Jobs and Careers
NO

Sr. Lead, Cyber Security, Data Protection - Risk & Remediation

Northern Trust
United Statesfull_timeVerifiedPosted 6 Mar 2025
💰 $194,700/yr($114,500/yr$194,700/yr)

About the role

About Northern Trust:

Northern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution that has been in continuous operation since 1889.  

Northern Trust is proud to provide innovative financial services and guidance to the world’s most successful individuals, families, and institutions by remaining true to our enduring principles of service, expertise, and integrity. With more than 130 years of financial experience and over 22,000 partners, we serve the world’s most sophisticated clients using leading technology and exceptional service.

This role is part of the Information Security & Data Protection organization, aligning to Business Information Security Officer (BISO) for Asset Servicing and Chief Operating Officer; this role will report to the BISO who report to the Global Chief Information Security Officer (CISO). We operate within a complex landscape driven by client expectations and the diverse needs that comes with operating in countries across the globe.

The role is for a Data Protection - Risk & Remediation accountable for driving control compliance with policies, standards and targeting prioritized applications/solutions/architectures to reduce risk.

The successfully candidate will work closely with Business Unit (BU) counterparts.  He/she will marry technical knowledge and experience in Information Security domains involving application security and security with business requirements for communicating with clients and other counterparties.

 Job responsibilities:

  • Identify and enable solutions that meet end-user expectations relative to performance, usability and security for the Data Protection Engineering and Architecture function.  Determine operational feasibility by evaluating, analyzing, problem definition, requirements, solution development, and proposing solutions.
  • Represent Information Security with BU stakeholders as a trusted advisor, finding pragmatic and cost-effective security solutions that efficiently support customer needs.  Collaborate with Technology, Info Sec, Risk, Enterprise Architecture and BU organizations as needed.  Be familiar with BU leadership, operations and priorities.
  • Offer guidance, best practices, and support across businesses to identify, assess, control and reduce data protection risk.  Drive awareness and understanding of the technology risk and controls framework and challenges to compliance with it.
  • Develop and administer the solutions and detective controls that meet system expectations relative to scalability, performance, fault tolerance, usability, and data integrity.  Maintain specialist knowledge in assigned security processes, governance, systems and/or frameworks.
  • Review documentation, processes or procedures, and recommends where automation or improvements can be implemented.
  • Operate independently and maintain in-depth knowledge of business unit/function; accomplish engineering and organization mission by completing related results as needed.
  • Lead risk reviews and assessments, identifying threats, communicating with BU and Application teams and stakeholders to define risk treatment activities.
  • Act as an InfoSec subject matter expert, primarily focused on data protection and application security across the Bank’s core technology within platforms.

Key Requirements;

  • Data Protection Risk & Remediation Consultant candidate preferably with 7-10 years Security, Risk and/or Technology experience across a broad range of architectures. Security Architecture experience with hands on experience designing and delivering technology solutions.
  • Relevant business experience/qualifications/knowledge: Expertise established in assessing and articulating technology and/or security risk in the context of various other operational risks and challenges facing the organization.  Ability to quickly identify, learn and assess BU requirements vis-à-vis security and risk standards.
  • Successful candidate is likely to have held roles such as Security Risk Consultant, Risk Consultant, Information or IT Security Risk Manager, IT Audit Manager, IT Incident Manager or Security Analyst.
  • Ability to clearly articulate and document security risks and requirements so that they are accurate, auditable and understandable. Extensive experience with risk frameworks, cloud technology including, hybrid environments, security from the start design (SSDLC).
  • Preferred technical qualifications such as CRISC, CISM, CISA, CISSP, AWS Certified Security etc.  Familiarity with Data Loss Prevent (DLP) solutions not required but strongly recommended.
  • Solid, practical and demonstrable experience of information security (technical and non-technical aspects), ideally with an understanding o

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Northern Trust

View company profile →