|
Role Overview The Cybersecurity and Client Engagement Risk Associate position in Asset and Wealth Management engages new and existing institutional clients, supports compliance activities (e.g., SOC reports, ISO, PCI, NYDFS, etc) and engages across the firm with Business, Engineering, Legal and Cyber SMEs. This role includes critical activities such assessing and negotiating tech risk commitments, responding and editing security agreements/assessments, and getting involved in addressing technical and business cyber activities. Key Responsibilities
- Client Due Diligence & Revenue Protection:
- Engagement: Proactively engages with institutional clients to articulate Goldman Sachs' robust information security posture and address their specific security and compliance inquiries.
- Client Vendor Due Diligence: Executes comprehensive client-focused vendor due diligence processes, assessing third-party information security risks specifically within the financial services regulatory landscape.
- Operational: Actively participates in and drives resolution of complex technical and business cyber activities, including security architecture reviews, control implementation, and operationalizing compliance requirements.
- Strategic innovation: Partner in integration of Artificial Intelligence (AI) and Machine Learning (ML) to automate due diligence, contract engagements, and scale the program efficiently.
- Research and evaluate emerging global client trends in client contract focus, and regulatory landscapes to advise affiliates and internal stakeholders on proactive contractual/regulatory risk mitigation strategies.
Skills and Experience Required
Preferred Qualifications
- BS degree in Computer Science, Cyber Security, Information Security, or a related technical field.
- Relevant industry certifications such as CISSP, CISM, CRISC, CISA, or cloud-specific security certifications (e.g., AWS Certified Security - Specialty).
- 1-2 yrs Operational and/or experience with Cloud services (as provider or client) or certified CCNA, CCNP, AWS security.
- Implementation and/or operational experience with Third Party Risk (TPRM), Risk Management Solutions (ex: SAP GRC, LogicManager, ServiceNow, Audit Board, RSA Archer, Reciprocity, etc.) or deploying automated DDQ workflows
- Scripting/Automation: Practical experience with scripting or automation (e.g., Python, PowerShell) for security tasks and data analysis.
- Familiarity with leveraging Artificial Intelligence and Machine Learning (AI/ML) for AI Governance (e.g., data poisoning, prompt injection), automating compliance checks, or enhancing cybersecurity capabilities, such as predictive risk modeling, anomaly detection in vendor assessments.
|