Enter a job title or keyword

Tech Risk, Risk Practices and Controls Management Vice President, Dallas

Goldman Sachs


Job Location:

Dallas, TX - USA

Monthly Salary: Not provided by the employer
Posted: 2 August 2026 (30+ days ago)
Application Deadline: 18 November 2026
Vacancies: 1 Vacancy

Job Summary

Description

WHO WE ARE

Led by the Chief Information Security Officer (CISO) Technology Risk secures Goldman Sachs against hackers and other cyber threats. We are responsible for detecting and preventing attempted cyber intrusions against the firm helping the firm develop more secure applications and infrastructure developing software in support of our efforts measuring cybersecurity risk and designing and driving implementation of cybersecurity controls. The team has global presence across the Americas APAC India and EMEA.

TheDigital Risk Office (DRO)is a specializedrisk and governance function embedded within the Engineering Division. The Risk Practices and Control Management (RPCM) team sits within DRO and establishes the standards governance and lifecycle discipline required to manage controls effectively from design through execution. The team is responsible for executing an integrated risk-aligned control environment that enforces regulatory responsiveness assessment readiness sustainable operational oversight and risk management.

YOUR IMPACT

As a Vice President in theRisk Practices and Control Management Team within the Digital Risk Office (DRO) you will play a pivotal role in shaping and maturing the technology control landscape across Goldman Sachs Engineering division. You will act as a trusted advisor and strategic partner to engineering leaders bridging the gap between complex technical architectures and risk governance.

By designing implementing and enhancing our control management framework you will directly influence how the firm mitigates technology risks ensures continuous audit and assessment readiness and maintains compliance with evolving global regulations. This high-visibility role offers a unique opportunity to drive operational resilience foster a strong risk-aware culture and deliver sustainable risk-aligned control solutions that protect the firms global systems and infrastructure.

HOW YOU WILL FULFILL YOUR POTENTIAL

Your responsibilities will focus on developing and maturing risk practices and control management across the engineering this role you and your team will collaborate closely with all control programs within engineering to understand control objectives control designs identified risks and the operational processes in which these controls reside. You will act as a trusted advisor to engineering teams guiding them on industry best practices for control identification design and measurement. Additionally you will partner on strategic firm-wide programs aimed at mitigating technology risks and enhancing operational resilience. By monitoring and analyzing new or evolving regulations impacting the technology control environment you will translate complex compliance mandates into actionable requirements for control risk and process owners. This position offers a unique vantage point to build a broad deep understanding of the business and technologies across the entire organization while collaborating with engineers and leaders at all levels.

To be successful in this role you must possess exceptional communication skills and the ability to articulate complex risk and control concepts clearly to both technical and non-technical stakeholders at all levels of the firm. You should have a proven track record of managing multiple complex programs simultaneously in a high-pressure dynamic environment where change is commonplace. Strong stakeholder management and collaborative leadership skills are essential as you will be responsible for influencing and driving consensus across diverse engineering and business teams.

Responsibilities include:

  • Oversee Risks and controls as part of first line of defense identifying weakness recommending improvements and educating the control program owners on risk posture across engineering products- including initiatives leveraging traditional AI generative AI and agentic AI.
  • Develop implement and enhance the control management framework processes standards and guidelines to ensure robust ongoing technology control management across all systems and infrastructures.
  • Foster a culture of partnership collaboration and transparency with control process and risk owning teams serving as a subject matter expert.
  • Assess and review technology policies standards and control changes to ensure comprehensive risk management and regulatory and industry standard alignment.
  • Review and evaluate technology control designs across engineering systems applications and infrastructure to ensure robust risk mitigation and compliance with industry standards (e.g. NIST SP 800-53 ISO 27001 COBIT).
  • Execute and maintain an integrated risk-aligned technology control environment ensuring all engineering systems applications and infrastructure controls are mapped directly to the firms risk taxonomy and business objectives.
  • Enforce regulatory responsiveness by continuously monitoring global regulatory developments (e.g. DORA NIST ISO) and translating complex compliance mandates into concrete actionable engineering controlrequirements.
  • Drive continuous assessment readiness across the Engineering division ensuring that all technology controls are documented evidenced and prepared for (1) evaluation by internal and external auditors (2) controls assessments such as RCSA and M&T.
  • Establish and manage sustainable operational oversight mechanisms including key risk indicators (KRIs) control metrics and continuous monitoring to proactively manage and mitigate technology risks.
  • Translatecomplex control implementation and risk mitigation strategies into clear non-technical business terms for senior leadership and key stakeholders.

BASIC QUALIFICATIONS

  • Experience with developing policies and procedures according to internationally recognized methodologies for IT management in the domains related to Software Engineering and IT Technology.
  • Strong understanding of enterprise technology concepts including cloud computing (AWS Azure GCP) microservices APIs containerization CI/CD pipelines databases and modern software engineering practices.
  • Framework Knowledge:Deep knowledge of industry-standard technology risk and control frameworks (e.g. NIST SP 800-53 NIST CSF ISO 27001 COBIT CSA CCM ITIL).
  • 7 years of relevant experience in technology risk management cybersecurity software engineering cloud security IT auditing or a first/1.5-line risk and control function within financial services or a major technology company.
  • Strong verbal and written communication skills with the ability to present complex technical risks clearly to senior stakeholders combined with a strong delivery focus in a fast-paced environment.
  • Bachelors degree in Computer Science Cybersecurity Information Technology or a related quantitative discipline.

PREFERRED QUALIFICATIONS

  • Relevant professional certifications (e.g. CISA CISM CRISC CISSP CCSP) are highly desirable.

#TechRiskCybersecurity




Required Experience:

Exec


About Company

The Goldman Sachs Group, Inc. is a leading global investment banking, securities, and asset and wealth management firm that provides a wide range of financial services.

View Profile View Profile