Technology Risk - Dallas - Security Engineering - Associate

The Goldman Sachs Group Inc
  • Dallas, TX
    12 days ago

    Job Description

    WHO WE ARE

    Led by the Chief Information Security Officer (CISO), Technology Risk secures Goldman Sachs against hackers and other cyber threats. We are responsible for detecting and preventing attempted cyber intrusions against the firm, helping the firm develop more secure applications and infrastructure, developing software in support of our efforts, measuring cybersecurity risk, and designing and driving implementation of cybersecurity controls. The team has global presence across the Americas, APAC, India and EMEA. Within Technology Risk, The Global Cyber Defense and Intelligence (GCDI) team identifies malicious activity, manages the lifecycle of vulnerabilities within GS technologies, and investigates and manages threats across the firm. We are a team of security, software, and product engineers that allow the firm to respond appropriately to firm risks using detection models, security architecture, and cutting-edge cyber threat analysis to manage internal and external threats against the firm.

    YOUR IMPACT

    In this role, you will work on an advanced threat detection and response team to proactively identify threats, deliver rapid responses, and develop detections using large data sets and analytic techniques such as standard deviation, simple matching, stack counting, outlier detection, regex, entity-based analysis, AI, and event-based methods. You will also have opportunities to automate incident response workflows and remediation activities to increase the efficacy of our incident response efforts.

    HOW YOU WILL FULFILL YOUR POTENTIAL

    As a Security Engineer in GCDI's Threat Management Center, you will be an integral part of a technical team that is responsible for providing the GCDI organization with security sensors and data sets that increase awareness of current and potential Cyber Threats. The ideal candidate should be someone with cyber security experience, hands-on technical skills on Windows, Linux and Network security, along with experience in utilizing security information for detection engineering, live intrusions and triage security events in real-time.

    Job Responsibilities:

    • Analyze potential infrastructure security incidents to determine if incident qualifies as a legitimate security breach
    • Perform host-based and network forensic investigations, determining the cause of the security incident and preserving evidence for potential legal action
    • Participate in a 24x7 on-call coverage model to prevent and remediate security threats against Goldman Sachs' global business network
    • Improve the security sensors by looking for opportunities to tune the security controls in response to an evolving security threat landscape
    • Lead the security projects/tasks assigned by taking ownership of planning, implementation & coordination
    • Develop use cases based on adversarial tactics, techniques and procedures (TTPs), and tuning event detection rules to optimize detection efficacy
    • Build anomaly detections by applying statistical principles such as standard deviation, stack counting, simple match and regular expression
    • Script in languages such as Python, PowerShell or Bash to build incident response workflows and automation

    Basic Qualifications:

    • Strong English verbal and written communication skills
    • Strong presentation skills
    • Highly motivated and passionate learner
    • Strong sense of ownership and driven to manage tasks to completion
    • Proficient scripting skills in Python and PowerShell
    • Advanced understanding of Linux Operating Systems
    • Designing Cloud architecture including security setup, and Incident response strategy
    • Hands-on experience in the use of Forensics toolkits such as Volatility, Rekall, The Sleuth Kit, Autopsy, and EnCase
    • Ability to conduct cyber security investigations as a Level 2 analyst
    • Understanding of how to use artificial intelligence tools to enhance productivity and security of the firm

    Preferred qualifications:

    • 1-4 years'' experience with expertise in triaging, analyzing & responding to different security events and conducting digital forensics on Windows, MacOS or Linux operating systems
    • Knowledge conducting incident response within a major public cloud (i.e. AWS, Google, Azure)
    • At least one of the following certifications: GNFA, GCFE, GCFA, CCFP, CFCE, ACE, OSCP, GCFR
    • Experience in security monitoring and cyber defense against AI-powered cyber attacks

    Numbers & Facts

    LocationDallas, TX

    Skills

    • Amazon Web Services (AWS)unmatched
    • Analysis Skillsunmatched
    • Architectural Designunmatched
    • Artificial Intelligence (AI)unmatched
    • Automationunmatched
    • Autopsyunmatched
    • Bash Scriptingunmatched
    • Cloud Architectureunmatched
    • Communication Skillsunmatched
    • Computer Forensicsunmatched
    • Computer Hackingunmatched
    • Computer Securityunmatched
    • Cyber Investigationunmatched
    • Data Analysisunmatched
    • Data Setsunmatched
    • Defense Intelligenceunmatched
    • EnCaseunmatched
    • English Languageunmatched
    • Forensic Toolkit (FTK)unmatched
    • GCFA - GIAC Certified Forensic Analystunmatched
    • Incident Responseunmatched
    • Information/Data Security (InfoSec)unmatched
    • Infrastructure Softwareunmatched
    • International Businessunmatched
    • Internet Securityunmatched
    • Intrusion Detection and Prevention (IDP)unmatched
    • Legalunmatched
    • Linux Operating Systemunmatched
    • Mac Operating Systemunmatched
    • Microsoft Windows Azureunmatched
    • Microsoft Windows Operating Systemunmatched
    • Network Securityunmatched
    • On Callunmatched
    • Presentation/Verbal Skillsunmatched
    • Problem Solving Skillsunmatched
    • Product Engineeringunmatched
    • Product Lifecycleunmatched
    • Public Cloudunmatched
    • Python Programming/Scripting Languageunmatched
    • Regular Expressionsunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Modelingunmatched
    • Scripting (Scripting Languages)unmatched
    • Security Analysisunmatched
    • Security Architectureunmatched
    • Security Attacksunmatched
    • Security Monitoringunmatched
    • Security Softwareunmatched
    • Sleuth Kitunmatched
    • Software Administrationunmatched
    • Software Developmentunmatched
    • Use Casesunmatched
    • Windows PowerShellunmatched
    • Writing Skillsunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder