Internal Audit, Tech Risk & Cybersecurity, Associate, Singapore

Singapore, Singapore, Singapore

Applications have closed

Goldman Sachs

The Goldman Sachs Group, Inc. is a leading global investment banking, securities and investment management firm that provides a wide range of financial services to a substantial and diversified client base.

View company page

Internal Audit – Core Engineering / Tech Risk and Cybersecurity (Associate, Singapore)

What We Do
As the third line of defense, Internal Audit’s mission is to independently assess the firm’s internal control structure, including the firm’s governance processes and controls, and risk management and capital and anti-financial crime frameworks, raise awareness of control risk and monitor the implementation of management’s control measures.  In doing so, internal Audit:

  • Communicates and reports on the effectiveness of the firm’s governance, risk management and controls that mitigate current and evolving risk
  • Raise awareness of control risk
  • Assesses the firm’s control culture and conduct risks; and
  • Monitors management’s implementation of control measures


Goldman Sachs Internal Audit is organized into global teams comprising business and technology auditors to cover all the firm’s businesses and functions, including global markets, investment banking, consumer and investment management, risk management, finance, cyber-security and technology risk, and core engineering. 

Who We Look For 
Goldman Sachs Internal Auditors demonstrate strong risk and control mindsets, analytical, exercise professional skepticism and are able to challenge and discuss effectively with management on risks and control measures.  We look for individuals who enjoy learning about audit, businesses and functions, have innovative and creative mindsets to adopt analytical techniques to enhance audit techniques, building relationships and are able to evolve and thrive in teamwork and in a fast-paced global environment. 


IA Core Engineering and Cybersecurity Team performs the review of technology risks and controls within a challenging, dynamic, and complex technology environment in GS. 


The role involves:

  1. Understanding the technology and cybersecurity related regulatory requirements in APAC and articulating their impact to the Internal Audit function. Additionally, provide key insights to the wider audit team on the application of these requirements.
  2. Identifying the regulatory requirements in the APAC applicable to GS’ technology and infrastructure landscape in the region and formulating an audit plan / strategy to address these requirements in compliance with the regulatory expectations.
  3. Identifying risks and new / updated regulatory requirements in the APAC region which can help in the future audit plan and strategy formulations.
  4. Bridging the gap between the local and global audit teams to ensure global audits are sufficiently leveraged to address region specific requirements, wherever applicable.
  5. Providing timely updates to the global counterparts on developments in the APAC region, including key technology developments and changes, new regulations / standards / guidelines, regulatory inspections, security incidents causing business disruption, key organizational changes etc.


A strong background in technology or engineering and a proven technology audit background are necessary. 

As part of the third line of defense, you will be involved in independently assessing the firm’s overall control environment, effectiveness of the firm’s controls that mitigate current and emerging risks, monitoring the management’s implementation of control measures and communicating the results to the firm’s local and global management. In doing so, you are supporting the provision of independent, objective and timely assurance around the firm’s internal control structure, and supporting the Audit Committee, the Board of Directors and Risk Committee in fulfilling their oversight responsibilities. You will play a vital role in the scoping and planning of the audits, deploy audit and analytical procedures and techniques to assess the design and operating effectiveness of the controls to mitigate the risks, and discuss the results with the firm’s local and global management. In addition, you will also monitor and follow-up with management on the resolution of the open audit findings.
  • Minimum 3 years of experience as a technology auditor, leading audits / compliance assessments covering IT general controls, cybersecurity controls, MAS requirements
  • Basic understanding of technology audit methodologies
  • Understanding of different components within the technology stack, e.g. Operating systems, networks or cloud computing
  • Strong written and verbal communication skills
  • Self-driven and proactive in taking full ownership and accountability of the assigned tasks and tracking them to completion within the stipulated timelines and as per the firm’s quality standards

Technology audit skills, including understanding of (but not limited to):

  • Relevant degree in Computer Science, Information Security, Engineering or equivalent
  • Relevant technology standards and regulations – ISO 27001, NIST Framework, MAS notices, standards and guidelines etc.
  • Relevant certification or industry accreditation (e.g., CISA, CISM, CISSP and/or Cloud  Certifications)  

The Goldman Sachs Group, Inc. is a leading global investment banking, securities and investment management firm that provides a wide range of financial services to a substantial and diversified client base that includes corporations, financial institutions, governments and individuals. Founded in 1869, the firm is headquartered in New York and maintains offices in all major financial centers around the world.


* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Tags: Audits Banking CISA CISM CISSP Cloud Compliance Computer Science Finance Governance ISO 27001 Monitoring NIST Risk management Strategy

Region: Asia/Pacific
Country: Singapore
Job stats:  6  0  0
Category: Compliance Jobs

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.