Search by job, company or skills

Goldman Sachs

Engineering-Bengaluru-Vice President-Security Engineering

8-14 Years

This job is no longer accepting applications

new job description bg glownew job description bg glownew job description bg svg
  • Posted 2 months ago

Job Description

Job Responsibilities:

  • Lead and/or support static, dynamic and security awareness services.
  • Drive adoption of application security controls within Software Development Life Cycle (SDLC).
  • Review issues identified by S-SDLC tools, ensuring compliance to established review SLAs.
  • Interface with Business Units, provide advice and consultation, to help remediate issues identified by S-SDLC tools.
  • Develop, and customise rules, to improve detection capability of S-SDLC tools.
  • Help engineer tools and solutions that facilitate the adoption of security controls.
  • Develop Proof-of-Concepts (PoC), to be shown as solutions, and handover to Engineering for broader rollout.
  • Work with engineers to develop customized security testing strategy to complement the existing security testing program managed by Technology Risk.
  • Be responsible to communicate program to broader developers community for solutions that might impact Developer Experience (DevEx).
  • Be responsible for the awareness, training and guidance on security related issues.
  • Conduct product evaluation of solutions that may benefit the S-SDLC program.

Basic Qualifications:

You will use your strong technical, interpersonal, organizational, written, and verbal communication skills to interact with your internal clients locally and globally. Your knowledge of Software Development Lifecycle (SDLC), Application Security and Risk Management techniques and methodologies will enable you to be an active member of the team along with your professional experience in one, or more, of the following disciplines:

  • Ability to explain common secure coding practices and application security vulnerabilities, based on guidance from the industry recognised cybersecurity frameworks and standards e.g. NIST Cyber Security Framework and OWASP.
  • Ability to engage technical client base of engineers and communicate security requirements, potential risks, and influence development practices.
  • Ability to communicate security flaws in a clear and concise manner to a broad range of audience from engineers, SMEs to senior management and provide clear remediation guidance.
  • Experience with software development methodologies e.g. Agile, DevOps etc.
  • Fluent in at least one major programming language (e.g. Java, Python, Go etc.)
  • Working knowledge of CI/CD platforms e.g. Gitlab, AWS Code Commit and Deploy (or similar).
  • Intermediate Knowledge of DevSecOps solutions i.e. ability to review identified findings, conduct analysis (e.g. impact, accuracy etc.), develop and customise detection capability of one or more of the following solutions:
  • Static Application Security Testing (SAST)
  • Dynamic/Interactive Application Security Testing (DAST/IAST)
  • Software Composition Analysis (SCA)
  • Infrastructure as Code (IaC)
  • Container Security
  • Mobile Security

Preferred qualifications:

  • Project management skills
  • Knowledge of Cloud (AWS, GCP, Azure) and Cloud Security applications

More Info

Job Type:
Function:
Employment Type:
Open to candidates from:
Indian

About Company

Goldman Sachs Asset Management is one of the world’s leading investment managers. GSAM provides institutional and individual investors with investment and advisory solutions, with strategies spanning asset classes, industries, and geographies. We help our clients navigate today’s dynamic markets, and identify the opportunities that shape their portfolios and long-term investment goals. We extend these global capabilities to the world’s leading pension plans, sovereign wealth funds, central banks, insurance companies, financial institutions, endowments, foundations, individuals and family offices.
We provide innovative investment solutions to help our clients meet their financial goals. We work with client coverage and product teams around the globe to help our institutional and retail clients across various industries navigate changing markets and make smart investments. We value self-starters with an entrepreneurial spirit, but still provide the support and resources to ensure your success.

Job ID: 118945163