About Northern Trust
As a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world’s most successful individuals, families, corporations and institutions.
Since 1889, we have aligned our efforts with our three guiding Principles That Endure: Service, Expertise, and Integrity. Together, they reflect the three cornerstones of business conduct which we strive to instill in our employees, whom we call partners, and to provide to our clients and the communities we serve worldwide.
With more than 135 years of financial experience and over 24,000 partners, we serve the world’s most sophisticated clients using leading technology and exceptional service.
Summary
The Northern Trust Technology Risk and Control function enables Global Information Technology to operate with a strong and sustainable first line of defense, fostering a deeply embedded control-aware culture, delivering compliant and secure technology capabilities, protecting clients, and meeting global regulatory expectations.
The Senior Lead, Technology Risk and Control role is responsible for leading the Technology Risk Treatment practice, which is a key component of the Technology Risk Treatment and Issue Management program. Specifically, this role is accountable for ensuring the appropriate use and effective operation of the firm’s risk acceptance process for the Technology organization. This includes providing ongoing direction, guidance, and challenge to a wide range of constituents across all Technology towers, facilitating and producing high-quality risk assessments, operating governance forums with senior leadership to review and challenge assessments, and maintaining and monitoring the risk acceptance inventory.
As a member of the Technology Risk & Control team, this role acts as an advisor to technology, risk, and executive stakeholders, drives strategic initiatives, and plays a critical role in shaping the firm’s overall technology risk management posture globally.
Responsibilities
- Own and drive the Technology Risk Treatment process, providing trusted leadership and guidance, working with control officers, control owners, and stakeholders to identify, assess, document, and track enterprise technology risk acceptances.
- Provide effective guidance and challenge to a wide array of Technology and business partners who seek risk acceptances to ensure remediation options are fully explored.
- Thoroughly analyze the impact, likelihood, and mitigating controls associated with gaps, and author clear, well-supported risk assessments, severity ratings, and recommended risk treatment options for review by senior leadership.
- Define and produce metrics and KPIs/KRIs that assist in program operations and management visibility of performance and ongoing risks.
- Lead risk treatment governance forums, ensuring materials are accurate, discussions are well-documented, and follow-up actions are clearly tracked to resolution.
- Prepare committee decks, meeting artifacts, and supporting documentation; assist with coordination and follow-through on meeting outcomes and action items.
- Provide guidance, coaching, and subject matter leadership to team members, setting expectations for quality, consistency, and professional development.
- Identify, prioritize, and lead continuous improvement and maturity initiatives across team processes, documentation, and knowledge management, ensuring sustained enhancements are embedded.
- Collaborate with peers across Technology, Risk (2LOD), and Audit (3LOD) functions, sharing knowledge and best practices to support team effectiveness and consistency.
- Actively influence decision making and behaviors across technology teams to reduce risk exposure and strengthen the overall technology risk management culture.
Knowledge and Skills
- Advanced, broad-based expertise in technology and cybersecurity risks and controls, with the ability to apply judgment across complex risk areas including resiliency, information security, SDLC, ITSM, operations, governance, SaaS, cloud, AI, and emerging technologies.
- Highly effective written and verbal communication skills, with the ability to articulate complex risk and control concepts clearly and concisely to both technical and non-technical stakeholders.
- Demonstrated capability to develop, review, and deliver management level materials, including summaries, analyses, and recommendations for governance forums and senior stakeholders.
- Hands on experience with enterprise GRC/IRM platforms (e.g., ServiceNow), including control hierarchy design, data quality considerations, workflow integration, and reporting.
- Self-directed and outcome oriented, capable of independently driving initiatives, prioritizing competing demands, and proposing well-reasoned paths forward.
- Strong project and program management skills, including planning, coordination, execution tracking, and issue escalation across cross functional initiatives.
- Proven collaboration and relationship management capabilities, including effective engagement with senior managers and leaders across technology, risk, and control functions.
- Recognized thought contributor with a track record of identifying process improvements, shaping solutions, and driving enhancements through implementation.
Experience
- 10-12+ years of experience in technology risk management, controls, audit, or related fields with transferable skills
- Bachelor’s degree in technology, cybersecurity, or related field
- Prior experience in financial services preferred
- Relevant technology or security certifications (e.g., CISSP, CRISC, CISM, CISA, etc.) preferred
Salary Range:
$95,600 - 162,400 USD
Salary range is a good faith estimate of base pay. Northern Trust provides a comprehensive benefits package including retirement benefits (401k and pension), health and welfare benefits (medical, dental, vision, spending accounts and disability), paid time off, parental and caregiver leave, life & accident insurance, and other voluntary and well-being benefits. Northern Trust also provides a discretionary bonus program that may include an equity component.
Work Authorization
Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. Northern Trust will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa).
Working with Us
As a Northern Trust partner, you will be part of a flexible and collaborative work culture, which has a strong history of financial strength and stability. Movement within the organization is encouraged, senior leaders are accessible, and you can take pride in working for a company committed to an inclusive workplace and assisting the communities we serve.
Philanthropy is deeply rooted in Northern Trust’s history and is an essential element of our culture. Employees around the world give their time and talent to work for the greater good of their communities.
Reasonable Accommodation
Northern Trust is committed to working with and providing adjustments to individuals with health conditions and disabilities. If you need a reasonable accommodation for any part of the employment process, please email our HR Service Center at [email protected], or alternatively you can discuss your individual requirements with the recruiter you are working with.
Seen 5 hours ago · Northern Trust postings close after a median of 30 days.
Original posting on Northern Trust's site ↗
Posting text belongs to the employer. Removal requests: contact us.
Nearby
Live postings like this one
Same employer first, then the same role elsewhere.
- 5h ago
- 5h ago
- 17h ago
- 17h ago
- 1d ago
- 1d ago
- 1d ago
- 1d ago
One job at a time
One posting. One CV. $25.
Pick the job you actually want and we write for it.