Sr. Lead – IAM (Identity and Access Management)
Northern TrustAbout the role
About Northern Trust:
Northern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution that has been in continuous operation since 1889.
Northern Trust is proud to provide innovative financial services and guidance to the world’s most successful individuals, families, and institutions by remaining true to our enduring principles of service, expertise, and integrity. With more than 130 years of financial experience and over 22,000 partners, we serve the world’s most sophisticated clients using leading technology and exceptional service.
The role will ensure formulation and execution of strategic and tactical solutions related to 1st line of defense (1LOD) IAM practices. The role will also be responsible for working collaboratively with business unit (BU) partners to enable and execute identity governance policy, standards and control adherence and serve as principal partner in strengthening and maintaining productive alliances with 2nd and 3rd line of defense challenge teams. This position will collaborate extensively with business, technology, risk and other corporate teams to establish and strengthen adoption of identity practices, standards and controls. As an IAM leader, the selected candidate will partner with IAM architecture, engineering, operations and program teams to ensure that identity governance and administration strategy and roadmaps are in alignment with other business needs and priorities.
This role is part of the Information Security organization, aligning to Business Information Security Officer (BISO) for Asset Servicing and Chief Operating Officer; this role will report to the BISO who reports to the Global Chief Information Security Officer (CISO). We operate within a complex landscape driven by client expectations and the diverse needs that comes with operating in countries across the globe.
The successfully candidate will work very closely with Business Unit (BU) counterparts. He/she will marry technical knowledge and experience in Information Security domains involving application security and security with business requirements for communicating with clients and other counterparties.
Job responsibilities:
- Identify and enable IAM solutions that meet BU and InfoSec end-user expectations relative to performance, usability and security for IAM standards and procedures. Determine operational feasibility by evaluating, analyzing, problem definition, requirements, solution development, and proposing solutions.
- Represent Information Security with BU stakeholders as a trusted advisor, finding pragmatic and cost-effective security solutions that efficiently support customer needs. Collaborate with Technology, Info Sec, Risk, Enterprise Architecture and BU organizations as needed. Be familiar with BU leadership, operations and priorities.
- Represent the IAM organization’s identity lifecycle capabilities, Privileged Access Management (PAM), Authentication, etc to the business units as well as to technology, risk and audit teams. Balance between strategic operational execution and development, and execution of tactical InfoSec and business function activities
- Offer guidance, best practices, and support across businesses to identify, assess, control and reduce IAM risk. Drive awareness and understanding within BU of the technology risk and controls framework and challenges to compliance with it. Enforce IAM Tower standards and controls across NT, whether applications and platforms are centrally or de-centrally managed
- Aid in developing the solutions and controls that meet system expectations relative to scalability, performance, fault tolerance, usability, and data integrity. Maintain specialist knowledge in assigned security processes, governance, systems and/or frameworks. May be responsible for performing BU-level training of access management principles, practices, standards and controls. With BU, respond to IAM-related audit and regulatory inquiries in partnership with other IAM, IT and Risk leadership teams.
- Review documentation, processes or procedures, and recommends where automation or improvements can be implemented. Lead risk reviews and assessments, identifying threats, communicating with BU and IAM teams and stakeholders to define risk treatment activities.
- Act as an InfoSec subject matter expert, primarily focused on IAM and application security across the Bank’s core technology within platforms.
QUALIFICATIONS
- Preferably with 7-10 years Security, Risk and/or Technology experience across a broad range of architectures. Broad understanding of identity and access management, and knowledge in identity governance and administration. As an IAM subject area expert, provides comprehensive, in-depth consulting and leadership to te
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s