Goldman Sachs is a leading global financial institution that delivers a broad range of financial services to a large and diversified client base that includes corporations, financial institutions, governments, and individuals. Founded in 1869, the firm is headquartered in New York and maintains offices in all major financial centers around the world. RISK Goldman Sachs' Core Engineering Risk Management in the Engineering Division develops comprehensive programs to manage operational and financial risks in support of the firm's risk appetite statement and strategic Engineering business plans. Risk teams play a critical function for the firm, driving how the firm considers and manages risk. The group works closely with the development teams and Technology Risk teams to help identify, resolve, and baseline risk remediation efforts and associated priorities. Risk professionals execute critical day-to-day risk management activities, lead strategic risk initiatives, and contribute to the ongoing advancement of the firm's risk management framework. They are analytically curious, have an aptitude to challenge, and an unwavering commitment to excellence. CORE ENGINEERING RISK MANAGEMENT The Core Engineering Risk Management group is responsible for designing, executing, and maintaining various aspects of the Engineering Division's risk governance and strategy components globally. This group reports into the Engineering Division's Chief Technology Officer (CTO) and plays a key role in increasing the transparency of risks and influencing related decision making and prioritization. HOW YOU WILL FULFILL YOUR POTENTIAL
- Drive risk reduction around technology, data, and risk and ensuring compliance with policies, procedures, and processes
- Build the overall risk profile of the division and work with stakeholders to create a plan towards reducing risk exposure in an agile, collaborative, and well socialized manner
- Create presentations and security risk related content for stakeholders
- Assist in determining the scope of risk projects and tracking through burndown completion
- Provide advice to business & technology users on (1) understanding of relevant Technology Risk policies and standards and (2) principles of security & controls as defined by the firm's Technology Risk and Control Framework, and (3) adoption of secure and resilient solutions
- Perform data analysis of known risk findings to identify gaps in compliance to information security (application and infrastructure) & vulnerability standards and policies, for both internal technology solutions as well as solutions provided by third-party service providers
- Provide clear and concise verbal and written recommendations and guidance to both business and technology staff on matters impacting their areas of focus
- Develop, maintain, and improve Technology Risk Program by highlighting emerging risks and their impact to the business
- Support the treatment and management of findings in the business unit from all sources
- Strong desire to grow and develop in the risk management space
- Perform analysis of risk findings to determine root cause and provide insight to stakeholders
SKILLS AND EXPERIENCE WE ARE LOOKING FOR
- 1-3 years of technology experience in one or more of the following areas: Information Security, Technology Governance, Operational Risk, Technology Audit, Technology Infrastructure or Application Development
- Strong program and project management skills and technology expertise
- Ability to analyze internal and external processes and integration to understand risk
- Ability to assess and evaluate corporate risk tolerance and translate into goals and new processes including software engineering, IT teams, and other relevant stakeholders
- Understanding of relevant audit and control standards and the ability to drive and maintain the compliance initiative across the organization
- Experience collaborating with a team of security experts in a diverse set of security topics including, but not limited to, security architecture, financial controls and regulatory compliance, identity and access management, penetration testing, data loss prevention, network security, security monitoring, white box testing/static code analysis, and building secure systems
- Ability to communicate effectively with technical and non-technical stakeholders
- Expertise with MS-Office 365 suite, and SharePoint
- Experience creating and clearly communicating business metrics to diverse audiences
- Experience with BI tooling
ABOUT GOLDMAN SACHS At Goldman Sachs, we commit our people, capital, and ideas to help our clients, shareholders, and the communities we serve to grow. Founded in 1869, we are a leading global investment banking, securities, and investment management firm. Headquartered in New York, we maintain offices around the world. We believe who you are makes you better at what you do. We're committed to fostering and advancing diversity and inclusion in our own workplace and beyond by ensuring every individual within our firm has a number of opportunities to grow professionally and personally, from our training and development opportunities and firmwide networks to benefits, wellness and personal finance offerings and mindfulness programs. Learn more about our culture, benefits, and people at GS.com/careers. We're committed to finding reasonable accommodations for candidates with special needs or disabilities during our recruiting process. Learn more: https://www.goldmansachs.com/careers/footer/disability-statement.html
|