Principal Technology Risk & Control Officer managing technology risk assessments and controls at Northern Trust, a leading financial institution. Collaborating across multiple technology domains to ensure alignment with business objectives and regulatory expectations.
Responsibilities
Lead technology risk and control assessments across a broad range of domains, including application development, infrastructure, cloud, data, identity and access management, resiliency, third‑party technology services, change management, and technology operations
Evaluate technology risks throughout system lifecycles, including design, build, deployment, operation, and decommissioning, ensuring alignment with enterprise risk appetite and regulatory expectations
Provide subject‑matter expertise to support the development, maintenance, and alignment of technology risk, control, and governance standards with industry frameworks and internal policies
Partner with technology teams to assess control design and operating effectiveness, and to drive timely remediation of technology risk findings from audits, regulatory exams, risk assessments, and internal reviews
Analyze the impact of technology risks on critical business services, key processes, and customer outcomes , including availability, integrity, resilience, and regulatory compliance
Participate in major incident, resiliency, and control‑failure events , providing technology risk guidance and contributing to root‑cause analysis and control enhancements
Support technology risk training, awareness, and advisory activities to strengthen risk ownership and decision‑making across engineering, operations, and delivery teams
Influence behaviors, resolve conflicts, and foster strong collaboration between technology, risk, and business stakeholders to promote a mature and accountable technology risk management culture
Requirements
10+ years of experience in technology, risk management, audit, or control functions covering multiple technology domains such as application development, infrastructure, cloud, data, identity and access management, operations, resiliency, or third‑party technology risk
Strong experience performing technology risk assessments using recognized risk management frameworks (e.g., NIST, COBIT, ISO, or equivalent)
Demonstrated ability to assess risk impact, control effectiveness, and residual risk, and to translate technical issues into business‑relevant risk insights
Proven consultative, analytical, and communication skills with experience engaging senior technology and risk leaders
Industry certifications (risk, technology, audit, or security) preferred but not required
Bachelor’s degree in Computer Science, Information Systems, Engineering, or a related discipline, or an equivalent combination of education and experience supporting complex technology environments
Benefits
retirement benefits (401k and pension)
health and welfare benefits (medical, dental, vision, spending accounts and disability)
paid time off
parental and caregiver leave
life & accident insurance
discretionary bonus program that may include an equity component
Head of AI Security at Absa developing security frameworks for AI systems. Responsible for safeguarding AI platforms against cybersecurity threats and ensuring secure development practices.
Security Officer responsible for armed security at the Arizona State Courts Building. Patrolling, monitoring security systems, and ensuring safety during shifts, holidays, and weekends.
Senior Security Engineer managing Privileged Access Management solutions for ZEISS. Engineering and supporting PAM ecosystem, with a focus on BeyondTrust Password Safe, and ensuring reliable service delivery.
Senior Mobile Developer focused on Information Security developing mobile applications for Android and iOS using Flutter. Ensuring adherence to best security practices and developing secure solutions.
Application Security Architect with software development and application security experience needed for WEX. Responsible for securing applications by guiding and assessing security solutions.
Network Engineer specialized in Security managing systems for Arauco, based in Santiago. Overseeing security protocols and configuration of security equipment in a corporate setting.
Security Administrator managing USAF unit - level security policies and procedures at Offutt AFB. Performing various administrative tasks in support of senior staff and commanders.
OT Cybersecurity Engineer ensuring secure operations of production environment at Mercedes - Benz Türk. Overseeing cybersecurity measures and collaborating with IT and planning teams.
OT Cybersecurity Engineer ensuring secure operation of industrial production environments for Mercedes - Benz Türk in Istanbul and Aksaray. Collaborating with cross - functional teams to uphold cybersecurity standards.
Data Center Security Engineer focusing on securing infrastructure for AI systems. Collaborating with teams on OT and IT security architecture and incident response.