Principal, GRC Cyber Risk Management
Northern TrustAbout the role
About Northern Trust
As a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world’s most successful individuals, families, corporations and institutions.
Since 1889, we have aligned our efforts with our three guiding Principles That Endure: Service, Expertise, and Integrity. Together, they reflect the three cornerstones of business conduct which we strive to instill in our employees, whom we call partners, and to provide to our clients and the communities we serve worldwide.
With more than 135 years of financial experience and over 24,000 partners, we serve the world’s most sophisticated clients using leading technology and exceptional service.
Role/ Department:
This role sits within Northern Trust’s Cybersecurity Governance, Risk and Compliance (GRC) organization, an integral part of the strategic evolution of cyber risk management capabilities across the enterprise.
The Cyber Risk Principal will partner with peers to drive the modernization of cyber risk identification, intelligence integration, assessment methodologies, and executive risk reporting. The role requires a forward-looking team player who understands how cybersecurity, cyber threat intelligence, data analytics, automation, and artificial intelligence are reshaping enterprise risk management within global financial institutions.
The ideal candidate combines strong cyber risk management expertise with the ability to leverage data-driven insights, threat intelligence, emerging technologies, and AI-enabled capabilities to improve risk visibility, prioritization, and decision-making.
The key responsibilities of the role include:
Lead the identification, assessment, prioritization, and reporting of cyber risks across the enterprise
Drive the evolution of cyber risk management toward data driven decision making by integrating cyber threat intelligence, attack surface insights, vulnerability trends, and control effectiveness metrics into enterprise cyber risk reporting
Conduct cyber risk assessments, thematic reviews, and cyber maturity assessments aligned to industry frameworks and regulatory expectations
Develop forward-looking cyber risk reporting that provides actionable insights to executive leadership, risk committees, and regulators
Partner with cyber domain experts (e.g., security operations, architecture) to improve risk reduction outcomes
Enhance cyber risk intelligence capabilities through analytics, automation, and AI-enabled processes
Drive continuous improvement in cyber risk methodologies, governance processes, and reporting capabilities
Translate highly technical cyber risks into clear business impact narratives and strategic recommendations
Evaluate emerging threats, including e.g., AI capabilities to determine enterprise cyber risk implications
Contribute to the development of risk metrics, KRIs, KCIs, maturity indicators, and predictive cyber risk analytics
Collaborate across Lines of Defense to strengthen enterprise cyber resilience and operational risk visibility
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s