2LOD Control Testing Senior Associate
Listed on 2026-08-14
-
Finance & Banking
Risk Manager/Analyst, Financial Compliance
About Northern Trust
As a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world’s most successful individuals, families, corporations and institutions.
About Northern Trust
As a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world’s most successful individuals, families, corporations and institutions.
Since 1889, we have aligned our efforts with our three guiding Principles That Endure:
Service, Expertise, and Integrity. Together, they reflect the three cornerstones of business conduct which we strive to instill in our employees, whom we call partners, and to provide to our clients and the communities we serve worldwide.
With more than 135 years of financial experience and over 24,000 partners, we serve the world’s most sophisticated clients using leading technology and exceptional service.
The Second Line of Defense (2
LOD) Controls Testing partner within Enterprise Risk Management (ERM) will work closely with peers, stakeholders, and their manager on the Second Line’s Controls Testing Program focused on Enterprise Risk Management (ERM), Entity Level Controls (ELCs), Cyber, Technology, and Non-Technology Controls.
The role is responsible for performing independent review and challenge activities across the Enterprise Risk Management Framework, assessing the effectiveness of risk management processes and controls, evaluating Entity Level Controls (ELCs), and providing independent assurance over the organization’s risk and control environment.
The Key Responsibilities Of The Role Include
- Test, validate, and assert to Business and Application Owners the control testing methodology and test procedures, ensuring that all documentation is accurate and complete.
- Perform 2
LOD validation work, including plan preparation, maintenance of work papers, identification of findings, and reporting results to risk committees. - Assess Enterprise Risk Management (ERM) programs, processes, and activities across the ERM lifecycle, including risk identification, assessment, monitoring, reporting, treatment, governance, and risk appetite management.
- Evaluate the design and operating effectiveness of Entity Level Controls (ELCs), including governance and oversight activities, risk reporting processes, issue management programs, policy governance, committee structures, and other enterprise-wide control environment activities.
- Manage day-to-day risk issues related to the design and implementation of new controls, working with various teams to ensure proper execution.
- Examine cyber, technology, operational, and enterprise-level controls, including ELCs, evaluate their design and operational effectiveness, determine exposure to risk, and partner with the business to develop remediation strategies.
- Assess risk as a Second Line governance function through Risk and Control Testing, Risk Identification, Change Initiative Risk Assessments, and other Enterprise Risk Management activities, as applicable.
- Perform independent review and challenge activities over risk management processes and control environments to assess alignment with Enterprise Risk Management Framework requirements, regulatory expectations, and industry standards.
- Provide Second Line risk and control testing findings to Risk Management leadership and risk committees, ensuring timely communication of identified issues.
- Demonstrate understanding of the Three Lines of Defense governance model and apply it consistently throughout testing activities.
- Demonstrate understanding of Enterprise Risk Management principles and apply ERM concepts consistently throughout testing and review activities.
- Assess governance structures, management oversight activities, risk reporting processes, and enterprise-wide control environments to identify opportunities for improvement and enhance organizational resilience.
- Effectively communicate operational and technical findings and control issues to executive and business leadership using language relevant to and understandable by the…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).