About The Position

Goldman Sachs & Co. LLC is seeking an Associate, Risk Governance in Dallas, Texas. This role involves leading and executing division-wide Risk and Control Self-Assessment (RCSA) initiatives globally to ensure alignment with US and international regulatory standards. The position requires conducting RCSAs across various engineering processes, including SDLC, CI/CD pipelines, cloud infrastructure, and production change management. The Associate will partner with engineering teams to identify operational and compliance risks, such as technology operations risks, infosec and cyber risks, third-party risks, data loss, data privacy, records management, and regulatory reporting integrity. A key responsibility is to drive the review and optimization of analytical tools and dashboards for RCSA and SOX mandates. The role also includes designing, documenting, and operationalizing preventive and detective controls within engineering workflows, and utilizing Generative AI tools to automate control evidence collection, summarization, policy drafting, risk assessments, and incident triage. The Associate will also triage operational incidents, perform root-cause analysis, coordinate responses to internal audit findings, and prepare materials for risk committees and senior management. Promoting a strong risk culture through training and onboarding is also part of the role, as is uplifting the risk taxonomy and recommending best practices for control design and execution testing.

Requirements

  • Master’s degree (U.S. or foreign equivalent) in Computer Science, Information Systems, Management Science, Cyber Security, or a related field, and one (1) year of experience in the job offered or in a related role OR Bachelor’s degree (U.S. or foreign equivalent) in Computer Science, Information Systems, Management Science, Cyber Security, or a related field, and three (3) years of experience in the job offered or in a related role.
  • Prior experience must include one (1) year of experience (with Master’s) or three (3) years of experience (with Bachelor’s) with risk Frameworks including NIST Cybersecurity Framework (CSF).
  • Prior experience must include one (1) year of experience (with Master’s) or three (3) years of experience (with Bachelor’s) with performing statistically driven analysis using various data analytical techniques to identify trends and propose process enhancements.
  • Prior experience must include one (1) year of experience (with Master’s) or three (3) years of experience (with Bachelor’s) with visualizing complex data analyses from raw data in risk management reports, using visualization tools such as Tableau, and communicating results to a wide variety of audiences.
  • Prior experience must include one (1) year of experience (with Master’s) or three (3) years of experience (with Bachelor’s) with leveraging analytics and automation experience to propose effective and efficient methods to enhance testing and sampling strategies to ensure the most effective risk detection and analyses.
  • Prior experience must include one (1) year of experience (with Master’s) or three (3) years of experience (with Bachelor’s) with developing processes and tools to identify and monitor data accuracy.

Responsibilities

  • Lead and execute division-wide Risk and Control Self-Assessment (RCSA) initiatives across the global enterprise to ensure full alignment with US and international regulatory standards.
  • Conduct Risk and Control Self-Assessments (RCSAs) across engineering processes including SDLC, CI/CD pipelines, cloud infrastructure, and production change management.
  • Partner with engineering teams to identify operational risks (e.g. Technology operations risks, infosec and cyber risks, third party risks, data loss) and compliance risks (e.g., data privacy, records management, regulatory reporting integrity).
  • Drive the review, and optimization of analytical tools and dashboards to streamline the assessment, visualization, and reporting of RCSA and SOX mandates.
  • Design, document, and operationalize preventive and detective controls embedded within engineering workflows (e.g., automated policy-as-code, pipeline gates, access provisioning checks).
  • Use Generative AI tools (e.g., GitHub Copilot, internal LLM copilots, agentic workflow platforms) to automate control evidence collection and summarization, draft policies, risk assessments, and audit responses and triage and classify incidents and risk events at scale.
  • Triage operational incidents and near-misses originating from engineering systems; perform root-cause analysis with SRE and engineering leads.
  • Coordinate responses to internal audit findings, 2LoD challenge related to engineering processes.
  • Prepare materials for Engineering Risk Committees and senior management forums; translate technical risk into business language.
  • Promote a strong risk culture through training, lunch-and-learns, and onboarding for new engineers.
  • Uplift risk taxonomy to reflect changes to risk profile for the Engineering Division - Identify new controls to effectively mitigate any gaps in risk exposure.
  • Recommend best practices for design and execution of controls testing within GS Engineering areas and to validate the remediation of identified system control weaknesses, utilizing various techniques such as data analysis, code review, re-performance of processing logic, observation and interviews to evaluate the adequacy of operational and compliance risks and controls.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service