
Posted 10 days ago
No clicks
**Role: Associate, Risk Governance - Dallas** - **Responsibilities:** Lead division-wide Risk and Control Self-Assessment (RCSA) initiatives; conduct RCSA across engineering processes; partner with teams to identify risks; drive optimization of analytical tools; design and operationalize preventive controls; automate control evidence and policy generation; triage operational incidents. - **Skills & Experience:** Master's or Bachelor’s degree with relevant experience in Computer Science, Information Systems, Management Science, or Cyber Security; experience with risk frameworks like NIST CSF; statistically driven data analysis; data visualization with tools like Tableau; automation and analytics to enhance risk detection; process development for data accuracy. - **Keywords:** Risk Governance, Risk and Control Self-Assessment (RCSA), Engineering Division, RCSA, data analytics, data visualization, automation, cybersecurity, Dallas, Texas.
- Compensation
- Not specified USD
- City
- Dallas
- Country
- United States
Currency: $ (USD)
Full Job Description
Job Duties: Associate, Risk Governance with Goldman Sachs & Co. LLC in Dallas, Texas. Lead and execute division-wide Risk and Control Self-Assessment (RCSA) initiatives across the global enterprise to ensure full alignment with US and international regulatory standards. Conduct Risk and Control Self-Assessments (RCSAs) across engineering processes including SDLC, CI/CD pipelines, cloud infrastructure, and production change management. Partner with engineering teams to identify operational risks (e.g. Technology operations risks, infosec and cyber risks, third party risks, data loss) and compliance risks (e.g., data privacy, records management, regulatory reporting integrity). Drive the review, and optimization of analytical tools and dashboards to streamline the assessment, visualization, and reporting of RCSA and SOX mandates. Design, document, and operationalize preventive and detective controls embedded within engineering workflows (e.g., automated policy-as-code, pipeline gates, access provisioning checks). Use Generative AI tools (e.g., GitHub Copilot, internal LLM copilots, agentic workflow platforms) to automate control evidence collection and summarization, draft policies, risk assessments, and audit responses and triage and classify incidents and risk events at scale. Triage operational incidents and near-misses originating from engineering systems; perform root-cause analysis with SRE and engineering leads. Coordinate responses to internal audit findings, 2LoD challenge related to engineering processes. Prepare materials for Engineering Risk Committees and senior management forums; translate technical risk into business language. Promote a strong risk culture through training, lunch-and-learns, and onboarding for new engineers. Uplift risk taxonomy to reflect changes to risk profile for the Engineering Division - Identify new controls to effectively mitigate any gaps in risk exposure. Recommend best practices for design and execution of controls testing within GS Engineering areas and to validate the remediation of identified system control weaknesses, utilizing various techniques such as data analysis, code review, re-performance of processing logic, observation and interviews to evaluate the adequacy of operational and compliance risks and controls.
Job Requirements: Masters degree (U.S. or foreign equivalent) in Computer Science, Information Systems, Management Science, Cyber Security, or a related field, and one (1) year of experience in the job offered or in a related role OR Bachelors degree (U.S. or foreign equivalent) in Computer Science, Information Systems, Management Science, Cyber Security, or a related field, and three (3) years of experience in the job offered or in a related role. Prior experience must include one (1) year of experience (with Masters) or three (3) years of experience (with Bachelors) with each of the following: risk Frameworks including NIST Cybersecurity Framework (CSF); performing statistically driven analysis using various data analytical techniques to identify trends and propose process enhancements; visualizing complex data analyses from raw data in risk management reports, using visualization tools such as Tableau, and communicating results to a wide variety of audiences; leveraging analytics and automation experience to propose effective and efficient methods to enhance testing and sampling strategies to ensure the most effective risk detection and analyses; and developing processes and tools to identify and monitor data accuracy.
The Goldman Sachs Group, Inc., 2026. All rights reserved. Goldman Sachs is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sex, national origin, age, veteran status, disability, or any other characteristic protected by applicable law.




