Skip to content
Goldman Sachs logo

Financial Services — Investment Banking · SIEM Platform Migration · Goldman Sachs

SIEM Platform Migration Project Manager Simulation — Goldman Sachs

Lead a $14.5M SIEM platform migration for Goldman Sachs after an OCC examination finding mandates modernization within 12 months. What was framed as a technology refresh is actually a regulatory remediation project — the OCC found critical gaps in log coverage, correlation capabilities, and incident response timelines that put Goldman's banking charter at risk. Navigate the Compliance Hammer across 27 simulated days as regulatory pressure, SOC operational complexity, and trading floor politics collide. Gain hands-on project management experience over 27 days of real decisions, stakeholders, and PMO deliverables — no prior experience required.

27-day simulationAdvancedHybridFinancial Services — Investment BankingIT: Information Security

The scenario

Goldman Sachs — one of the world's leading investment banking, securities, and investment management firms with $2.9 trillion in assets under supervision — has been directed by the Office of the Comptroller of the Currency to remediate critical deficiencies in its Security Information and Event Management infrastructure within 12 months. The OCC's annual cybersecurity examination identified that Goldman's aging ArcSight SIEM platform — deployed on-premises 9 years ago — has significant gaps in log source coverage, correlation rule effectiveness, and incident detection timelines that fall below regulatory expectations for a Global Systemically Important Bank. The remediation plan, approved by Goldman's Board Risk Committee, calls for a full migration from ArcSight to Splunk Cloud at a total programme cost of $14.5M. The business case is not optional — the OCC finding carries a Matters Requiring Attention classification, one step below a formal enforcement action. Failure to remediate within the prescribed timeline risks escalation to a Consent Order, which would be publicly disclosed and trigger additional regulatory scrutiny from the SEC, FINRA, and the Federal Reserve. The project appears well-defined: migrate 800 documented log sources to Splunk Cloud, rebuild SOC dashboards and alert workflows, and establish regulatory compliance reporting that meets OCC examination standards. Accenture Security has been engaged as the systems integrator, with Splunk Professional Services providing cloud architecture and onboarding support. But beneath the documented surface lies 9 years of organic SOC growth — undocumented correlation rules built by individual analysts, trading surveillance log feeds that bypass the official SIEM infrastructure, custom parsers for proprietary trading systems, and a tangled web of integrations with CrowdStrike, Palo Alto, ServiceNow, and Goldman's proprietary security tooling that no single person fully understands.

What you'll do as the project manager

  • Migrate all documented log sources (800+) from ArcSight to Splunk Cloud within the OCC-mandated 12-month remediation timeline, achieving full log ingestion parity
  • Rebuild SOC operational capabilities in Splunk Enterprise Security — including correlation rules, alert triage workflows, investigation dashboards, and incident response playbooks — with zero degradation in mean time to detect (MTTD) or mean time to respond (MTTR)
  • Establish regulatory compliance reporting in Splunk that satisfies OCC cybersecurity examination standards, SEC Rule 10 cybersecurity incident disclosure requirements, and FINRA trade surveillance obligations
  • Integrate Splunk Cloud with Goldman's security ecosystem — CrowdStrike Falcon, Palo Alto firewalls, ServiceNow SecOps, Tanium, Akamai WAF, and Zscaler cloud security — maintaining automated threat detection and response workflows
  • Complete SOC analyst training and operational cutover with measured competency, ensuring the 24/7 SOC can operate exclusively on Splunk within 30 days of go-live

Project management skills you'll build

Stakeholder management & communication
Budget and schedule control
Risk identification & mitigation
Scope management & change control
PMO governance & phase-gate reviews
SIEM Platform Migration delivery in Financial Services — Investment Banking

The challenges you'll navigate

  • Log source coverage gap: The OCC finding specifically cited inadequate log coverage. If the migration reveals that actual log sources exceed the documented 800 — particularly in trading surveillance and proprietary systems — the migration scope, timeline, and budget will expand significantly
  • SOC operational disruption: The 24/7 SOC is Goldman's front line against cyber threats. Any degradation in detection or response during migration creates both security risk and regulatory exposure. Dual-platform operation adds complexity and analyst fatigue
  • Regulatory timeline pressure: The 12-month OCC remediation deadline is non-negotiable. Unlike a discretionary technology project, this deadline cannot be extended through internal governance — only the OCC can grant an extension, and requesting one signals weakness
  • Trading surveillance complexity: Goldman's trading surveillance infrastructure feeds both the SIEM and FINRA's trade monitoring requirements. Migrating these log sources touches regulatory obligations that exist independently of the SIEM project
  • Vendor dependency on undocumented complexity: Accenture's SOW was scoped against the documented environment. Custom correlation rules, proprietary parsers, and undocumented integrations are explicitly out of scope — creating a commercial gap that will surface during execution

Technology & stakeholders

Splunk Cloud / ArcSight (Legacy) / CrowdStrike Falcon / Palo Alto Networks / Cisco ASA & Catalyst / AWS (GovCloud) / ServiceNow SecOps / Tanium / Akamai / ZscalerSplunk Cloud (Enterprise Security premium app)Splunk Search Processing Language (SPL)ArcSight ESM (legacy SIEM — correlation rules, active channels, dashboards)ArcSight SmartConnectors (log collection agents)CrowdStrike Falcon (EDR integration)Palo Alto Networks (NGFW — PAN-OS syslog integration)Cisco ASA & Catalyst (network device logging)AWS GovCloud (Splunk Cloud infrastructure)ServiceNow Security Operations (incident management integration)Tanium (endpoint visibility and response)Akamai WAF/CDN (web application security logging)Zscaler (cloud security / CASB logging)STIX/TAXII (threat intelligence feed integration)Syslog / CEF / LEEF (log transport protocols)Goldman Sachs Marquee (proprietary trading platform telemetry)

You'll manage 6 stakeholders, including Rajesh Nair (Managing Director, Chief Information Security Officer), Katherine Aldridge (VP, Technology Risk & Governance), David Park (VP, Security Engineering), and more.

What you'll walk away with

A verified, shareable record of a completed enterprise project — plus the PMO deliverables you produced along the way (charter, project plan, SteerCo deck, closure document). It's real, demonstrable project management experience you can put on your resume and speak to in interviews.

Frequently asked questions

Do I need project management experience to start?

No. This simulation is built for aspiring and practicing project managers alike — you learn by doing. You make real decisions and get feedback, with no PMP or prior PM job required.

How long does this simulation take?

It runs over 27 days, roughly 32 minutes per day, covering the full project lifecycle from initiation to closure.

What will I learn?

You practice the core of project management — stakeholder management, budget and schedule control, risk, scope, and PMO governance — in the context of siem platform migration in financial services — investment banking.

Is this based on the real Goldman Sachs?

It's a realistic scenario inspired by Goldman Sachs and the Financial Services — Investment Banking sector. Details and names are fictionalized for training — it's a simulation, not a record of any actual project.

What do I get at the end?

A verified project completion plus the PMO deliverables you produced (charter, plan, SteerCo deck, closure) — proof of hands-on experience you can show employers.

Related simulations

Ready to gain real PM experience?

Run Goldman Sachs's siem platform migration and 48+ more enterprise simulations.

See plans & start