ForgeApply · Job listing
2LOD Control Testing Senior Associate
Northern Trust
Tailor your resume for this Northern Trust job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Northern Trust's site. Free trial, no card required.
About this role
About Northern Trust
As a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world’s most successful individuals, families, corporations and institutions.
Since 1889, we have aligned our efforts with our three guiding Principles That Endure: Service, Expertise, and Integrity. Together, they reflect the three cornerstones of business conduct which we strive to instill in our employees, whom we call partners, and to provide to our clients and the communities we serve worldwide.
With more than 135 years of financial experience and over 24,000 partners, we serve the world’s most sophisticated clients using leading technology and exceptional service.
The Second Line of Defense (2LOD) Controls Testing partner within Enterprise Risk Management (ERM) will work closely with peers, stakeholders, and their manager on the Second Line’s Controls Testing Program focused on Enterprise Risk Management (ERM), Entity Level Controls (ELCs), Cyber, Technology, and Non-Technology Controls.
The role is responsible for performing independent review and challenge activities across the Enterprise Risk Management Framework, assessing the effectiveness of risk management processes and controls, evaluating Entity Level Controls (ELCs), and providing independent assurance over the organization’s risk and control environment.
The key responsibilities of the role include:
• Test, validate, and assert to Business and Application Owners the control testing methodology and test procedures, ensuring that all documentation is accurate and complete. • Perform 2LOD validation work, including plan preparation, maintenance of workpapers, identification of findings, and reporting results to risk committees. • Assess Enterprise Risk Management (ERM) programs, processes, and activities across the ERM lifecycle, including risk identification, assessment, monitoring, reporting, treatment, governance, and risk appetite management. • Evaluate the design and operating effectiveness of Entity Level Controls (ELCs), including governance and oversight activities, risk reporting processes, issue management programs, policy governance, committee structures, and other enterprise-wide control environment activities. • Manage day-to-day risk issues related to the design and implementation of new controls, working with various teams to ensure proper execution. • Examine cyber, technology, operational, and enterprise-level controls, including ELCs, evaluate their design and operational effectiveness, determine exposure to risk, and partner with the business to develop remediation strategies. • Assess risk as a Second Line governance function through Risk and Control Testing, Risk Identification, Change Initiative Risk Assessments, and other Enterprise Risk Management activities, as applicable. • Perform independent review and challenge activities over risk management processes and control environments to assess alignment with Enterprise Risk Management Framework requirements, regulatory expectations, and industry standards. • Provide Second Line risk and control testing findings to Risk Management leadership and risk committees, ensuring timely communication of identified issues. • Demonstrate understanding of the Three Lines of Defense governance model and apply it consistently throughout testing activities. • Demonstrate understanding of Enterprise Risk Management principles and apply ERM concepts consistently throughout testing and review activities. • Assess governance structures, management oversight activities, risk reporting processes, and enterprise-wide control environments to identify opportunities for improvement and enhance organizational resilience. • Effectively communicate operational and technical findings and control issues to executive and business leadership using language relevant to and understandable by the business. • Apply strong risk assessment framework knowledge and experience to identify key risks and controls, performing thorough risk assessments. • Exhibit strong project management skills, adapting to change quickly, managing multiple tasks, and demonstrating flexibility in prioritization. • Maintain a strong working knowledge of banking and financial regulatory requirements to ensure appropriate levels of testing. • Support continuous improvement efforts related to ERM programs, controls testing methodologies, governance processes, reporting capabilities, and quality assurance activities.
Qualifications: • 5-7 years of experience in Internal Audit, IT Audit, Risk Management, Enterprise Risk Management, Operational Risk, Compliance, Cybersecurity, IT Risk and Control, or related disciplines. • Experience assessing Enterprise Risk Management (ERM) programs, governance processes, risk management activities, and control environments. • Familiarity with Entity Level Controls (ELCs), Risk and Control Self-Assessments (RCSAs), issue management programs, risk governance activities, and risk reporting processes. • Strong understanding of Enterprise Risk Management frameworks, governance structures, and the Three Lines of Defense model. • CISSP, CISM, CISA, CRISC, CIA, or equivalent certifications highly preferred. • Strong working knowledge of inherent cyber risks within the financial services industry. • Cloud, MFA, password vaulting (e.g., CyberArk), Secure SDLC, and technology control concepts preferred. • Analytical and communication skills required to summarize and analyze complex information. • Organizational skills required to coordinate risk-related activities with peers and senior executives. • Advanced Microsoft Office 365 skills and familiarity with risk management and GRC platforms (e.g., ServiceNow, Fusion) to track, manage, and report control testing results, issues, and remediation activities.
This position resides within Enterprise Risk Management (ERM) and is responsible for providing independen
Salary insight
The midpoint of this range ($95k) is about 25% below the median disclosed salary for Phoenix roles listed on ForgeApply ($127k across 194 jobs).
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Northern Trust role before you apply.
Tailor my resume for this jobSimilar jobs
- Senior Associate Quality Assurance — Amgen · Thousand Oaks, California, United States
- Sr. Associate, Quality Assurance Engineering — Alcon · Fort Worth, Texas
- Quality Control Analyst II — Roche · South San Francisco
- Senior Development Test Engineer — K2spacecorporation · Los Angeles, CA
- IT Quality Assurance Analyst 2 — Sefl · Lexington, SC
- Sr. System Test Engineer - HiL — Torcrobotics · Remote
- Senior Quality Test Engineer — Torcrobotics · Fort Worth, Texas
- Quality Control Associate — Cookunity · New York, New York, United States
More like this: More jobs at Northern Trust · Browse all jobs
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)