Source description
About the role
Lead - ICG IIS Application Vulnerability Assessment About Northern Trust As a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the worlds most successful individuals, families, corporations and institutions. Since 1889, we have aligned our efforts with our three guiding Principles That Endure: Service, Expertise, and Integrity. Together, they reflect the three cornerstones of business conduct which we strive to instill in our employees, whom we call partners, and to provide to our clients and the communities we serve worldwide. With more than 135 years of financial experience and over 24,000 partners, we serve the worlds most sophisticated clients using leading technology and exceptional service. Northern Trust is seeking a dynamic and experienced candidate to lead the Application Vulnerability Assessment function within the Infrastructure Control Governance (ICG) team . This role is critical to ensur e the security, availability, and regulatory compliance of our Important Internal Ser vi ce s (IIS) applications. The ideal candidate will bring audit expertise , strong leadership capabilities, and a strategic mindset to identify and mitigate Single Points of Failure (SPOF) across our Mission C ritical Assets (MCA) . JOB RESPONSIBILITIES Team Leadership & Oversight Supervise day-to-day operations of the IIS Application Vulnerability Assessment team. Assign tasks, monitor performance, and ensure timely execution of activities. Provide coaching, mentoring, and training to staff to ensure consistent quality and compliance. Application Vulnerability & SPOF Assessment Oversee vulnerability assessments and architectural reviews of IIS-MCA applications to identify SPOFs and systemic risks. Ensure assessments are aligned with business- criticality, regulatory requirements. Drive the development and adoption of standardized assessment methodologies and tooling. Stakeholder Engagement Collaborate with product owners, practice leads , infrastructure, and compliance stakeholders to understand application dependencies and risk exposure. Communicate technical findings in business terms to senior leadership, regulators, and audit teams. Represent the function in governance forums, risk committees, and strategic planning sessions. Compliance & Regulatory Alignment Ensure all assessment and remediation activities align with relevant financial regulations and compliance frameworks such as: ISO 27001, NIST Cybersecurity Framework, PCI-DSS, SOC 2, GDPR, etc. Support internal and external audits with documentation, evidence, and remediation tracking. Maintain audit readiness and ensure timely closure of compliance gaps. Risk Management & Remediation Oversight Prioritize vulnerabilities and SPOFs based on business impact, regulatory exposure, and operational risk. Facilitate and support the cross-functional identification of application vulnerabilities to ensure compliance with ser vi ce level agreements and established timelines. Establish robust governance mechanisms for the validation, tracking, reporting, and escalation of daily team activities. Innovation & Continuous Improvement Stay current with emerging threats, FinTech trends, and evolving regulatory landscapes. Identify opportunities for automation, process optimization, and proactive risk detection. Responsibilities and Ethical Conduct As a partner at Northern Trust, you must actively manage and mitigate risk and act with integrity. In accordance with our core values of ser vi ce , integrity, and expertise , you are expected to: Adhere to all applicable risk management programs, policies, and procedures. Complete all mandatory training by the deadline. Understand how your behavior could expose Northern Trust, its clients, and financial markets to different types of risk. Ensure that Northern Trust or its clients are not exposed to inappropriate or excessive risk. Escalate any risk concerns, including those resulting from mistakes / errors to a manager or business unit risk officer. Exercise diligence regarding cyber-security Cooperate with internal control functions (including first-line Control, Risk, Compliance, Audit, self-assigned, etc.) and applicable regulatory bodies. Avoid conflicts of interest or behaviors that might produce unfair outcomes for Northern Trust or its clients or damage the integrity of financial markets Must Haves: Risk Assessment & IT Audit Expertise Proven experience in scheduling and performing risk assessments or IT audits across critical ITIL and resiliency domains, including: Incident and Problem Management Change Management Disaster Recovery & Resiliency Availability and Capacity Management Infrastructure Security Leading team Proven experience in leading technical teams and managing cross-functional stakeholders and senior management . Communication & Collaboration Excellent written and verbal communication for cross functional .
More at Northern Trust
Related open roles
Cyber Security IT Risk Analyst
Mumbai
RCE Post - Lead, Insider Threat Hunter (India)
India
Lead - ICG IIS Application Vulnerability Assessment
India
Sr Associate, Cyber Sec Eng (Pune)
Mumbai
Lead– High Risk Issue Validation and Issue Governance & Oversight
Location not specified
Lead - ICG – IIS Application Vulnerability Assessment
Location not specified