controls. You will interact with all parts of the firm while contributing to ongoing testing, monitoring, and policy development across the IAM domain.

You will become a trusted Risk Advisor with the discipline to communicate technology risks and mitigation approaches in a global environment. The position offers direct exposure to senior management and the Board on changes in the information security landscape.

Requirements

  • Experience integrating and tuning software security controls within continuous deployment SDLC.
  • Ability to review, triage, and remediate security findings by interfacing with Business Units.
  • Capability to help raise developer security awareness.

Responsibilities

  • Collaborate with Technology Risk on information security and cybersecurity risk management across the IAM domain.
  • Establish and maintain policies, standards, and controls to address information security risks in accordance with best practices and regulations.
  • Conduct ongoing testing and monitoring to evaluate adoption of necessary engineering controls.
  • Ensure senior management and the Board of Directors remain informed of changes in the information security environment.
  • Identify software security flaws and provide security assurance advice to engineers managing application risks.
  • Review, triage, and remediate findings by interfacing with Business Units.
  • Help raise developer security awareness through guidance on secure development practices.