Sr Associate, Cyb Sec IT RiskM
Northern Trust
About Northern Trust
As a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world’s most successful individuals, families, corporations and institutions.
Since 1889, we have aligned our efforts with our three guiding Principles That Endure: Service, Expertise, and Integrity. Together, they reflect the three cornerstones of business conduct which we strive to instill in our employees, whom we call partners, and to provide to our clients and the communities we serve worldwide.
With more than 135 years of financial experience and over 24,000 partners, we serve the world’s most sophisticated clients using leading technology and exceptional service.
This role provides specialized technology risk advisory support across key IT Service Management (ITSM) processes, including Incident, Change, and Problem Management. The individual acts as a trusted risk partner to ITSM process owners by assessing control design and operating effectiveness, identifying control gaps, and advising on risk treatment strategies aligned to Technology Risk standards. The role combines control assessment execution, risk analysis, and stakeholder advisory, with a strong focus on practical risk mitigation, consistency in documentation, and readiness for internal audits, RCSA exercises, and regulatory reviews.
Role and Responsibilities
ITSM Control Assessment Execution Plan and execute ITSM control assessments within an assigned scope of Incident, Change, and Problem Management processes. Perform assessments in alignment with established policies, standards, and control testing methodologies, under the guidance of senior leadership. Control Design and Operating Effectiveness Evaluation Evaluate the design and operational effectiveness of ITSM controls to identify gaps, execution weaknesses, and process deviations. Clearly articulate root causes, control impacts, and associated technology risk implications. Validate that controls are: Appropriately defined and documented Consistently executed by process owners Supported by complete, accurate, and reliable evidence. Risk Advisory and Issue Support Provide risk-based advisory guidance to control and process owners on identified control weaknesses. Support the documentation, classification, and escalation of issues arising from assessments. Advise on appropriate risk treatment options—including remediation, risk acceptance, or escalation—in accordance with Technology Risk and IT Risk Management standards. Assessment Documentation and Tooling Ensure assessment results, evidence, and supporting artifacts are accurately documented and maintained in ServiceNow / Integrated Risk Management (IRM) tools. Adhere to documentation standards to support transparency, auditability, and reuse for future assessments. Stakeholder Engagement and Communication Engage with ITSM process owners, technology teams, and risk stakeholders to explain assessment results, control gaps, and risk impacts in a clear and practical manner. Contribute to working sessions, governance forums, and RCSA readiness discussions by providing timely updates and insights relevant to ITSM risk posture. Trend Analysis and Continuous Improvement Identify recurring issues, themes, and systemic control weaknesses across assessments. Provide recommendations to enhance control design, process execution, and testing approaches. Contribute to continuous improvement of ITSM control frameworks and readiness for audits and regulatory reviews. Standards and Industry Awareness Maintaining working knowledge of ITSM, control, and technology risk best practices, including relevant industry standards. Apply this knowledge to assessments and advisory discussions to ensure alignment with evolving expectations.
Don't want to miss the next one?
Subscribe to daily email alerts for roles matching your interests.