Principal, Cyber Security - Governance, Risk and Controls (GRC)
Northern TrustAbout the role
About Northern Trust:
Northern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution that has been in continuous operation since 1889.
Northern Trust is proud to provide innovative financial services and guidance to the world’s most successful individuals, families, and institutions by remaining true to our enduring principles of service, expertise, and integrity. With more than 130 years of financial experience and over 22,000 partners, we serve the world’s most sophisticated clients using leading technology and exceptional service.
Principal Responsibilities/Requirements:
Primary candidate has techno-functional knowledge and experience in Information Security domain involving undertakings and projects focusing on data security activities. This includes prior contributions to the strategic direction of data security programs, working knowledge of, and experience with the development and enterprise-wide implementation of end-to-end processes, as well as data security best practices.
Develop, socialize, maintain, and interpret complex data security governance elements (e.g., policy, standard, TOM, procedures, and business continuity plans) that define data security requirements.
Develop, implement, and execute governance and monitoring processes as required per internal/external standards and regulations (e.g.: FFIEC, GDPR, etc).
Responsible for execution of Data Protection Risk & Controls Self Assessments (RCSA) and the development of Process Risk & Controls Inventories (PRCI).
Responsible for monitoring KRI/KPI and conducting escalation activities for noncompliance to data protection policies, standards, and procedures to various levels of leadership
Contributes to the optimization, execution, and maintenance of a data security program elements, especially those involving business processes, repeatable methods, automation, and measurements needed for a viable risk-based data security program (e.g.: KRI/KPI metrics).
Works with information security management frameworks (i.e., ISO 2700X, NIST CSF, SANS Top 20 Critical Security Controls, etc.)
Responds both verbally, and in writing, to complex inquiries and new periodic exams from both internal partners (e.g., legal, compliance, audit, risk) and external partners (e.g., regulators, external auditors, third-parties). This also includes prior experience in optimization and execution methods to improve future responses to such inquiries, as well as prior experience providing peer-review of such responses.
Responsible for the management and tracking of internal and external issues or areas of concerns related to the Data Protection program (e.g.: audit responses, etc)
Responsible for managing the content on the Enterprise-wide knowledge and collaboration workspace specifically for the Data Protection program.
Minimum:
Bachelor’s degree or equivalent experience
Experience with Data Governance teams at both the Enterprise and various business levels level
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s