Risk, Operational Risk, Information & Cybersecurity - Vice President - New York

New York, New York, United States

Goldman Sachs

The Goldman Sachs Group, Inc. is a leading global investment banking, securities and investment management firm that provides a wide range of financial services to a substantial and diversified client base.

View all jobs at Goldman Sachs

Apply now Apply later

Organization: Risk Division, Operational Risk 

Team / Role: Information and Cybersecurity

Level/Location: Vice President, Dallas - Salt Lake City

The Operational Risk Department at Goldman Sachs is an independent risk management function responsible for developing and implementing a standardized framework to identify, measure, and monitor operational risk across the firm. 

This Information and Cybersecurity role is for a professional with technology subject matter expertise dedicated to strengthening the components of the firm’s operational risk management framework relating to information and cybersecurity risks.  This role will be responsible to continuously identify, monitor, measure and assess operational risk for the Engineering division and Engineering elements of other divisions.    

Responsibilities:

  • Identify, monitor, and analyze operational risks arising from the execution of technology operations including but not limited to cybersecurity, cloud security, patch management, data protection/privacy, identity access management, etc. and develop evidence-based challenges focused on improving such operations
  • Monitor the control inventory for sufficiency and completeness and challenge the absence of controls and implementation of controls within engineering standards
  • Propose qualitative and quantitative operational risk appetite/tolerance and monitor risk taking trends through bespoke metrics at firmwide and divisional/sub-divisional levels, escalating concerns to senior management when warranted
  • Conduct scenario analysis by working with stakeholders to develop plausible tail risk scenarios used in quantifying specific businesses exposure to potential risk
  • Facilitate operational risk event and data collection; perform detailed reviews of trends to identify significant risks and ensure monitoring and remediation 
  • Review New Activities and ensure operational risks arising from acquisitions, new products and/or business, and migrations, etc. are properly considered
  • Contribute to divisional and functional risk profile assessments by highlighting risk issues and trends to senior divisional managers and senior Operational Risk management team 
  • Conduct quarterly triggered assessments for the division to ensure the divisions risk and control self -assessment outcome are consistent, credible, and underpinned by appropriate evidence
  • Remain current on business drivers, regulatory and industry changes impacting the firms information and cybersecurity activities and obligations
  • Contribute to the advancement of operational risk methods and practices and the operational risk management framework 
  • Identify and drive initiatives that improve the risk management activities at the firm
  • This role requires an energetic self-starter that can liaise with Engineering teams both regionally and globally.  Experience and knowledge in a regulated enterprise network, preferably financial institution’s technology infrastructure/applications and control requirements are required together with strong interpersonal and analytical skills for this role.

 

Qualifications

  • Strong business acumen with general awareness of technology related processes, risks and business flows
  • 8+ years of relevant experience, which could include working in operational risk; in a financial institution’s technology division; a technology company that builds or maintains enterprise systems, like cloud services; offensive or defensive cybersecurity; or IT or Information Security/Cybersecurity auditors.
  • Strong verbal and written communication skills with the ability to present with impact and influence
  • Experience with frameworks like NIST (Cybersecurity Framework, 800-53), COBIT, Cloud Security Alliance Cloud Controls Matrix ,and/or ISO 27001
  • Ability to work in a fast-paced environment with a strong delivery focus
  • Strong organizational skills (project management experience a plus)
  • Ability to work in a team environment and knowledge share with other colleagues within team
  • Proficiency in World, Excel, PowerPoint, SharePoint/OneDrive – SQL, graph databases and Tableau (would be a plus)
  • Familiarity with enterprise risk management best-practices and controls
  • Possess a Bachelor's Degree in Computer Science, Cybersecurity, Business and Technology Management, Finance, Data Science, or related disciplines
  • Technology skills including substantive subject matter expertise in several areas, including:
  • Deep understanding of Linux and Windows operating systems
  • Internet infrastructure design and installation and support of network devices and firewalls
  • Cloud computing concepts, technologies, risks and mitigating controls
  • Systems and security administration and configuration of servers and desktops (UNIX, Windows, directory services etc.)
  • Security risks related to web, mobile, web services, and client/server architectures
  • Encryption schemes (symmetric, asymmetric, and hashing) and how they may be applied in an application architecture
  • Vulnerability assessment and penetration testing methodologies and processes for web, thick client and mobile applications
  • Experience with Splunk and/or other SIEM platforms would be useful but not required
  • Threat modelling, intelligence and incident response
  • Management, monitoring and operations of technology (backups, change management, system monitoring, incident/problem Management)
  • Business continuity planning and disaster recovery design and implementation
  • Security within the software development lifecycle

 


  ABOUT GOLDMAN SACHS
  At Goldman Sachs, we commit our people, capital and ideas to help our clients, shareholders and the communities we serve to grow. Founded in 1869, we are a leading global investment banking, securities and investment management firm. Headquartered in New York, we maintain offices around the world. 
  We believe who you are makes you better at what you do. We're committed to fostering and advancing diversity and inclusion in our own workplace and beyond by ensuring every individual within our firm has a number of opportunities to grow professionally and personally, from our training and development opportunities and firmwide networks to benefits, wellness and personal finance offerings and mindfulness programs. Learn more about our culture, benefits, and people at GS.com/careers. 
  We’re committed to finding reasonable accommodations for candidates with special needs or disabilities during our recruiting process. Learn more: https://www.goldmansachs.com/careers/footer/disability-statement.html
 
  © The Goldman Sachs Group, Inc., 2023. All rights reserved. Goldman Sachs is an equal employment/affirmative action employer Female/Minority/Disability/Veteran/Sexual Orientation/Gender Identity
 

Salary Range 
The expected base salary for this New York, New York, United States-based position is $130000-$260000. In addition, you may be eligible for a discretionary bonus if you are an active employee as of fiscal year-end.

Benefits 
Goldman Sachs is committed to providing our people with valuable and competitive benefits and wellness offerings, as it is a core part of providing a strong overall employee experience. A summary of these offerings, which are generally available to active, non-temporary, full-time and part-time US employees who work at least 20 hours per week, can be found here.

Apply now Apply later
  • Share this job via
  • 𝕏
  • or
Job stats:  0  0  0

Tags: Banking Cloud COBIT Computer Science Encryption Finance Firewalls Hashing Incident response ISO 27001 Linux Monitoring NIST NIST 800-53 Pentesting Privacy Risk management RMF SDLC SharePoint SIEM Splunk SQL UNIX Windows

Perks/benefits: Career development Competitive pay Salary bonus Wellness

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.