Senior Lead, Technology Risk & Controls - SOX / SOC Programs
Listed on 2026-08-18
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Business Analyst, IT Consultant
About Northern Trust
As a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world's most successful individuals, families, corporations and institutions.
Since 1889, we have aligned our efforts with our three guiding Principles That Endure:
Service, Expertise, and Integrity. Together, they reflect the three cornerstones of business conduct which we strive to instill in our employees, whom we call partners, and to provide to our clients and the communities we serve worldwide.
With more than 135 years of financial experience and over 24,000 partners, we serve the world's most sophisticated clients using leading technology and exceptional service.
Senior Lead, Technology Risk & Controls
- SOX / SOC Programs
Summary:
You will join Northern Trust's Technology Risk and Control team as a leader responsible for overseeing the Technology SOX and SOC (SOC 1 / SOC
2) control programs across a global technology environment. This role partners closely with Technology leadership, Control Officers, Compliance, Internal Audit, External Audit, and Second Line of Defense (2
LOD) partners to ensure the design, implementation, monitoring, and continuous improvement of technology controls supporting regulatory, financial reporting, and client assurance requirements.
As a trusted advisor to senior technology executives, you will provide subject matter expertise on IT General Controls (ITGCs), technology risk management, control maturity, audit readiness, and remediation strategies. You will drive enterprise-wide control excellence, lead interactions with external auditors, oversee complex remediation initiatives, and influence risk-informed decision-making across the global technology organization.
You will be part of a dedicated and high-performing team committed to strengthening control awareness, operational resilience, and risk governance throughout Northern Trust's technology environments.
Responsibilities:
- Represent the Technology organization as liaison for the global SOX and SOC report issuance , ensuring effective governance, control execution, audit readiness, and regulatory compliance.
- Serve as the subject matter expert for Information Technology General Controls (ITGCs), including Access Management, Privileged Access Management, Change Management, System Development Lifecycle (SDLC), Information Produced by the Entity (IPE), Technology Operations, Automated Controls, and Cloud and Infrastructure Controls.
- Lead and perform technology risk and control assessments across critical applications, infrastructure platforms, cybersecurity processes, cloud environments, and technology-enabled business services.
- Drive control design reviews, control effectiveness assessments, maturity evaluations, and control optimization initiatives to improve the overall technology control environment.
- Partner with technology executives, application owners, and control owners to identify , assess, and remediate control deficiencies, audit findings, and regulatory issues through sustainable corrective action plans.
- Advis e on complex remediation programs, including root cause analysis, corrective action planning, issue governance, and validation of remediation effectiveness.
- Serve as the primary liaison for External Audit, Internal Audit, Compliance, and Risk Management functions by coordinating audit activities, leading walkthroughs, challenging audit observations when appropriate , and ensuring timely delivery of evidence and management responses.
- Monitor and advise on SOX and SOC scoping activities, application onboarding, impact assessments, control changes, and implementation of new regulatory or audit requirements.
- Support Control Officers in executive reporting, issue tracking and resolution, key risk indicator reporting, and risk appetite monitoring.
- Review and challenge risk assessments, control documentation, management assertions, testing results, and deliverables prepared by team members and third-party partners.
- Influence behaviors to reduce risk and foster a strong technology risk management culture throughout the enterprise.
- Identify opportunities to enhance control monitoring, analytics, automation, and continuous assurance capabilities.
Your Knowledge and
Skills:
- Deep expertise in SOX, SOC 1, and SOC 2 compliance programs within complex technology environments.
- Significant experience executing risk assessments, control effectiveness assessments, inherent risk evaluations, and residual risk assessments.
- Significant experience evaluating and testing controls across technology domains including Identity and Access Management, Cloud Governance, Change Management, Software Development Lifecycle, Cybersecurity Operations, Vendor Risk Management, Technology Governance, Infrastructure and Platform Services, Information Security, and IT Asset Management.
- Excellent executive presentation skills, including preparation and delivery of materials for senior…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).