Tech Risk, Risk Practices and Controls Management - Vice President, Dallas
About the role
Led by the Chief Information Security Officer (CISO), Technology Risk secures Goldman Sachs against hackers and other cyber threats. We are responsible for detecting and preventing attempted cyber intrusions against the firm, helping the firm develop more secure applications and infrastructure, developing software in support of our efforts, measuring cybersecurity risk, and designing and driving implementation of cybersecurity controls. The team has global presence across the Americas, APAC, India and EMEA.
The Digital Risk Office (DRO) is a specialized risk and governance function embedded within the Engineering Division. The Risk Practices and Control Management (RPCM) team sits within DRO and establishes the standards, governance, and lifecycle discipline required to manage controls effectively from design through execution. The team is responsible for executing an integrated, risk-aligned control environment that enforces regulatory responsiveness, assessment readiness, sustainable operational oversight and risk management.
As a Vice President in the Risk Practices and Control Management Team within the Digital Risk Office (DRO), you will play a pivotal role in shaping and maturing the technology control landscape across Goldman Sachs’ Engineering division. You will act as a trusted advisor and strategic partner to engineering leaders, bridging the gap between complex technical architectures and risk governance. By designing, implementing, and enhancing our control management framework, you will directly influence how the firm mitigates technology risks, ensures continuous audit and assessment readiness, and maintains compliance with evolving global regulations. This high-visibility role offers a unique opportunity to drive operational resilience, foster a strong risk-aware culture, and deliver sustainable, risk-aligned control solutions that protect the firm’s global systems and infrastructure.
Responsibilities
- Oversee risks and controls as part of the first line of defense, identifying weaknesses, recommending improvements, and educating control program owners on risk posture across engineering products—including initiatives leveraging traditional AI, generative AI, and agentic AI.
- Develop, implement, and enhance the control management framework, processes, standards, and guidelines to ensure robust, ongoing technology control management across all systems and infrastructures.
- Foster a culture of partnership, collaboration, and transparency with control, process, and risk-owning teams, serving as a subject matter expert.
- Assess and review technology policies, standards, and control changes to ensure comprehensive risk management and alignment with regulatory and industry standards.
- Review and evaluate technology control designs across engineering systems, applications, and infrastructure to ensure robust risk mitigation and compliance with industry standards (e.g., NIST SP 800-53, ISO 27001, COBIT).
- Execute and maintain an integrated, risk-aligned technology control environment, ensuring all engineering systems, applications, and infrastructure controls are mapped directly to the firm's risk taxonomy and business objectives.
- Enforce regulatory responsiveness by continuously monitoring global regulatory developments (e.g., DORA, NIST, ISO) and translating complex compliance mandates into concrete, actionable engineering control requirements.
- Drive continuous assessment readiness across the Engineering division, ensuring that all technology controls are documented, evidenced, and prepared for evaluation by internal and external auditors, as well as controls assessments such as RCSA and M&T.
- Establish and manage sustainable operational oversight mechanisms, including key risk indicators (KRIs), control metrics, and continuous monitoring, to proactively manage and mitigate technology risks.
- Translate complex control implementation and risk mitigation strategies into clear, non-technical business terms for senior leadership and key stakeholders.
Requirements
- Experience with developing policies and procedures according to internationally recognized methodologies for IT management in domains related to Software Engineering and IT Technology.
- Strong understanding of enterprise technology concepts, including cloud computing (AWS, Azure, GCP), microservices, APIs, containerization, CI/CD pipelines, databases, and modern software engineering practices.
- Deep knowledge of industry-standard technology risk and control frameworks (e.g., NIST SP 800-53, NIST CSF, ISO 27001, COBIT, CSA CCM, ITIL).
- 7+ years of relevant experience in technology risk management, cybersecurity, software engineering, cloud security, IT auditing, or a first/1.5-line risk and control function within financial services or a major technology company.
- Strong verbal and written communication skills with the ability to present complex technical risks clearly to senior stakeholders, combined with a strong delivery focus in a fast-paced environment.
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related quantitative discipline.
Preferred Qualifications
- Relevant professional certifications (e.g., CISA, CISM, CRISC, CISSP, CCSP) are highly desirable.