Bachelor’s degree in computer science or a related discipline with relevant experience in the field of Technology Security
Professional certifications (such as CISA, CRISC, CISM, CISSP or similar) is a plus
Proven knowledge in domains including: Information Security Governance and Risk Management, Access Control, Vulnerability and Penetration, Network Security, Application Security, Cryptography, Security Architecture and Design, Operations Security, Business Continuity and Disaster Recovery Planning, Legal, Regulations, Investigations and Compliance, Physical and Environmental Security, Cloud Security
Knowledge of risk treatment and issues management functions and industry tools
Knowledge of security architecture patterns, requirements, and security controls (e.g., data protection, access controls, network segmentation, AI)
Knowledge of security controls like Authentication, Authorization, Data Security, IAM
Understanding of information security and Cyber Security Frameworks like NIST, CIS, ISO
Understanding of information security, network management, operating systems, software development, database systems, and information technology
Technology controls around Cloud Computing reviews
Advanced experience with MS Office, SharePoint, and Reporting tools
Excellent written and verbal communication skills
Experience working in global, cross-functional, collaborative teams
Attention to detail
Flexibility, multi-tasking, and good business judgment skills
Ability to work well in both individual contributor and team capacity
Responsibilities
Conduct security risk assessments on new and existing Northern Trust third-party business partners
Ensure proper preventative and detective controls are in place and prepare recommendations to strengthen control weaknesses
Monitor the status of remediation actions and provide periodic updates to applicable stakeholders
Work across the lines of defense to coordinate changes, provide review and challenge, and respond to audit and regulatory requirements
Participate in cyber incident responses to provide guidance related to cyber security risks and control assurance
Interact professionally and develop relationships with individuals and teams at any level in Northern Trust
Foster a positive and collaborative environment
Contribute to automation, analytics, and continuous improvements of processes
Train associates on the incident/issue management process and procedures via mentoring