Day 1 — The Regulatory Briefing
Goldman Sachs · SIEM Platform Migration to Splunk Cloud
Section 1 of 5 · Scene Setup
~18 min left
Scene Setup
You badge in at 200 West Street at 8:15 AM on a Monday morning. Goldman Sachs headquarters rises 43 stories above the Hudson River — glass and steel, deliberately understated for a firm that manages $2.9 trillion in assets. The lobby is controlled chaos: turnstiles scanning badges, security guards with earpieces, and a stream of analysts in fleece vests heading toward the elevator banks. Your temporary badge reads "CONTRACTOR — ENGINEERING" and gets you past the first checkpoint. A security escort meets you at the 28th floor — the Cybersecurity & Technology Risk wing — and walks you through a set of glass doors that require a second badge tap.
Katherine Aldridge, VP of Technology Risk & Governance, is waiting in a glass-walled conference room labeled "GS-28-Fortis." She is mid-40s, precise in manner, wearing a navy blazer and reading glasses pushed up on her head. A printed agenda sits in front of her, color-coded. She stands, shakes your hand firmly. "Welcome to Goldman. I'm Katherine — I run Technology Risk and I'm your direct manager for this programme. I've been holding this together for five weeks since our last PM left. Let me be direct: this project has a regulatory deadline that does not move, a budget that was approved at the Board level, and a vendor that's been onboarded but not yet fully mobilized. You are stepping into a moving train."
She walks you through the floor. It is quieter than you expected — most of the Security Engineering team works remotely three days a week, she explains. You pass a SOC observation window where a handful of analysts sit in front of multi-monitor setups, ArcSight dashboards glowing green and amber. "That's the 24/7 SOC. Twelve analysts across three shifts. They live in ArcSight. Everything we're about to do affects how they work." She points to a corner office. "That's David Park's office — VP Security Engineering. He built all of this. You'll meet him tomorrow." She pauses at a closed door labeled "CISO — R. Nair." "Rajesh is expecting us at 9:00. He wants to brief you personally on the OCC finding. It's classified internally as Sensitive — do not discuss specifics outside the programme team."
Katherine hands you a laptop, a SecurID token for VPN access, and a thin folder. Inside: a one-page programme summary, the previous PM's exit notes (three paragraphs, brutally honest), and a printed copy of the OCC examination finding summary with "CONFIDENTIAL — REGULATORY" stamped in red across the top. "Read the OCC document before we go in. Rajesh will assume you've read it."