Technology Risk - Control Enablement and Transformation-Dallas-Vice President

Goldman Sachs

Dallas (TX)

On-site

USD 150,000 - 190,000

Full time

5 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Goldman Sachs is seeking a seasoned Security Controls Lead to strengthen the first line of defense by overseeing risk-based controls across engineering systems and cloud environments. You will design and implement a robust control framework, drive improvements to control execution, and automate evidence capture.

The role requires deep regulatory knowledge and clear communication with senior leadership. Ideal candidates have 10+ years in security controls or technology risk within financial

Qualifications

  • Hands-on security controls experience with design and operating effectiveness.
  • Experience developing IT policies and procedures per recognized IT management methodologies.
  • Strong understanding of cloud platforms (AWS, Azure, GCP) and IAM, microservices, APIs, containers, CI/CD.
  • Deep knowledge of industry-standard security frameworks (NIST SP 800-53, NIST CSF, ISO 27001, COBIT, CSA CCM, CIS Controls, ITIL).
  • 10+ years of experience in security controls or technology risk in financial services or major tech company.
  • Strong verbal and written communication skills with ability to present risks to senior stakeholders.
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or related field.

Responsibilities

  • Oversee security risks and controls as part of the first line of defense.
  • Develop, implement, and enhance the control management framework across systems and infrastructure.
  • Improve design and execution of existing security controls and reduce noise while automating evidence capture.
  • Foster collaboration with control, process and risk teams and act as SME on control design and operation.
  • Assess and review policies, standards, and control changes to ensure regulatory alignment.
  • Review security control designs across engineering systems to ensure robust risk mitigation.
  • Maintain integrated security control environment mapped to risk taxonomy and business objectives.
  • Establish and manage KRIs, control health metrics, and continuous monitoring.
  • Translate complex control strategies into clear business terms for leadership.

Skills

Security controls
Policies & procedures
Cloud security
Framework knowledge
10+ years experience
Communication skills
Bachelor's degree

Education

Bachelor's degree in CS/Cybersecurity/IT

Job description

Who We Are

Led by the Chief Information Security Officer (CISO), Technology Risk secures Goldman Sachs against hackers and other cyber threats. We are responsible for detecting and preventing attempted cyber intrusions against the firm, helping the firm develop more secure applications and infrastructure, developing software in support of our efforts, measuring cybersecurity risk, and designing and driving implementation of cybersecurity controls. The team has global presence across the Americas, APAC, India and EMEA.

Job Description

Led by the Chief Information Security Officer (CISO), Technology Risk secures Goldman Sachs against hackers and other cyber threats. We are responsible for detecting and preventing attempted cyber intrusions against the firm, helping the firm develop more secure applications and infrastructure, developing software in support of our efforts, measuring cybersecurity risk, and designing and driving implementation of cybersecurity controls. The team has global presence across the Americas, APAC, India and EMEA. Goldman Sachs has one of the most progressive Technology Risk teams in the industry and is continuing to push the development of risk in preference to security within technology and the business. Year on year success has led the team to work deeper into the organization and gain valuable insights into how technology needs to function, what its risk really is and how this impacts the business.

Responsibilities Include
  • Oversee security risks and controls as part of the first line of defense, identifying weaknesses, recommending improvements, and educating control program owners on risk posture across engineering products, including initiatives leveraging traditional AI, generative AI and agentic AI.
  • Develop, implement, and enhance the control management framework, processes, standards, and guidelines - including defining what good control design and execution look like, to ensure robust, ongoing security control management across all systems and infrastructures.
  • Improve the design and execution of existing security controls to reduce noise where possible and make them run smoothly, rationalizing duplicative or low-value controls, tuning thresholds and false positives, removing unnecessary manual steps, and automating control execution and evidence capture etc.
  • Foster a culture of partnership, collaboration and transparency with control, process and risk owning teams, serving as the subject matter expert on security control design and operation.
  • Assess and review technology and security policies, standards, and control changes to ensure comprehensive risk management and regulatory and industry standard alignment.
  • Review and evaluate security control designs across engineering systems, applications, and infrastructure, including how controls are actually configured and operated, to ensure robust risk mitigation and compliance with industry standards (e.g., NIST SP 800-53, NIST CSF, ISO 27001, COBIT, CSA CCM, CIS Controls).
  • Execute and maintain an integrated, risk-aligned security control environment, ensuring all engineering systems, applications, and infrastructure controls are mapped directly to the firm's risk taxonomy and business objectives.
  • Establish and manage sustainable operational oversight mechanisms, including key risk indicators (KRIs), control health metrics, and continuous monitoring, to proactively manage and mitigate technology and security risks.
  • Translate complex control implementation and risk mitigation strategies into clear, non-technical business terms for senior leadership and key stakeholders.
Basic Qualifications
  • Hands-on security controls experience, assessing control design and operating effectiveness, and redesigning controls to improve how they perform in practice (not solely attestation or testing-based assurance).
  • Experience with developing policies and procedures according to internationally recognized methodologies for IT management in the domains related to Software Engineering and IT Technology.
  • Strong understanding of enterprise technology concepts, including cloud computing (AWS, Azure, GCP), identity and access management, microservices, APIs, containerization, CI/CD pipelines, databases, logging and monitoring tooling, and modern software engineering practices.
  • Framework Knowledge: Deep knowledge of industry-standard security, technology risk and control frameworks (e.g., NIST SP 800-53, NIST CSF, ISO 27001, COBIT, CSA CCM, CIS Controls, ITIL).
  • 10+ years of relevant experience in security controls, technology risk management, cybersecurity, software engineering, cloud security, IT auditing, or a first/1.5-line risk and control function within financial services or a major technology company.
  • Strong verbal and written communication skills with the ability to present complex technical risks clearly to senior stakeholders, combined with a strong delivery focus in a fast-paced environment.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related quantitative discipline.
Preferred Qualifications
  • Relevant professional certifications (e.g., CISA, CISM, CRISC, CISSP, CCSP) are highly desirable.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Technology Risk - Control Enablement and Transformation-Dallas-Vice President
Technology Risk - Control Enablement and Transformation-Dallas-Vice President

The Goldman Sachs Group • Dallas (TX)

On-site
USD 150,000 - 210,000
Technology Risk - Control Enablement and Transformation-Dallas-Vice President
Technology Risk - Control Enablement and Transformation-Dallas-Vice President

Goldman Sachs (lateral) • Dallas (TX)

On-site
USD 180,000 - 240,000
Technology Risk - Control Enablement and Transformation-Dallas-Vice President
Technology Risk - Control Enablement and Transformation-Dallas-Vice President

Goldman Sachs Group, Inc. • Dallas (TX)

On-site
USD 200,000 - 300,000
Tech Risk - Security Architecture- VP- Dallas
Tech Risk - Security Architecture- VP- Dallas

The Goldman Sachs Group • Dallas (TX)

On-site
USD 100,000 - 130,000
Technology Risk - Vice President, Agentic Systems Engineer / Technical Lead, New York
Technology Risk - Vice President, Agentic Systems Engineer / Technical Lead, New York

Goldman Sachs • New York (NY)

On-site
USD 140,000 - 200,000
Security Engineering - New York - Vice President
Security Engineering - New York - Vice President

The Goldman Sachs Group • New York (NY)

On-site
USD 130,000 - 180,000
Tech Risk, Risk Practices and Controls Management - Vice President, Dallas
Tech Risk, Risk Practices and Controls Management - Vice President, Dallas

Goldman Sachs Group, Inc. • Dallas (TX), Northern (KY)

Hybrid
USD 180,000 - 250,000
Tech Risk, Risk Practices and Controls Management - Vice President, Dallas
Tech Risk, Risk Practices and Controls Management - Vice President, Dallas

Goldman Sachs Bank AG • Dallas (TX)

On-site
USD 180,000 - 280,000
Healthcare & Medical Insurance
Retirement & Financial Wellness
Generous vacation policies
Technology Risk - Dallas - Security Engineering
Technology Risk - Dallas - Security Engineering

Goldman Sachs • Dallas (TX)

On-site
USD 110,000 - 170,000
Technology Risk - Dallas - Security Engineering
Technology Risk - Dallas - Security Engineering

Goldman Sachs • Dallas (WV)

On-site
USD 120,000 - 180,000