Job offer
Senior Lead, Technology Risk & Controls - SOX / SOC Programs
As Senior Lead for Technology Risk & Controls at Northern Trust in Chicago, you will lead the global SOX and SOC compliance programs and advise senior technology executives on IT general controls. The position requires 8–11 years of experience, relevant certifications, and a salary ranging from $140,000 to $160,000.
Summary
- You will join Northern Trust’s Technology Risk and Control team as a leader responsible for overseeing the Technology SOX and SOC (SOC 1, SOC 2) control programs across a global technology environment.
- This role collaborates with financial audit and external audit firms, specifically assisting with the design, risk assessment, development of controls, and continuous improvement of technology controls that support audit reporting, financial reporting, and client assurance responsibilities.
- As a trusted advisor to senior technology executives, you will provide global subject matter expertise on IT General Controls (ITGC), including risk management, audits of internal controls, audit committee reporting, oversight of third-party providers, and the integrated use of audit tools for issue tracking, issue remediation, and control testing.
- This role involves the ongoing analysis of organizational needs and the development of action plans, recommendations, and strategic initiatives to determine the operational and capital requirements necessary to meet organizational objectives.
Responsibilities
- Oversee major compliance projects that include the development of actionable plans, business analysis, process design and workflows, documentation of procedures, and the creation and execution of data analysis.
- Provide management with quarterly reports and present the findings and recommendations to the Board of Directors.
- Create and lead special projects to mitigate risks identified during audit and assessment engagements.
- Provide guidance and facilitate the development of frameworks for risk identification, assessment, and mitigation using ISO 81000.
- Apply risk management and control frameworks across multifaceted internal and external risk management, compliance, and audit programs.
- Work closely with Technology and Global Risk partners to develop and implement efficient processes and practices.
- Support technology risk self-assessments, prepare testing and remediation task lists, and deliver test results and milestones as expected by external auditors and third-party partners.
Your Knowledge and Skills
- Experience working with audit firms and service providers that require the regular implementation of service organization controls, including the preparation and assessment of the initiative and control structure.
- A strong understanding of the principles of IT General Controls (ITGCs) and industry best practices, including SOX, SOC, GDPR, and PCI DSS.
- Extensive experience working with ERP systems (SAP, Oracle, Microsoft Dynamics 365, NetSuite, Workday, Workday Financial, Workday Human Capital Management, Workday Service Cloud).
- A strong understanding of IT risk and control frameworks and industry best practices, including COBIT, NIST, ISO 27001, and ISO 22301.
- Experience working with technical and management teams in an IT governance and audit environment.
- Proven ability to manage, lead, and coach a team in an environment where change is the norm.
- Proficiency is required in IT audit and control testing tools, data analytics software (ACL, IDEA, SQL, Power BI/Tableau, Python, R), and collaboration platforms (Jira, Confluence, ServiceNow).
- Strong analytical, written, and verbal communication skills.
Qualifications
- A bachelor's degree in CPA, CIA, CISA, CISM, CRISC, CISSP, or a related field is required.
- Relevant industry-recognized certifications are required; one combination, including but not limited to: Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), Certified Risk and Information Systems Controls (CRISC), Certified Internal Auditor (CIA), Certified Protection Professional (CPP).
Working With Us
- Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship, either now or in the future.
- Minimum Experience: 8–11 Years
- Maximum Experience: More than 12
- Work Schedule: Regular Work Schedule
- Location: Chicago, Illinois; Full-time
- Salary Range: $140,000 - $160,000
Job details