Bachelor’s degree in computer science or a related discipline
At least ten or more years of experience in the field of Technology Security
Proven knowledge in domains such as Information Security Governance and Risk Management, Access Control, Vulnerability and Penetration, Network Security, Application Security, Cryptography, Security Architecture and Design, Operations Security, Business Continuity and Disaster Recovery Planning, Legal/Regulations/Investigations and Compliance, Physical and Environmental Security, Cloud Security
Knowledge of regulatory requirements and guidelines relating to Cyber Security, Information Security, Business Resilience, and Business Continuity Management
Knowledge of risk treatment and issues management functions and industry tools
Excellent written and verbal communication skills
Experience working in global, cross-functional, collaborative teams
Attention to detail
In-depth understanding of information security, network management, operating systems, software development, database systems, and information technology
Understanding of information security and Cyber Security Frameworks like NIST, Center for Internet Security (CIS), ISO, etc
Technology controls around Cloud Computing reviews
Advanced experience with MS Office, SharePoint, and Reporting tools
Professional certifications (such as CISA, CRISC, CISM, CISSP or similar) is a plus
Ability to interact professionally and develop relationships at any level
Flexibility, multi-tasking, and good business judgment skills
Ability to work well as an individual contributor and in a team capacity
Responsibilities
Conduct security risk assessments on new and existing Northern Trust third-party business partners
Ensure proper preventative and detective controls are in place and prepare recommendations to strengthen control weaknesses
Review master services contracts of third parties to identify information technology and security-related clauses
Support Issue Owners and/or Issue Identifiers in accurate documentation of root cause analysis, impact analysis, severity ratings, and corresponding remediation actions
Review evidence provided to validate remediation actions were implemented as required and meet all acceptance criteria to close the issue
Monitor the status of remediation actions and provide periodic updates to applicable stakeholders
Work across the lines of defense to coordinate changes, provide review and challenge, and respond to audit and regulatory requirements
Participate in cyber incident responses to provide guidance related to cyber security risks and control assurance
Foster a positive and collaborative environment
Contribute to automation, analytics, and continuous improvements of processes
Train associates on the incident/issue management process and procedures via mentoring