About this role
What We Do
At Goldman Sachs, Engineers do not just build technology - we make progress possible. We connect people and capital with ideas, solve complex engineering challenges for clients, and build scalable software, low-latency infrastructure, cyber defense capabilities, and data-driven platforms that operate at the speed of global markets.
Engineering - comprising the Technology Division and global strategists groups - is central to the firm’s business. Our environment requires strategic thinking, rapid execution, and practical solutions that push the limits of digital possibility.
Who We Are
Led by the Chief Information Security Officer (CISO), Technology Risk (TR) protects Goldman Sachs by strengthening cyber detection and prevention, securing applications and infrastructure, building software for security operations, measuring cyber risk, and designing effective controls. TR operates globally across the Americas, APAC, India, and EMEA.
Within TR, the Secure SDLC team enables developers across the firm to build secure technology solutions that meet high application security and development standards. The team embeds security into the engineering ecosystem through governance of SAST, DAST, infrastructure as code (IaC) security, software supply chain security, and automated control gating.
As application delivery evolves, the Secure SDLC team leads the adoption of AI-augmented analysis and agentic AI workflows that embed secure-by-design principles directly into developer environments.
Your Impact
As a Vice President (VP) - Secure SDLC Lead, you will define and govern the firm’s global Secure SDLC strategy, reduce enterprise technology risk, strengthen application resilience, and enable secure software delivery at scale. You will connect application security engineering, developer platforms, and senior stakeholders to embed effective controls into high-risk financial systems without slowing engineering velocity.
You will advance next-generation application security practices-including AI-augmented analysis, shift-left controls, and agentic AI workflows - while improving governance, control adoption, remediation efficiency, and developer experience across global business units.
Key Responsibilities
• Lead and evolve the firm's Secure Software Development Lifecycle (Secure SDLC) strategy across global engineering teams. • Drive adoption of application security controls throughout the software development lifecycle, including static and dynamic security testing. • Partner with engineering teams to embed security-by-design principles into SDLC and CI/CD processes. • Lead application security reviews, threat modelling activities, and security testing programmes. • Oversee and enhance security testing capabilities, including SAST, DAST and emerging AI-enabled security testing solutions. • Assess application security risks and help engineering teams prioritise remediation efforts. • Collaborate with engineering, product and technology stakeholders to improve security controls and developer security practices. • Evaluate emerging technologies and AI-driven security capabilities to strengthen Secure SDLC services. • Mentor and support security engineers while promoting a strong application security culture across the firm. Basic Qualifications
• 7+ years of experience in Application Security, Secure SDLC, DevSecOps or Product Security. • Strong understanding of Secure SDLC principles and software development practices. • Hands-on experience with Application Security and security testing methodologies. • Experience with SAST, DAST and application security tooling. • Experience integrating security controls into CI/CD pipelines and modern engineering workflows. • Strong understanding of threat modelling, vulnerability management and application risk assessment. • Excellent communication and stakeholder management skills. Preferred Qualifications
• Experience leading or driving Secure SDLC initiatives in large-scale engineering environments. • Knowledge of industry frameworks and standards such as OWASP Top 10, CWE and NIST. • Familiarity with AI-enabled security tooling and AI security concepts. • Experience with cloud-native application security and modern software architectures. • Background in Financial Services, FinTech or another highly regulated industry. • Relevant security certifications such as CISSP, CSSLP, GIAC or cloud security certifications. How You Will Fulfill Your Potential Strategic Leadership & Governance: Define and govern the enterprise roadmap for SAST, DAST, software supply chain security, IaC scanning, and security awareness, aligning priorities with risk reduction, regulatory expectations, and engineering adoption.
AI & Security Innovation: Lead the adoption of AI-augmented Secure SDLC capabilities, using intelligent control gating and agentic workflows to improve detection quality, prioritisation, and operational scale.
Enterprise Control Integration: Embed application security controls into global CI/CD pipelines and developer workflows, increasing control coverage while minimising delivery friction.
Senior Stakeholder Management: Partner with business, engineering, and product leaders to set secure coding standards, prioritise remediation, establish SLAs, and remove security bottlenecks affecting enterprise delivery.
Solution Engineering & Platform Oversight: Oversee proprietary and open-source Secure SDLC platforms from requirements and architecture through UAT, deployment, QA, and continuous improvement.
Advanced Threat & Risk Management: Lead threat modelling, attack surface analysis, design reviews, and risk assessments, translating findings into prioritised remediation and control improvements.
Regulatory & Compliance Alignment: Align Secure SDLC controls with internal policy, financial regulatory expectations, and industry frameworks including NIST SSDF, OWASP Top 10, OWASP LLM Top 10, and CWE.
Team Mentorship & Secure-by-Design Culture: Mentor security engineers and influence developer communities to improve secure coding adoption, reduce repeat findings, and strengthen secure-by-design culture.
ABOUT GOLDMAN SACHS At Goldman Sachs, we commit our people, capital and ideas to help our clients, shareholders and the communities we serve to grow. Founded in 1869, we are a leading global investment banking, securities and investment management firm. Headquartered in New York, we maintain offices around the world. We believe who you are makes you better at what you do. We're committed to fostering and advancing diversity and inclusion in our own workplace and beyond by ensuring every individual within our firm has a number of opportunities to grow professionally and personally, from our training and development opportunities and firmwide networks to benefits, wellness and personal finance offerings and mindfulness programs. Learn more about our culture, benefits, and people at GS.com/careers. We’re committed to finding reasonable accommodations for candidates with special needs or disabilities during our recruiting process. Learn more: https://www.goldmansachs.com/careers/footer/disability-statement.html © The Goldman Sachs Group, Inc., 2023. All rights reserved. Goldman Sachs is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sex, national origin, age, veterans status, disability, or any other characteristic protected by applicable law.