Head of Identity & Access Management (IAM) Governance, Risk & Operations
Northern TrustAbout the role
About Northern Trust:
Northern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution that has been in continuous operation since 1889.
Northern Trust is proud to provide innovative financial services and guidance to the world’s most successful individuals, families, and institutions by remaining true to our enduring principles of service, expertise, and integrity. With more than 130 years of financial experience and over 22,000 partners, we serve the world’s most sophisticated clients using leading technology and exceptional service.
Overview
We are seeking a strategic and execution-focused Head of IAM Governance, Risk & Operations to lead and modernize Identity & Access Management Governance, Risk and Operations program.
This role extends beyond traditional IAM to include next-generation identity challenges, including AI agents, non-human identities, and autonomous systems. You will define how identity is governed in an era where agentic AI act with delegated authority.
Grounded in balancing power, control, and alignment—you will ensure identity systems are secure by design, governed with intent, and constrained by policy, preventing uncontrolled privilege expansion across both human and machine actors.
Key Responsibilities
IAM Governance & Strategy
- Define and implement a modern IAM governance framework spanning:
- Human identities
- Machine/service identities / AI agents and autonomous actors
- Establish policies and standards based on global regulations
- Lead governance forums to ensure accountability across technology, security, and business domains
- Partner with data governance to align identity controls with data sensitivity and usage
Agentic AI Identity & Governance
- Define and operationalize identity frameworks for agentic AI, including:
- Unique identity issuance for AI agents
- Scoped permissions and task-based entitlements
- Lifecycle management (creation, delegation, revocation, termination)
- Establish policy guardrails for autonomous decision-making systems, ensuring:
- Traceability of actions
- Attribution of decisions
- Controlled delegation of authority
- Implement controls to prevent:
- Privilege escalation by AI agents
- Unauthorized data access or propagation
- “Identity sprawl” across machine and AI ecosystems
- Partner with AI/ML teams to integrate IAM into AI pipelines, orchestration layers, and model execution environments
Risk & Compliance
- Own IAM risk identification across human and non-human identities.
- Define risk models for autonomous access, delegated authority, and machine-to-machine interactions
- Ensure compliance with evolving regulatory expectations related to AI governance and identity accountability
- Lead audit readiness for IAM and AI identity controls
- Develop KPIs/KRIs for:
- Identity risk exposure
- Access anomalies (human vs. agentic)
- Policy violations and drift
Operations & Execution
- Oversee IAM operations across:
- Joiner/Mover/Leaver (JML) lifecycle
- Access certifications and continuous attestation
- Privileged Access Management (PAM)
- Authentication and authorization services
- Implement access controls (adaptive, context-aware, risk-based)
- Ensure operational scalability as identity volumes grow exponentially with AI adoption
Leadership & Stakeholder Engagement
- Build and lead a forward-looking IAM organization capable of supporting AI-era identity challenges
- Partner with:
- Risk<
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s