
Goldman Sachs MENA
Lead Security Engineering Vice President
- Permanent
- Doha, Qatar
- Experience 5 - 10 yrs
Job expiry date: 21/04/2026
Job overview
Date posted
07/03/2026
Location
Doha, Qatar
Salary
Undisclosed
Compensation
Job description
The Lead Security Engineering Vice President (Asset & Wealth Management Information Security) within the Asset & Wealth Management division is responsible for defining, implementing, and overseeing the information security and cybersecurity risk posture for the Asset Management Private business. The role leads security engineering and information security governance across the division, ensuring alignment between commercial objectives and robust cybersecurity risk management practices to protect client assets and sensitive data while maintaining resilience against an evolving threat landscape. The position provides strategic leadership across Governance, Risk & Compliance (GRC), Application Security & Advisory, and Product Security functions while also overseeing embedded Technology Risk Officers assigned to Asset Management Private business verticals. The role focuses on establishing a unified and proactive cybersecurity risk management framework that ensures regulatory compliance with global financial regulations including SEC, FINRA, GDPR, and CCPA while enabling secure technological innovation across Asset Management initiatives. Responsibilities include working closely with internal application development teams building next-generation critical business applications to ensure information security and business resiliency control requirements are integrated within application architectures. The role collaborates with global Application Security Risk, Business Continuity, Risk Measurement, and Technology Risk teams to develop and implement security and resiliency controls aligned with recognized frameworks such as NIST, OWASP, SANS Top 20, PCI DSS, and CIS Controls. The position provides risk assessment and advisory services to technology engineers and business management by communicating technology risks, mitigation strategies, and risk acceptance decisions. The role also involves assessing application architectures for design-related security risks, recommending remediation strategies, and advising engineering leadership and developers on emerging threats in web and mobile application environments. The role drives adoption of embedded application security controls within the Software Development Life Cycle (SDLC), provides subject matter expertise in secure application design and development techniques, and supports the convergence of information security standards, solutions, and tools across the organization. Additional responsibilities include developing customized security testing strategies to complement vulnerability scanning and security testing programs managed by Technology Risk, analyzing vulnerability scan reports, and advising development teams on secure coding and application security best practices. The role requires expertise in multi-domain information security disciplines including vendor security, vulnerability management, data loss prevention, data encryption, and infrastructure security, as well as knowledge of technology risk analytics including metrics reporting and dashboarding. Preferred technical expertise includes secure coding languages such as Python, Java, and Go, industry certifications such as CISSP, CISM, CRISC, CISA, or AWS Certified Security – Specialty, and familiarity with leveraging AI/ML technologies to enhance security operations and scale cybersecurity programs.
Required skills
Key responsibilities
- Define and oversee the information security and cybersecurity risk posture for the Asset Management Private business within the Asset & Wealth Management division
- Lead and manage Governance, Risk & Compliance (GRC), Application Security & Advisory, and Product Security teams while providing oversight and guidance to embedded Technology Risk Officers across Asset Management business verticals
- Collaborate with internal application development teams to integrate information security and business resiliency control requirements into next-generation business applications
- Partner with global Application Security Risk, Business Continuity, Risk Measurement, and Technology Risk teams to develop and implement best-in-class cybersecurity and resiliency controls
- Conduct technology risk assessments and provide advisory services to technology engineers, engineering leadership, and business management regarding risk mitigation and risk acceptance strategies
- Assess application architectures and existing applications for design-related security risks and guide teams on remediation actions and secure development approaches
- Provide subject matter expertise on emerging web and mobile application threats and advise development teams on secure application design and secure coding techniques
- Drive adoption of embedded application security controls within the Software Development Life Cycle (SDLC) and support the implementation of secure development frameworks
- Contribute to the adoption and convergence of information security standards, solutions, and tools aligned with frameworks such as NIST, OWASP, SANS Top 20, PCI DSS, and CIS Controls
- Develop customized security testing strategies and analyze vulnerability scanning reports to enhance application security testing programs and support secure application deployment
Experience & skills
- Demonstrate at least 5 years of progressive experience across multiple information security domains including vendor security, application security, vulnerability management, data loss prevention, data encryption, and infrastructure security
- Demonstrate expert knowledge of global financial regulatory frameworks including SEC, FINRA, GDPR, and CCPA and the ability to apply cybersecurity risk management methodologies such as FAIR (Factor Analysis of Information Risk)
- Demonstrate expertise in performing technology risk assessments, identifying gaps in compliance with information security policies, and recommending risk mitigation strategies
- Demonstrate familiarity with leading cybersecurity frameworks and standards including NIST, OWASP, SANS Top 20, PCI DSS, and CIS Controls
- Demonstrate expertise in secure application design, Software Development Life Cycle (SDLC) practices, vulnerability scanning, code review analysis, and application security best practices
- Demonstrate capability in technology risk data analytics including metrics reporting and dashboarding for cybersecurity risk monitoring
- Demonstrate experience collaborating with engineering teams, technology risk functions, and audit partners to deliver security programs and resolve audit findings
- Possess a BS or MS degree in Computer Science, Cyber Security, Information Security, or a related technical field
- Possess relevant cybersecurity certifications such as CISSP, CISM, CRISC, CISA, or cloud security certifications including AWS Certified Security – Specialty
- Demonstrate knowledge of secure coding languages including Python, Java, or Go and familiarity with applying AI/ML technologies to enhance security operations