Bachelor’s degree in computer science or a related discipline and at least ten or more years of experience in the field of Technology Security or an equivalent combination of education and work experience
Relevant certification (e.g., CISA, CRISC, CISM, CISSP) is a plus
Proven knowledge in domains such as: Information Security Governance and Risk Management, Access Control, Vulnerability and Penetration, Network Security, Application Security, Cryptography, Security Architecture and Design, Operations Security, Business Continuity and Disaster Recovery Planning, Legal, Regulations, Investigations and Compliance, Physical and Environmental Security, Cloud Security
Knowledge of regulations related to banking and compliance
Well versed with contract language, analysis, and negotiation process
Excellent written and verbal communication skills
Able to converse and develop business relationships with individuals and teams at any level within Northern Trust
Knowledge of IT Security Domains/Frameworks (e.g., NIST, ISO27001)
Knowledge of Compliance regulations
Understanding of IT Audit process
In-depth understanding of information security, risk assessments, security risk management principles
Principle understanding of Technology controls relating to Application and system vulnerabilities
Advanced experience with MS Office, SharePoint, and Reporting tools
Ability to develop visual representations of processes and risks to support executive updates
Report writing skills
Ability to work well in both an individual contributor and team capacity
Ability to rapidly and effectively adapt to a highly dynamic and fast-paced work environment
Responsibilities
Perform information security risk assessment processes for new and existing Northern Trust’s third parties business partners
Perform assessment of IT controls operation, identifying gaps, risks, and areas for improvement
Review master services contracts of third parties to identify information technology and security related clauses
Work with procurement teams to formulate/renew contracts as per the information security team guidelines
Document and report to management all findings from risk assessment processes
Collaborate with internal stakeholders & functional teams to ensure that all identified risks within each third party are assigned to business owners and tracked for timely closure
Interact in a professional manner and develop relationships with individuals and teams at any level in Northern Trust