Security Engineering - Vice President
The Goldman Sachs Group Inc
New York, NY, United States
1 day ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on jobs.localjobnetwork.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$150,000.0 - $250,000.0
Working hours
Regular working hours
Job source
Tech stack
Kubernetes Security
Application Programming Interfaces (APIs)
Artificial Intelligence
Amazon Web Services
Data Analysis
Microsoft Azure
Bash Shell
Cloud Computing Security
Cloud Engineering
Cyber Security
Data Governance
Software Design Patterns
+31 more
Identity and Access Management
Intrusion Detection and Prevention
Python (Programming Language)
Key Management
Network Security
Machine Learning
Open Web Application Security
Windows PowerShell
Systems Development Life Cycle
Cloud Services
Azure Machine Learning
Systems Integration
Software Vulnerability Management
Data Logging
Scripting
Google Cloud
Cloud Platform System
Large Language Models
Software Security
Generative AI
Agentic-AI
National Institute of Standards and Technology Cybersecurity Framework
AI Platforms
Data Management
Machine Learning Operations
Prompt Injection
CIS Benchmarks
Oracle Cloud Infrastructure
Databricks
Vulnerability Analysis
Microservices
Job description
- Conduct comprehensive cloud security assessments, evaluating designs, configurations, and implementations across major cloud service providers (CSPs) including AWS, Azure, and GCP.
- Architect and drive enterprise-wide cloud security strategies, including baselines, guardrails, and secure design patterns for cloud-native and hybrid environments.
- Identify and analyze potential security risks, vulnerabilities, and misconfigurations within cloud environments, AI/ML platforms, and applications.
- Perform software architecture design reviews for cloud deployments, including AI/ML pipelines, LLM integrations, agentic frameworks, and data platforms.
- Develop and enforce security controls for AI/ML systems, covering model security, data governance, prompt injection defenses, supply chain integrity, and inference infrastructure hardening.
- Collaborate with AI engineering, platform, and development teams to embed security throughout the SDLC and CI/CD pipelines, including AI[1]specific development workflows.
- Develop, evaluate, and document security measures, controls, and guardrails to protect data, applications, APIs, and infrastructure across cloud and AI environments.
- Provide senior technical advisory services on cloud security, AI security, and security engineering to internal stakeholders, ensuring alignment with firm-wide security policies and industry best practices.
- Develop and maintain scripts, automated solutions, and security tooling to streamline security processes, vulnerability identification, and compliance checks across cloud and AI environments.
- Stay current on emerging threats across cloud, AI/ML, and security engineering domains, including adversarial ML techniques, cloud-native attack vectors, and evolving regulatory requirements.
- Lead and mentor technical security teams; influence senior stakeholders and align security posture with business objectives.
- Contribute to incident response and remediation efforts related to cloud security and AI security events as required.
Requirements
- 12+ years of hands-on experience in cybersecurity, with depth spanning in the following domains:
- Cloud Security: Architecting and assessing security for cloud-native and hybrid environments across major CSPs (AWS, Azure, GCP, OCI).
- Security Engineering: Building security tooling, automation, detection capabilities, or secure-by-design systems at scale.
- AI Engineering Security: Securing AI/ML systems, LLM-based applications, agentic pipelines, or ML infrastructure.
- Cybersecurity Generalist: Broad cross-domain expertise including network security, identity and access management, threat modeling, vulnerability management, incident response, and compliance.
- Strong development and scripting proficiency (Python, PowerShell, Bash, or similar) for automation, security tooling, and data analysis.
- Deep, demonstrated knowledge of cloud security architecture across at least one major CSP (AWS strongly preferred), including IAM, network security, encryption/key management, workload/container security, and monitoring/logging.
- Technical expertise in application security architecture, including secure-by-design patterns, threat modeling, and enterprise AppSec standards for web, API, and microservices environments.
- Proven experience securing AI/ML systems or platforms, including familiarity with threats specific to LLMs, model pipelines, and AI supply chains.
- Proven track record driving security initiatives across large, complex enterprise environments with cross-functional impact., * Experience in financial services or other highly regulated industries, with familiarity with relevant compliance frameworks.
- Advanced knowledge of industry security frameworks and standards (e.g., NIST AI RMF, NIST CSF, ISO 27001, CIS Benchmarks, MITRE ATLAS, OWASP LLM Top 10).
- Familiarity with AI/ML security frameworks including OWASP LLM Top 10, MITRE ATLAS, and NIST AI Risk Management Framework.
- Strong leadership and communication skills to influence at the executive level, mentor technical teams, and represent security in cross-functional forums.
- Relevant certifications across security and cloud domains (e.g., CISSP, CCSP, AWS Certified Security - Specialty, Azure Security Engineer
- Associate, Google Cloud Professional Cloud Security Engineer, GIAC certifications).
- Experience with MLOps, model deployment pipelines, and AI platform security (e.g., SageMaker, Vertex AI, Azure ML, Databricks).
- Hands-on experience with red teaming, or adversarial testing of AI/ML systems
Benefits & conditions
The expected base salary for this New York, New York, United States-based position is $150000-$250000. In addition, you may be eligible for a discretionary bonus if you are an active employee as of fiscal year-end.
About the company
- Led by the Chief Information Security Officer (CISO), Technology Risk secures Goldman Sachs against hackers and other cyber threats. We are responsible for detecting and preventing attempted cyber intrusions against the firm, helping the firm develop more secure applications and infrastructure, developing software in support of our efforts, measuring cybersecurity risk, and designing and driving implementation of cybersecurity controls. The team has a global presence across the Americas, APAC, India, and EMEA.
- Within Technology Risk, Advisory is the consultative and technology subject matter expertise arm, responsible for assessing new technology initiatives for risk, partnering with engineers to architect and design secure products and services, embedding implementation reviews as part of the SDLC and CI/CD pipeline via code analysis and penetration testing, and guiding technology innovation in terms of security and control across Goldman Sachs. The team plays a critical role in designing and assessing controls for our transition to building native public cloud applications, as well as securing the firm’s rapidly expanding AI/ML infrastructure and engineering platforms.
- Goldman Sachs has one of the most progressive Technology Risk teams in the industry and is continuing to push the development of risk in preference to security within technology and the business. Year-on-year success has led the team to work deeper into the organization and gain valuable insights into how technology needs to function, what its risk really is, and how this impacts the business.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on jobs.localjobnetwork.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Loading talks and stories from around this role…