Lead - Technology Risk and Control Self Assessment

Northern TrustChicago, IL
$83,100 - $141,300

About The Position

The Technology Risk & Control team plays a critical role in strengthening Northern Trust's First Line of Defense by promoting effective risk management practices, enhancing control environments, and supporting the delivery of resilient, secure, and compliant technology services. The Lead, Technology Risk & Control Self-Assessment (RCSA) will be responsible for leading the execution and continuous enhancement of the Technology RCSA Program across Global Technology. This role will partner closely with Technology leaders, Risk Management, Compliance, and Audit to drive consistent risk identification, assessment, monitoring, and reporting practices while promoting a strong risk and control culture. The successful candidate will provide subject matter expertise, governance oversight, and strategic guidance to support effective management of technology risks and controls, ensuring alignment with enterprise risk management frameworks, regulatory expectations, and business objectives.

Requirements

  • Strong knowledge of technology risk management, operational risk, controls, governance, and Risk & Control Self-Assessment (RCSA) methodologies.
  • Understanding technology risk domains including cybersecurity, infrastructure, cloud computing, technology operations, software development, resilience, and data management.
  • Familiarity with industry frameworks and standards including NIST, ISO 27001, COBIT, ITIL, and regulatory expectations applicable to financial services.
  • Demonstrated ability to influence stakeholders, provide constructive challenge, and build strong partnerships across multiple levels of the organization.
  • Excellent analytical, problem-solving, communication, and presentation skills with the ability to translate complex risk topics into meaningful business insights.
  • Experience leveraging data analytics, reporting tools, and emerging technologies to improve risk management processes and reporting effectiveness.
  • Proven ability to lead cross-functional initiatives and drive continuous improvement in a complex, highly regulated environment.
  • Bachelor’s degree in information technology, Cybersecurity, Information Security, Risk Management, or a related discipline.
  • Prior experience in Technology Risk or a related field.
  • Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. Northern Trust will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa).

Nice To Haves

  • Experience within the financial services industry is preferred.
  • Professional certifications such as CISSP, CISA, CRISC, CGEIT, or equivalent are preferred.

Responsibilities

  • Lead the execution and ongoing maturity of the Technology Risk & Control Self-Assessment (RCSA) Program across Global Technology.
  • Drive consistent identification, assessment, monitoring, and reporting of technology risks and controls, ensuring alignment with Enterprise Risk Management standards and regulatory expectations.
  • Partner with Technology leaders, Control Officers, Risk, Compliance, and Audit teams to strengthen risk visibility, control effectiveness, and remediation outcomes.
  • Provide effective challenge and risk advisory support to stakeholders on risk assessments, control design, control effectiveness, and risk treatment strategies.
  • Facilitate governance forums and risk reviews to evaluate technology risk exposures, emerging risks, and alignment with established risk appetite and tolerance thresholds.
  • Develop and enhance risk reporting, metrics, dashboards, and management information that support informed decision-making by senior leadership.
  • Drive continuous improvement initiatives focused on enhancing assessment methodologies, strengthening data quality, improving reporting capabilities, and increasing overall risk management maturity.
  • Promote risk awareness and accountability through stakeholder engagement, training, and consistent application of RCSA standards and practices.
  • Support executive and governance committee reporting by providing insights into key risk themes, trends, control effectiveness, and emerging areas of concern.
  • Serve as a trusted partner and subject matter expert on technology risk management practices across Global Technology.

Benefits

  • retirement benefits (401k and pension)
  • health and welfare benefits (medical, dental, vision, spending accounts and disability)
  • paid time off
  • parental and caregiver leave
  • life & accident insurance
  • other voluntary and well-being benefits
  • discretionary bonus program that may include an equity component
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service