Engineering Division-New York-Vice President, Risk Governance-10424173

Goldman SachsNew York, NY
$176,000 - $264,000Onsite

About The Position

Goldman Sachs Services LLC is seeking a Vice President, Risk Governance in New York, New York. This role involves leading the transformation and optimization of the Technology Risk function to enhance the effectiveness and efficiency of the information security and cyber security program. The position requires partnering with Technology Risk and Engineering leadership to set clear, measurable goals and align transformation activities with divisional strategic objectives and regulatory requirements. Key responsibilities include performing Application Security Assessments (Code Review, Penetration Test, Design Review, Threat modelling), communicating findings to application engineers, and reviewing Application Security architecture, policies, and standards. The role also involves identifying software vulnerabilities, researching secure cloud leverage, analyzing security threats, and providing security consulting within the Firm.

Requirements

  • Master’s degree (U.S. or foreign equivalent) in Computer Science, Computer Engineering, Cyber Security Engineering or a related field and three (3) years of experience in the job offered or a related role OR Bachelor’s degree (U.S. or foreign equivalent) in Computer Science, Computer Engineering, Cyber Security Engineering or a related field and five (5) years of experience in the job offered or a related role.
  • Prior experience must include three (3) years (with a Master’s degree) OR five (5) years (with a Bachelor’s degree) with: technical Project Management or Program Management function within the financial services or technology industry.
  • Prior experience must include three (3) years (with a Master’s degree) OR five (5) years (with a Bachelor’s degree) with: target Operating Model (TOM), control framework, process engineering, automation and location strategy.
  • Prior experience must include three (3) years (with a Master’s degree) OR five (5) years (with a Bachelor’s degree) with: software engineering fundamentals, identifying risks, assessing mitigating controls, and making recommendations on improving the control environment.
  • Prior experience must include three (3) years (with a Master’s degree) OR five (5) years (with a Bachelor’s degree) with: working within an engineering or cybersecurity environment.
  • Prior experience must include three (3) years (with a Master’s degree) OR five (5) years (with a Bachelor’s degree) with: risk, compliance, regulatory, or information technology/security.
  • Prior experience must include three (3) years (with a Master’s degree) OR five (5) years (with a Bachelor’s degree) with: risk management methodologies and frameworks.
  • Prior experience must include three (3) years (with a Master’s degree) OR five (5) years (with a Bachelor’s degree) with: data analysis and visualization experience including Microsoft Excel.

Responsibilities

  • Lead to transform and optimize the overall Technology Risk function to drive increased effectiveness and efficiency of the information security and cyber security program.
  • Partner with the Technology Risk and Engineering leadership to articulate clear, measurable goals and align the transformation activities with the divisional strategic objectives and regulatory drivers.
  • Perform Application Security Assessments (Code Review, Penetration Test, Design Review, Threat modelling) and communicate the results to the respective application engineers.
  • Review Application Securing architecture, policies, standards definitions, and carry out documentation of the above.
  • Identify vulnerabilities in software applications and software designing processes to reduce security risks.
  • Actively research new cloud services and identify ways in which the Firm can leverage the Cloud in a secure manner.
  • Work with stakeholders to understand the design architecture of software components to analyze security threats and risks.
  • Share issues and recommendations with component owners and advise on how they can implement secure remediation.
  • Enable a world-class cyber defense program by working closely with other technical, incident management, and forensic personnel to develop a fuller understanding of activity of cyber threat actors.
  • Provide security consulting within the Firm as needed.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service