Security Engineer - Vice President - IAM - Jersey City

Goldman Sachs•Jersey City, NJ
•$130,000 - $250,000•Hybrid

About The Position

Identity Security is part of the Identity and Access Management (IAM) business unit within Foundation Engineering Division of Goldman Sachs. The Senior Vice President (SVP) of Certificate and PKI Technologies will serve as the leader responsible for global strategy, engineering, deployment, and operations of the enterprise Public Key Infrastructure (PKI), cryptography, and digital certificate lifecycle management. This role is critical to securing the enterprise's digital identity footprint across multi-cloud, on-premises, and IoT environments. The VP will lead a high-performing team of security engineers to ensure robust, compliant, and highly available trust services that align with industry standards set by organizations like the NIST Computer Security Resource Center and the CA/Browser Forum.

Requirements

  • Ability to thrive in our global organization in a fast paced, result oriented, hybrid workplace.
  • Team player, eager to work in a global organization.
  • Enjoys working in an Agile environment.
  • Strong emphasis on personal initiative and ownership.
  • Customer focused and values good developer experience.
  • A passion for learning new technologies.

Nice To Haves

  • 10+ years of experience in cybersecurity and information technology, with at least 8+ years of dedicated leadership experience in PKI, cryptography, and data protection.
  • Deep understanding of asymmetric/symmetric cryptography, TLS/SSL protocols, SSH key management, code signing, and HSM management.
  • Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Cryptography, or a related field.
  • Preferred certifications include CISSP, CISM, or specialized cryptographic credentials.

Responsibilities

  • Define and execute the global enterprise roadmap for PKI, certificate management, and cryptographic services, ensuring alignment with overall cybersecurity and business objectives.
  • Oversee the design, implementation, and maintenance of internal and external Certificate Authorities (CAs), Registration Authorities (RAs), Hardware Security Modules (HSMs), and Key Management Systems (KMS).
  • Drive the adoption of automated certificate lifecycle management (CLM) tools and protocols (e.g., ACME, EST, SCEP) to eliminate manual processes and prevent outages caused by expired certificates.
  • Ensure strict adherence to cryptographic standards, industry regulations, and audit requirements (e.g., WebTrust, SOC2, ISO 27001). Establish and maintain the enterprise Certificate Policy and Certification Practice Statement (CP/CPS).
  • Architect scalable PKI solutions tailored for modern environments, including Kubernetes, service meshes and hybrid-cloud deployments (AWS, Azure, GCP).
  • Serve as the escalation point for cryptographic vulnerabilities, certificate-related outages, and emergency key rotations.
  • Manage relationships with external Certificate Authorities and security vendors. Represent the organization in industry consortiums to stay ahead of emerging cryptographic trends, such as Post-Quantum Cryptography (PQC).

Benefits

  • Discretionary bonus
  • Competitive benefits and wellness offerings
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service