Engineering-L2-Warsaw-Vice President-Secure SDLC Lead

Goldman Sachs

Warszawa

On-site

PLN 667,000 - 1,038,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Goldman Sachs is seeking a Vice President, Secure SDLC Lead to define and govern the firm’s global Secure SDLC strategy. You will reduce enterprise technology risk and enable secure software delivery at scale while collaborating with senior stakeholders across engineering platforms and product teams.

You will advance AI-augmented analysis, shift-left controls, and agentic AI workflows, strengthening governance, remediation efficiency, and developer experience across global business units.

Qualifications

  • 7+ years of experience in Application Security, Secure SDLC, DevSecOps or Product Security.
  • Strong understanding of Secure SDLC principles and software development practices.
  • Hands-on experience with Application Security and security testing methodologies.
  • Experience with SAST, DAST and application security tooling.
  • Experience integrating security controls into CI/CD pipelines and modern engineering workflows.
  • Strong understanding of threat modelling, vulnerability management and application risk assessment.
  • Excellent communication and stakeholder management skills.

Responsibilities

  • Lead and evolve the firm's Secure SDLC strategy across global engineering teams.
  • Drive adoption of application security controls throughout the software development lifecycle, including static and dynamic security testing.
  • Partner with engineering teams to embed security-by-design principles into SDLC and CI/CD processes.
  • Lead application security reviews, threat modelling activities and security testing programmes.
  • Oversee and enhance security testing capabilities, including SAST, DAST and emerging AI-enabled security testing solutions.
  • Assess application security risks and help engineering teams prioritise remediation efforts.
  • Collaborate with engineering, product and technology stakeholders to improve security controls and developer security practices.
  • Evaluate emerging technologies and AI-driven security capabilities to strengthen Secure SDLC services.
  • Mentor and support security engineers while promoting a strong application security culture across the firm.

Skills

Secure SDLC
Application Security
DevSecOps
Threat modelling
CI/CD integration
SAST
DAST
Cloud security
Security tooling
Stakeholder management

Tools

SAST
DAST
IaC security tooling
CI/CD pipelines

Job description

What We Do

At Goldman Sachs, Engineers do not just build technology - we make progress possible. We connect people and capital with ideas, solve complex engineering challenges for clients, and build scalable software, low-latency infrastructure, cyber defense capabilities, and data-driven platforms that operate at the speed of global markets.

Engineering - comprising the Technology Division and global strategists groups - is central to the firm’s business. Our environment requires strategic thinking, rapid execution, and practical solutions that push the limits of digital possibility.

Who We Are

Led by the Chief Information Security Officer (CISO), Technology Risk (TR) protects Goldman Sachs by strengthening cyber detection and prevention, securing applications and infrastructure, building software for security operations, measuring cyber risk, and designing effective controls. TR operates globally across the Americas, APAC, India, and EMEA.

Within TR, the Secure SDLC team enables developers across the firm to build secure technology solutions that meet high application security and development standards. The team embeds security into the engineering ecosystem through governance of SAST, DAST, infrastructure as code (IaC) security, software supply chain security, and automated control gating.

As application delivery evolves, the Secure SDLC team leads the adoption of AI-augmented analysis and agentic AI workflows that embed secure-by-design principles directly into developer environments.

Your Impact

As a Vice President (VP) - Secure SDLC Lead, you will define and govern the firm’s global Secure SDLC strategy, reduce enterprise technology risk, strengthen application resilience, and enable secure software delivery at scale. You will connect application security engineering, developer platforms, and senior stakeholders to embed effective controls into high-risk financial systems without slowing engineering velocity.

You will advance next-generation application security practices-including AI-augmented analysis, shift-left controls, and agentic AI workflows - while improving governance, control adoption, remediation efficiency, and developer experience across global business units.

Key Responsibilities

  • Lead and evolve the firm's Secure Software Development Lifecycle (Secure SDLC) strategy across global engineering teams.
  • Drive adoption of application security controls throughout the software development lifecycle, including static and dynamic security testing.
  • Partner with engineering teams to embed security-by-design principles into SDLC and CI/CD processes.
  • Lead application security reviews, threat modelling activities, and security testing programmes.
  • Oversee and enhance security testing capabilities, including SAST, DAST and emerging AI-enabled security testing solutions.
  • Assess application security risks and help engineering teams prioritise remediation efforts.
  • Collaborate with engineering, product and technology stakeholders to improve security controls and developer security practices.
  • Evaluate emerging technologies and AI-driven security capabilities to strengthen Secure SDLC services.
  • Mentor and support security engineers while promoting a strong application security culture across the firm.
Basic Qualifications
  • 7+ years of experience in Application Security, Secure SDLC, DevSecOps or Product Security.
  • Strong understanding of Secure SDLC principles and software development practices.
  • Hands-on experience with Application Security and security testing methodologies.
  • Experience with SAST, DAST and application security tooling.
  • Experience integrating security controls into CI/CD pipelines and modern engineering workflows.
  • Strong understanding of threat modelling, vulnerability management and application risk assessment.
  • Excellent communication and stakeholder management skills.
Preferred Qualifications
  • Experience leading or driving Secure SDLC initiatives in large-scale engineering environments.
  • Knowledge of industry frameworks and standards such as OWASP Top 10, CWE and NIST.
  • Familiarity with AI-enabled security tooling and AI security concepts.
  • Experience with cloud-native application security and modern software architectures.
  • Background in Financial Services, FinTech or another highly regulated industry.
  • Relevant security certifications such as CISSP, CSSLP, GIAC or cloud security certifications.

How You Will Fulfill Your Potential

Strategic Leadership & Governance: Define and govern the enterprise roadmap for SAST, DAST, software supply chain security, IaC scanning, and security awareness, aligning priorities with risk reduction, regulatory expectations, and engineering adoption.

AI & Security Innovation: Lead the adoption of AI-augmented Secure SDLC capabilities, using intelligent control gating and agentic workflows to improve detection quality, prioritisation, and operational scale.

Enterprise Control Integration: Embed application security controls into global CI/CD pipelines and developer workflows, increasing control coverage while minimising delivery friction.

Senior Stakeholder Management: Partner with business, engineering, and product leaders to set secure coding standards, prioritise remediation, establish SLAs, and remove security bottlenecks affecting enterprise delivery.

Solution Engineering & Platform Oversight: Oversee proprietary and open-source Secure SDLC platforms from requirements and architecture through UAT, deployment, QA, and continuous improvement.

Advanced Threat & Risk Management: Lead threat modelling, attack surface analysis, design reviews, and risk assessments, translating findings into prioritised remediation and control improvements.

Regulatory & Compliance Alignment: Align Secure SDLC controls with internal policy, financial regulatory expectations, and industry frameworks including NIST SSDF, OWASP Top 10, OWASP LLM Top 10, and CWE.

Team Mentorship & Secure-by-Design Culture: Mentor security engineers and influence developer communities to improve secure coding adoption, reduce repeat findings, and strengthen secure-by-design culture.

ABOUT GOLDMAN SACHS
At Goldman Sachs, we commit our people, capital and ideas to help our clients, shareholders and the communities we serve to grow. Founded in 1869, we are a leading global investment banking, securities and investment management firm. Headquartered in New York, we maintain offices around the world.

We believe who you are makes you better at what you do. We're committed to fostering and advancing diversity and inclusion in our own workplace and beyond by ensuring every individual within our firm has a number of opportunities to grow professionally and personally, from our training and development opportunities and firmwide networks to benefits, wellness and personal finance offerings and mindfulness programs. Learn more about our culture, benefits, and people at GS.com/careers.

We’re committed to finding reasonable accommodations for candidates with special needs or disabilities during our recruiting process. Learn more: https://www.goldmansachs.com/careers/footer/disability-statement.html

© The Goldman Sachs Group, Inc., 2023. All rights reserved.

Goldman Sachs is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sex, national origin, age, veterans status, disability, or any other characteristic protected by applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Engineering-L2-Warsaw-Vice President-Secure SDLC Lead Warsaw · Poland · Vice President
Engineering-L2-Warsaw-Vice President-Secure SDLC Lead Warsaw · Poland · Vice President

Goldman Sachs Bank AG • Warszawa

Hybrid
PLN 600,000 - 900,000
Healthcare & Medical Insurance
Financial Wellness & Retirement
On-site Health Centers
Data Engineering - Global Banking and Markets -Warsaw-Vice President
Data Engineering - Global Banking and Markets -Warsaw-Vice President

Goldman Sachs • Warszawa

On-site
Diversity and inclusion initiatives
Training and development opportunities
Wellness and personal finance programs
Software Engineer - GBM Regulatory Engineering-Warsaw-Vice President
Software Engineer - GBM Regulatory Engineering-Warsaw-Vice President

Goldman Sachs Group, Inc. • Warszawa

On-site
PLN 200,000 - 320,000
Data Engineering - Global Banking and Markets -Warsaw-Vice President
Data Engineering - Global Banking and Markets -Warsaw-Vice President

Goldman Sachs Group, Inc. • Warszawa

Hybrid
PLN 350,000 - 850,000
Security Engineering
Security Engineering

Goldman Sachs Bank AG • Warszawa

On-site
PLN 255,000 - 365,000
Healthcare & Medical Insurance
Fitness reimbursement
Child Care services
+1
The Core Engineering-Software Engineering - Analyst/Associate - Metrics & Analytics Platforms - Counterparty Credit Risk Eng
The Core Engineering-Software Engineering - Analyst/Associate - Metrics & Analytics Platforms - Counterparty Credit Risk Eng

Goldman Sachs • Warszawa

On-site
PLN 180,000 - 280,000
Engineering - Regional Chief of Staff - Associate – Warsaw
Engineering - Regional Chief of Staff - Associate – Warsaw

Goldman Sachs • Warszawa

On-site
PLN 180,000 - 280,000
Health insurance
Software Engineer - GBM Regulatory Engineering-Warsaw-Vice President
Software Engineer - GBM Regulatory Engineering-Warsaw-Vice President

Goldman Sachs • Warszawa

On-site
PLN 420,000 - 650,000
Software Engineer - GBM Regulatory Engineering-Warsaw-Vice President
Software Engineer - GBM Regulatory Engineering-Warsaw-Vice President

Goldman Sachs Bank AG • Warszawa

On-site
PLN 450,000 - 750,000
Internal Audit, Global Banking and Markets Operations Engineering, Associate, Warsaw
Internal Audit, Global Banking and Markets Operations Engineering, Associate, Warsaw

Goldman Sachs Group, Inc. • Warszawa

Hybrid
PLN 180,000 - 240,000