Technology Risk - Dallas- Data Privacy Associate
On-siteDallas, Texas, United States
Job Summary
Conduct security reviews of systems and applications to identify potential data privacy risks and recommend technical mitigation strategies. Drive the adoption of robust data security controls and privacy-enhancing technologies across applications and platforms to uplift the control posture for personal data. Provide advice and guidance to engineering teams on applying relevant security policies and standards, and on integrating security controls defined in the firm's Technology Risk and Control Framework to enable privacy by design from the outset. Collaborate with Legal and Compliance to understand regulatory requirements and translate them into actionable technical security controls. This role supports the planning, execution, and enhancement of data protection initiatives within Goldman Sachs Technology Risk, focusing on strengthening personal data security and implementing privacy-by-design principles through technical controls.
Required Qualifications
- Bachelor's degree in information/cyber security, Computer Science, Software Engineering, or a related technical field.
- 1-3 years of experience in security, technical risk management, or data protection function.
- Strong understanding of data security concepts and practices, including encryption, access controls, data minimization, and data de-identification.
- Familiarity with privacy-by-design principles and their practical implementation within technology solutions.
- Technical knowledge of technology architecture, infrastructure, and the Software Development Lifecycle (SDLC).
- Experience with data analysis tools like Excel, PowerBI, or Alteryx.
- Proven analytical thinking abilities and problem-solving skills, particularly in assessing technical security risks related to data privacy.
- Excellent oral, written, and presentation communication skills, with the ability to explain complex technical details to diverse audiences.
- Ability to work effectively in a team environment and independently
Desired Qualifications
- Relevant industry certifications (e.g., Security+, CySA+, CCSP, CIPT, CISSP, CIPM).
- Experience with technical risk analysis and control frameworks (e.g., NIST Cybersecurity Framework, ISO 27001/27701).
- Understanding of relational database technologies (e.g., SQL) and data storage principles.
- Knowledge of networking technologies and operating systems.
- Familiarity with data lifecycle management, data mapping, and inventory from a security control perspective.
- An understanding of the regulatory environment related to technology control requirements, with an emphasis on how security controls address global data protection regulations.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.