Job offer

Principal, GRC Cyber Risk Management

Northern Trust is seeking a Principal for GRC Cyber Risk Management to lead the identification, assessment, and reporting of cyber risks across the company. This hybrid position in Tempe, AZ, requires at least five years of experience in cyber risk management, as well as knowledge of frameworks such as NIST CSF and ISO 27001.

Tasks

  • Lead the identification, assessment, prioritization, and reporting of critical risk data across the enterprise to inform management decisions, support risk appetite management, and demonstrate management-level alignment of cyber risk assessments, remedial reviews, and other maturity assessments in accordance with industry frameworks and regulatory expectations.
  • Develop key reporting frameworks that provide solid insights into controls for executive leadership, risk committees, and regulators.
  • Partner with experts in various risk domains (e.g., security, operations, architecture) to improve risk mitigation outcomes.
  • Enhance cyber risk intelligence capabilities through automated outputs and the reinvestment of process automation.
  • Translates highly technical risk data into the needs, actions, and strategic priorities of core business owners.
  • Evolution aligns targets, including first-, second-, and third-party entities within enterprises, to reveal the implications of cyber risk.
  • Participate in our efforts to develop GRC capabilities such as automation, third-party risk, and cyber-related risk.

Requirements

  • Bachelor's degree in information security, computer science, or a related field. A master's degree is preferred.
  • At least 5 years of experience in cybersecurity, with a focus on risk management and the development of cybersecurity risk management frameworks for methodologies such as NIST CSF, CMMI for PSM, ISO 27001, and vetted risk assessments.
  • A strong understanding of modern threat and risk trends, risk methodologies, risk assessment environments, technology, and the implications of emerging AI.
  • Gain experience in leveraging analytics, automation, or data engineering capabilities to improve cyber risk detection and outcomes.
  • Demonstrated ability to translate complex risk data requirements into meaningful information in technical and regulatory environments: communication and presentation skills, with the ability to break down technical risk for both technical and non-technical audiences.
  • Excellent analytical, problem-solving, and decision-making skills.
  • Numerous certifications, such as CISSP, CISM, CRISC, or similar.

We offer

  • Salary Range: $124,500 - $183,000
  • The salary range is a good-faith estimate of base pay.
  • Northern Trust offers a comprehensive benefits package that includes unlimited personal days (PTO) and health and wellness benefits (medical, dental, and vision, depending on the role and department).

Job details

© 2025 House of Skills by skillaware. All rights reserved.
Our website uses cookies to make navigation easier for you and to analyze the use of the site. You can find more information in our privacy policy.