Northern Trust
Financial Services
Lead,TechnologyandCyberRiskManagement
Neural analysis suggests this role is
optimal for Lead candidates.
“Lead, Technology and Cyber Risk Management at Northern Trust. Skills: Technology risk management, Cybersecurity risk management, Information security. Develop and maintain technology and cybersecurity risk metrics. Develop and maintain risk assessments”
Industry & Context.
Assess complex data; Formulate sound risk decisions; Well-justified risk decisions
What They're Looking For.
Must Have
CISA, CISM, CRISC, CISSP, or equivalent certification, Bachelor's degree in Accounting, Finance, Information Technology, MIS, Computer Science, or related discipline, Experience assessing IT processes including information security, system development and change management, computer operations, and data protection, Working knowledge of Financial Services regulatory requirements, Hands-on experience applying industry frameworks such as COBIT 5, ISO 27001/27002, and NIST 800-53, Analytical skills with the ability to assess complex data, Proven ability to manage multiple priorities with urgency and attention to detail, Excellent written and verbal communication skills, Ability to produce clear, well-structured documentation and reports, Ability to work effectively both independently and within global, multi-national teams
Nice to Have
Advanced degree in an IT-related field is desirable, Experience creating metrics and reporting using tools such as Power BI and PowerPoint, Exposure to one or more information security disciplines, Professional presence and ability to build working relationships
What You'll Do.
Develop and maintain technology and cybersecurity risk metrics
Develop and maintain risk assessments
Manage preparation and delivery of materials for engagements
Identify and assess risks associated with internal technologies
Identify and assess risks associated with externally hosted
Define requirements for information security programs
Define requirements for technology risk management programs
Define execution plans for information security programs
Define execution plans for technology risk management programs
Ensure risk management programs align with regulations
Ensure risk management programs align with industry standards
Ensure risk management programs align with compliance requirements
Communicate security policies and requirements clearly
measurable metrics for risk management programs
Review and assess technology controls
Review and assess security controls
Drive risk reduction through defined risk treatment
Drive risk reduction through remediation processes
Document risk findings
Report risk findings to management
Document remediation plans
Track remediation plans
Report remediation plans to management
Collaborate with Information Security teams
Collaborate with Privacy teams
Collaborate with Enterprise Risk teams
Evaluate risk advice on strategic business initiatives
Evaluate risk advice on strategic technology initiatives
Provide risk advice on strategic business initiatives
Provide risk advice on strategic technology initiatives
Participate in cybersecurity incident response activities
Stay current on industry trends
Stay current on emerging threats
Stay current on emerging technologies
Stay current on regulatory developments
Advise management on potential business impact
Advise management on potential financial impact
How You'll Work.
Team & Collaboration
Global, multi-national teams; Information Security teams; Privacy teams; Enterprise Risk teams
Communication Scope
Executive presentations; Written communication; Verbal communication; Clear documentation; Structured reports
Full Job Description
**_About Northern Trust:_** Northern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution that has been in continuous operation since 1889. Northern Trust is proud to provide innovative financial services and guidance to the world’s most successful individuals, families, and institutions by remaining true to our enduring principles of service, expertise, and integrity. With more than 130 years of financial experience and over 22,000 partners, we serve the world’s most sophisticated clients using leading technology and exceptional service. **_The Role_** This role is an individual contributor position responsible for the execution of activities supporting IT and Cybersecurity Risk Management, including regulatory interactions, IT risk and control assessments, information security initiatives, and management reporting. The role plays a key part in the identification, assessment, management, and reporting of technology and information security risk, with direct responsibility for delivering work across one or more core practice areas within the Information Security and Technology Risk Management Program. The individual will work closely with peers and management and will contribute to strategic IT Risk and Information Security initiatives. **_The key responsibilities of the role include;_** * Develop and maintain technology and cybersecurity risk metrics and assessments to inform the firm of its risk posture * Manage preparation and delivery of materials for key engagements, including regulatory interactions, audit examinations, and senior management meetings * Identify and assess risks associated with internal technologies and externally hosted systems * Define requirements and execution plans for information security and technology risk management programs * Ensure risk management programs align with applicable regulations, industry standards, and compliance requirements * Communicate security policies and requirements clearly t
Applying for this Lead, Technology and Cyber Risk Management role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Workday
- Workday has a multi-step form — save your progress after every section.
- "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
- Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
- Job requisition numbers are useful when following up with HR by email.
ANONYMOUS · UNFILTERED
What do employees actually say about Northern Trust?
Real rants from real employees. Read before you apply.