What We Do
As the third line of defense, Internal Audit independently assesses the firm’s governance, risk management and control environment. Our work helps the firm identify control gaps, challenge risk management practices, and support timely remediation of current and emerging risks.
Internal Audit provides assurance over the effectiveness of controls across the firm, including business processes, engineering platforms, cyber, data, operational resilience and regulatory risks. In doing so, Internal Audit:
- Communicates and reports on the effectiveness of governance, risk management and controls;
- Raises awareness of current and emerging control risks;
- Assesses the firm’s control culture and conduct risks;
- Challenges management’s design and implementation of control measures; and
- Monitors the remediation of identified control issues.
Goldman Sachs Internal Audit is organized into global teams comprising business and engineering auditors covering the firm’s businesses and functions, including Global Banking & Markets, Asset & Wealth Management, Risk, Finance, Operations, Engineering, Cybersecurity and other enterprise-wide functions.
Who We Look For
Goldman Sachs Internal Auditors demonstrate strong risk and control mindsets, analytical, exercise professional skepticism and are able to challenge and discuss effectively with management on risks and control measures. We look for individuals who enjoy learning about audit, businesses and functions, have innovative and creative mindsets to adopt analytical techniques to enhance audit techniques, building relationships and are able to evolve and thrive in teamwork and in a fast-paced global environment.
Global Banking & Markets – Engineering Audit
As a Global Banking & Markets Engineering auditor, you will assess engineering processes, systems, applications and controls that support the firm’s trading, booking, settlement, reporting and risk management activities. The role provides exposure to front-office platforms, data flows, application controls and general engineering controls across the region and globally.
The audit coverage may include areas such as application entitlements, software change management, system resiliency, data quality, data retention, information security controls, cloud and infrastructure risk, vendor and third-party dependency risk, and the governance of new engineering practices such as AI / GenAI-enabled development and automation.
Your Impact
As part of the third line of defense, you will help provide independent and objective assurance over the firm’s control environment. Your work will support management, the Audit Committee, the Board of Directors and Risk Committees in understanding whether key risks are appropriately identified, controlled and remediated.
You will contribute to audits that assess how engineering risks are managed across critical business processes. This includes evaluating whether controls are well designed, operating effectively, and keeping pace with changes in business strategy, regulation, engineering practices and the external risk environment.
Responsibilities
As an Analyst / Associate, you will be a member of an audit team and play an important role in audit planning, execution and reporting. Your responsibilities may include:
- Understanding business and engineering processes, including trading platforms, data flows, system architecture and operational workflows;
- Identifying key engineering, data, cyber, operational and regulatory risks;
- Assessing the design and operating effectiveness of controls;
- Reviewing application controls, entitlement processes, change management, incident management, data quality, data retention and system resiliency controls;
- Evaluating risks associated with cloud platforms, third-party services, automation and AI-enabled development practices;
- Performing data analysis to identify trends, exceptions and control issues;
- Documenting audit work clearly and supporting conclusions with evidence;
- Communicating audit observations and control concerns to stakeholders; and
- Working with global audit colleagues and management to support timely remediation of identified issues.
Basic Qualifications
- At least 2 years of experience as an engineering auditor, risk management professional, consultant, software engineer, control specialist or other relevant industry experience;
- University degree in Computer Science, Engineering, Information Systems, Finance, Risk Management or a related discipline;
- Strong written and verbal communication skills;
- Understanding of software development, system architecture and engineering control concepts;
- Basic understanding of databases, operating systems, messaging, APIs, cloud or infrastructure concepts;
- Ability to analyze risks and controls across complex engineering environments;
- Strong analytical, problem-solving and teamwork skills;
- Interest in learning about financial markets, trading systems and regulatory expectations; and
- Japanese language skills required.
Preferred Qualifications
- Experience in Internal Audit, engineering risk management, cybersecurity, application development, software quality assurance, operational resilience or control testing
- Understanding software development lifecycle, DevOps, change management and production release processes;
- Experience with data analytics tools or programming languages such as Python, SQL, Java, C++ or similar;
- Knowledge of cyber risk, identity and access management, cloud governance, data governance or third-party dependency risk;
- Awareness of AI / GenAI governance, model risk, automation risk or controls over AI-enabled development;
- Experience reviewing application controls supporting trading, booking, settlement, reporting, clearing or payment processes;
- Relevant certification or industry accreditation such as CISA, CISSP, CRISC, CIA or similar;
- Knowledge of financial products, banking, markets, clearing or payment services; and
- Strong project management skills and ability to manage multiple priorities.
ABOUT GOLDMAN SACHS
At Goldman Sachs, we commit our people, capital and ideas to help our clients, shareholders and the communities we serve to grow. Founded in 1869, we are a leading global investment banking, securities and investment management firm. Headquartered in New York, we maintain offices around the world.
We believe who you are makes you better at what you do. We're committed to fostering and advancing diversity and inclusion in our own workplace and beyond by ensuring every individual within our firm has a number of opportunities to grow professionally and personally, from our training and development opportunities and firmwide networks to benefits, wellness and personal finance offerings and mindfulness programs. Learn more about our culture, benefits, and people at GS.com/careers.
We’re committed to finding reasonable accommodations for candidates with special needs or disabilities during our recruiting process. Learn more: https://www.goldmansachs.com/careers/footer/disability-statement.html
© The Goldman Sachs Group, Inc., 2025. All rights reserved.
Goldman Sachs is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sex, national origin, age, veterans status, disability, or any other characteristic protected by applicable law.