
Principal – Cyber Security, Risk and Controls
Northern Trust
full-time
Posted on:
Location Type: Hybrid
Location: Chicago • Illinois • United States
Visit company websiteExplore more
Salary
💰 $114,700 - $194,900 per year
Job Level
Tech Stack
About the role
- Lead technology risk and control assessments across a broad range of domains, including application development, infrastructure, cloud, data, identity and access management, resiliency, third‑party technology services, change management, and technology operations
- Evaluate technology risks throughout system lifecycles, including design, build, deployment, operation, and decommissioning, ensuring alignment with enterprise risk appetite and regulatory expectations
- Provide subject‑matter expertise to support the development, maintenance, and alignment of technology risk, control, and governance standards with industry frameworks and internal policies
- Partner with technology teams to assess control design and operating effectiveness, and to drive timely remediation of technology risk findings from audits, regulatory exams, risk assessments, and internal reviews
- Analyze the impact of technology risks on critical business services, key processes, and customer outcomes , including availability, integrity, resilience, and regulatory compliance
- Participate in major incident, resiliency, and control‑failure events , providing technology risk guidance and contributing to root‑cause analysis and control enhancements
- Support technology risk training, awareness, and advisory activities to strengthen risk ownership and decision‑making across engineering, operations, and delivery teams
- Influence behaviors, resolve conflicts, and foster strong collaboration between technology, risk, and business stakeholders to promote a mature and accountable technology risk management culture
Requirements
- 10+ years of experience in technology, risk management, audit, or control functions covering multiple technology domains such as application development, infrastructure, cloud, data, identity and access management, operations, resiliency, or third‑party technology risk
- Strong experience performing technology risk assessments using recognized risk management frameworks (e.g., NIST, COBIT, ISO, or equivalent)
- Demonstrated ability to assess risk impact, control effectiveness, and residual risk, and to translate technical issues into business‑relevant risk insights
- Proven consultative, analytical, and communication skills with experience engaging senior technology and risk leaders
- Industry certifications (risk, technology, audit, or security) preferred but not required
- Bachelor’s degree in Computer Science, Information Systems, Engineering, or a related discipline, or an equivalent combination of education and experience supporting complex technology environments
Benefits
- retirement benefits (401k and pension)
- health and welfare benefits (medical, dental, vision, spending accounts and disability)
- paid time off
- parental and caregiver leave
- life & accident insurance
- discretionary bonus program that may include an equity component
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
technology risk assessmentscontrol designoperating effectivenessrisk management frameworksNISTCOBITISOrisk impact assessmentcontrol effectiveness assessmentresidual risk assessment
Soft Skills
consultative skillsanalytical skillscommunication skillsconflict resolutioncollaborationinfluencerisk ownershipdecision-makingstakeholder engagementtraining and awareness
Certifications
risk management certificationtechnology certificationaudit certificationsecurity certification