Vice President, Security Engineering

Goldman Sachs

Quick summary

Work type
On-site
Location
New York, NY
Salary
$150,000–$250,000 / yr
Posted
1 day ago

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $185k
This role $200k
$129k most similar roles pay here $263k

This role pays more than 71% of similar roles. Most pay $157,200–$212,175 — the shaded band above. At the midpoint, this role pays about $200k versus about $185k for comparable roles.

Based on 240 similar postings.

Employer

About Goldman Sachs

Goldman Sachs is a leading global investment banking, securities, and investment management firm providing financial services to corporations, financial institutions, governments, and individuals.

Goldman Sachs currently has 187 open roles on FindRole.

Listed pay typically runs $130,000–$250,000 across 60 roles with salary data.

Most-posted roles

View all roles at Goldman Sachs

At a glance

TL;DR · Vice President, Security Engineering

As the Vendor Risk Program Vice President in Technology Risk Advisory at Goldman Sachs, you will lead a team responsible for assessing and managing Information Security risks across the firm’s vendor ecosystem. Your day-to-day responsibilities include shaping the Vendor Technology Risk strategy, conducting deep-dive technical cybersecurity assessments, and designing security controls to mitigate risks. You will work closely with business units to manage risk portfolios and ensure compliance with regulatory requirements. The role requires expertise in cloud computing, AI/ML, zero trust architecture, and threat modeling frameworks like OWASP Top 10 and SANS Top 25. Ideal candidates should have at least five years of relevant experience, proficiency in cybersecurity risk assessments, and knowledge of the procurement process. Preferred qualifications include certifications such as CISSP or CCSP and a background in conducting IT/cyber security assessments.

What you'll do

  • Lead a team assessing threats and risks to manage vendor Information Security Risk portfolios.
  • Conduct core deep-dive technical cybersecurity assessments of vendors’ logical security controls.
  • Design cloud, mobile, and application security assessments for vendor technology risk management.
  • Develop and document security measures and guardrails to protect firm data and systems.
  • Negotiate and review contractual requirements related to information and cyber security.

What we're looking for

  • At least 5 years of experience in technical cybersecurity risk assessments and security strategy design.
  • Develop and document security measures, controls, and guardrails to protect data, applications, APIs, network infrastructure, and systems.
  • Design comprehensive cybersecurity architecture through threat modeling (OWASP Top 10, SANS Top 25) and data flow analysis.
  • Negotiate and review Information and Cyber Security contractual requirements for vendors.
  • Working knowledge of the regulatory landscape and its applicability to vendor ecosystems.
  • Understanding of new technologies like Cloud computing, AI/ML, zero trust, and their security risks.

More like this

Similar roles

Vice President, Security Architecture

Prudential Financial

Newark, NJ 72 days ago $221,900$333,000
AWS Azure Zero Trust Identity and Access Management (IAM) Defense-in-Depth Resilience-Focused Design Cloud-Native Security Architecture Infrastructure-as-Code Policy-Based Controls Data Governance Advanced Analytics AI/ML Platforms Distributed Systems Enterprise Data Security Encryption Terraform CI/CD Kubernetes Prometheus Grafana

Vice President, Engineering - Authentication

Okta Inc

Bellevue, WA +1 49 days ago $310,000$426,800
AWS Azure Agile DevOps CI/CD Python JavaScript SQL PostgreSQL Kubernetes Docker Terraform Prometheus Grafana OAuth OpenID Connect Zero Trust Role-Based Access Control Security Monitoring
Hybrid

Technology Operational Risk Management Lead, Cybersecurity

JPMorgan Chase

Jersey City, NJ +3 2 days ago $147,250$215,000
Cybersecurity Operational_Risk_Management KPIs_KRIs Control_Assessment Infrastructure_Architecture Application_Architecture Testing_and_Monitoring Data_Driven_Approaches Automated_Testing Complex_System_Analysis Business_Process_Support Risk_Framework_Procedures Senior_Level_Influence Multi_Tasking Verbal_Communication Written_Communication Persuasive_Presentation