ForgeApply
Try it free

ForgeApply · Job listing

Senior Lead, Technology Risk & Controls - SOX / SOC Programs

Northern Trust

Chicago, IL, US$96k – $162khybrid

Tailor your resume for this Northern Trust job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Northern Trust's site. Free trial, no card required.

About this role

About Northern Trust

As a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world’s most successful individuals, families, corporations and institutions.

Since 1889, we have aligned our efforts with our three guiding Principles That Endure: Service, Expertise, and Integrity. Together, they reflect the three cornerstones of business conduct which we strive to instill in our employees, whom we call partners, and to provide to our clients and the communities we serve worldwide.

With more than 135 years of financial experience and over 24,000 partners, we serve the world’s most sophisticated clients using leading technology and exceptional service.

Senior Lead, Technology Risk & Controls  - SOX / SOC Programs  

Summary:  

You will join   Northern   Trust’s Technology Risk and Control team as a leader responsible for overseeing the Technology SOX and SOC (SOC 1 / SOC 2) control programs across a global technology environment. This role partners closely with Technology leadership, Control Officers, Compliance, Internal Audit, External Audit, and Second Line of Defense (2LOD) partners to ensure the design, implementation, monitoring, and continuous improvement of technology controls supporting regulatory, financial reporting, and client assurance requirements.  

As a trusted advisor to senior technology executives, you will provide subject matter   expertise   on IT General Controls (ITGCs), technology risk management, control maturity, audit readiness, and remediation strategies. You will drive enterprise-wide control excellence, lead interactions with external auditors, oversee complex remediation initiatives, and influence risk-informed decision-making across the global technology organization.  

You will be part of a dedicated and high-performing team committed to strengthening control awareness, operational resilience, and risk governance throughout Northern Trust’s technology environments.  

Responsibilities:  

• Represent the Technology organization as   liaison   for   the global SOX and SOC   report issuance , ensuring effective governance, control execution, audit readiness, and regulatory compliance.  

• Serve as the subject matter expert for Information Technology General Controls (ITGCs), including Access Management, Privileged Access Management, Change Management, System Development Lifecycle (SDLC), Information Produced by the Entity (IPE), Technology Operations, Automated Controls, and Cloud and Infrastructure Controls.  

• Lead and perform technology risk and control assessments across critical applications, infrastructure platforms, cybersecurity processes, cloud environments, and technology-enabled business services.  

• Drive control design reviews, control effectiveness assessments, maturity evaluations, and control optimization initiatives to improve the overall technology control environment.  

• Partner with technology executives, application owners, and control owners to   identify , assess, and remediate control deficiencies, audit findings, and regulatory issues through sustainable corrective action plans.  

• Advis e   on   complex   remediation programs, including root cause analysis, corrective action planning, issue governance, and validation of remediation effectiveness.  

• Serve as the primary liaison for External Audit, Internal Audit, Compliance, and Risk Management functions by coordinating audit activities, leading walkthroughs, challenging audit observations when   appropriate , and ensuring   timely   delivery of evidence and management responses.  

• Monitor and   advise   on SOX   and SOC scoping activities, application onboarding, impact assessments, control changes, and implementation of new regulatory or audit requirements.  

• Support Control Officers in executive reporting, issue tracking and resolution, key risk indicator reporting, and risk appetite monitoring.  

• Review and challenge risk assessments, control documentation, management assertions, testing results, and deliverables prepared by team members and third-party partners.  

• Influence behaviors to reduce risk and foster a strong technology risk management culture throughout the enterprise.  

• Identify   opportunities to enhance control monitoring, analytics, automation, and continuous assurance capabilities.  

Your Knowledge and Skills:  

• Deep   expertise   in SOX, SOC 1, and SOC 2 compliance programs within complex technology environments.  

• Significant experience   executing risk assessments, control effectiveness assessments, inherent risk evaluations, and residual risk assessments.  

• Significant experience   evaluating and testing controls across technology domains including Identity and Access Management, Cloud Governance, Change Management, Software Development Lifecycle, Cybersecurity Operations, Vendor Risk Management, Technology Governance, Infrastructure and Platform Services, Information Security, and IT Asset Management.  

• Excellent executive presentation skills, including preparation and delivery of materials for senior leadership, governance committees, and regulatory audiences.  

• Excellent written and verbal communication skills with the ability to influence and challenge senior stakeholde rs.  

• Significant experience   developing and implementing Technology Risk and Control Frameworks, Risk and Control Matrices, and control monitoring programs.  

• Extensive experience managing relationships with External Auditors, Internal Audit, Compliance, and 2LOD Risk Management functions.  

• Proven ability to lead large-scale remediation initiatives, including root cause analysis, corrective action planning, and sustainable control implementation.  

• Strong understanding of industry frameworks and standards including COSO, COBIT, NIST, SOX, SOC 1, and SOC 2.  

• Experience   leveraging   governance, risk, and compliance (GRC) platf

Salary insight

The midpoint of this range ($129k) is about 5% below the median disclosed salary for Chicago roles listed on ForgeApply ($135k across 1,245 jobs).

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Tailor your resume for this Northern Trust role before you apply.

Tailor my resume for this job

Similar jobs

More like this: More jobs at Northern Trust · Browse all jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)