Jobs and Careers
NO

Specialist - IT Governance and Testing

Northern Trust
United Statesfull_timeVerifiedPosted 23 Jan 2025
💰 $162,400/yr($95,600/yr$162,400/yr)

About the role

About Northern Trust:

Northern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution that has been in continuous operation since 1889.  

Northern Trust is proud to provide innovative financial services and guidance to the world’s most successful individuals, families, and institutions by remaining true to our enduring principles of service, expertise, and integrity. With more than 130 years of financial experience and over 22,000 partners, we serve the world’s most sophisticated clients using leading technology and exceptional service.

Northern Trust is seeking a seasoned IT governance and control professional to support the IT SOX, SOC and CCAR compliance effort.  The Specialist will assist with establishing, maintaining, and enhancing IT compliance frameworks, risk management strategies, testing methodology and governance policies. A successful candidate will have expertise in aligning IT processes with organizational goals, ensuring regulatory compliance and managing enterprise IT risks. The ideal candidate will collaborate with cross functional teams to identify and assess risks, enhance controls, monitor compliance efforts, implement best practices and drive efficiency in testing methodologies, and support audits.

Major Duties:

  • Maintaining, and enhancing IT compliance frameworks, risk management strategies and IT governance policies. Identify risks associated with the use of technology for the business processes and ITGC.
  • Evaluate IT processes to ensure compliance with regulatory standards (SOX, SOC and CCAR).
  • Conduct periodic reviews and walkthrough exercise of IT controls for adherence to the standards.
  • Document IT controls narratives/workflows to align with regulatory requirements.
  • Support the internal testing team through IT control testing escalations, produce meaningful, measured metrics in regard to IT control testing for the compliance programs.
  • Review and assess controls through established frameworks.
  • Support training and IT control awareness activities for stakeholders and control owners.
  • Work with teams and controls owners/stakeholders to determine action plans to remediate identified risks and control exceptions.
  • Document and report findings and assist management with remediation efforts.
  • Collaborate with Information Security, Privacy, and Risk Management teams to provide continuous improvement to Technology controls and compliance frameworks.
  • Maintain accurate documentation of test result, findings, and remediation efforts and maintaining accurate date in the compliance tools.
  • Assist to facilitate the SOX and SOC reports audits by preparing test matrix, determine IT scope and centralized PBC.
  • Track and monitor audit progress and generate matric and reports for leadership and stakeholders.


Knowledge:

  • Understanding of information security, IT audit and IT risk management principles.
  • Understanding of assessments of IT related processes such as system and information security, system development and change management, computer operations and data protection.
  • Understanding of Financial Services industry regulations, specifically those set forth in the Federal Financial Institutional Examination Council (FFIEC) handbooks and other country specific regulatory authorities.
  • Demonstrated ability to work well in both an individual contributor and team capacity, in particular multi-national teams.
  • Strong written and verbal communication skills. Able to prepare clearly written, organized documents, reports and communications that demonstrate proper justification and support for any conclusions and assessment results and contain correct grammar, punctuation and spelling.
  • Able to interact in a professional manner and develop relationships with individuals and teams at any level in Northern Trust or third-party service provider.


Experience:

  • 8+ years of IT audit or IT risk management experience.
  • Bachelor’s degree in accounting, Finance, Information Technology, Management Information Systems, Computer Science or a related discipline.
  • Related Industry qualification (e.g. audit Cert) is preferred not required.
  • Strong understanding of IT infrastructure, applications, and systems e.g. Operating system, databases, network, compliance tools. Experience with GRC Governance Risk and Control tools. Proficient in control testing methodologies and tools
  • Excellent analytical and critical thinking skills. Strong verbal and written communication skills. Ability to collaborate effectively with technical and non-technical team's stakeholders.


#LI-Hybrid

S

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Northern Trust

View company profile →