Enter a job title or keyword

Technology Risk Control Enablement and Transformation-Dallas-Vice President

Goldman Sachs


Job Location:

Dallas, IA - USA

Monthly Salary: Not provided by the employer
Posted: 29 September 2026 (13 hours ago)
Application Deadline: 27 December 2026
Vacancies: 1 Vacancy

Job Summary

Description

Who We Are:

Led by the Chief Information Security Officer (CISO) Technology Risk secures Goldman Sachs against hackers and other cyber threats. We are responsible for detecting and preventing attempted cyber intrusions against the firm helping the firm develop more secure applications and infrastructure developing software in support of our efforts measuring cybersecurity risk and designing and driving implementation of cybersecurity controls. The team has global presence across the Americas APAC India and EMEA.

Goldman Sachs has one of the most progressive Technology Risk teams in the industry and is continuing to push the development of risk in preference to security within technology and the business. Year on year success has led the team to work deeper into the organization and gain valuable insights into how technology needs to function what its risk really is and how this impacts the business.

Responsibilities include:

  • Oversee security risks and controls as part of the first line of defense identifying weaknesses recommending improvements and educating control program owners on risk posture across engineering products including initiatives leveraging traditional AI generative AI and agentic AI.
  • Develop implement and enhance the control management framework processes standards and guidelines - including defining what good control design and execution look like to ensure robust ongoing security control management across all systems and infrastructures.
  • Improve the design and execution of existing security controls to reduce noise where possible and make them run smoothly rationalizing duplicative or low-value controls tuning thresholds and false positives removing unnecessary manual steps and automating control execution and evidence capture etc.
  • Foster a culture of partnership collaboration and transparency with control process and risk owning teams serving as the subject matter expert on security control design and operation.
  • Assess and review technology and security policies standards and control changes to ensure comprehensive risk management and regulatory and industry standard alignment.
  • Review and evaluate security control designs across engineering systems applications and infrastructure including how controls are actually configured and operated to ensure robust risk mitigation and compliance with industry standards (e.g. NIST SP 800-53 NIST CSF ISO 27001 COBIT CSA CCM CIS Controls).
  • Execute and maintain an integrated risk-aligned security control environment ensuring all engineering systems applications and infrastructure controls are mapped directly to the firms risk taxonomy and business objectives.
  • Establish and manage sustainable operational oversight mechanisms including key risk indicators (KRIs) control health metrics and continuous monitoring to proactively manage and mitigate technology and security risks.
  • Translate complex control implementation and risk mitigation strategies into clear non-technical business terms for senior leadership and key stakeholders.

Basic Qualifications:

  • Hands-on security controls experience assessing control design and operating effectiveness and redesigning controls to improve how they perform in practice (not solely attestation or testing-based assurance).
  • Experience with developing policies and procedures according to internationally recognized methodologies for IT management in the domains related to Software Engineering and IT Technology.
  • Strong understanding of enterprise technology concepts including cloud computing (AWS Azure GCP) identity and access management microservices APIs containerization CI/CD pipelines databases logging and monitoring tooling and modern software engineering practices.
  • Framework Knowledge: Deep knowledge of industry-standard security technology risk and control frameworks (e.g. NIST SP 800-53 NIST CSF ISO 27001 COBIT CSA CCM CIS Controls ITIL).
  • 10 years of relevant experience in security controls technology risk management cybersecurity software engineering cloud security IT auditing or a first/1.5-line risk and control function within financial services or a major technology company.
  • Strong verbal and written communication skills with the ability to present complex technical risks clearly to senior stakeholders combined with a strong delivery focus in a fast-paced environment.
  • Bachelors degree in Computer Science Cybersecurity Information Technology or a related quantitative discipline.

Preferred Qualifications:

  • Relevant professional certifications (e.g. CISA CISM CRISC CISSP CCSP) are highly desirable.



Required Experience:

Exec


About Company

The Goldman Sachs Group, Inc. is a leading global investment banking, securities, and asset and wealth management firm that provides a wide range of financial services.

View Profile View Profile