About Northern Trust
As a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world’s most successful individuals, families, corporations and institutions.
Since 1889, we have aligned our efforts with our three guiding Principles That Endure: Service, Expertise, and Integrity. Together, they reflect the three cornerstones of business conduct which we strive to instill in our employees, whom we call partners, and to provide to our clients and the communities we serve worldwide.
With more than 135 years of financial experience and over 24,000 partners, we serve the world’s most sophisticated clients using leading technology and exceptional service.
The Second Line of Defense (2LOD) Controls Testing partner within Enterprise Risk Management (ERM) will work closely with peers, stakeholders, and their manager on the Second Line’s Controls Testing Program focused on Enterprise Risk Management (ERM), Entity Level Controls (ELCs), Cyber, Technology, and Non-Technology Controls.
The role is responsible for performing independent review and challenge activities across the Enterprise Risk Management Framework, assessing the effectiveness of risk management processes and controls, evaluating Entity Level Controls (ELCs), and providing independent assurance over the organization’s risk and control environment.
The key responsibilities of the role include:
- Test, validate, and assert to Business and Application Owners the control testing methodology and test procedures, ensuring that all documentation is accurate and complete.
- Perform 2LOD validation work, including plan preparation, maintenance of workpapers, identification of findings, and reporting results to risk committees.
- Assess Enterprise Risk Management (ERM) programs, processes, and activities across the ERM lifecycle, including risk identification, assessment, monitoring, reporting, treatment, governance, and risk appetite management.
- Evaluate the design and operating effectiveness of Entity Level Controls (ELCs), including governance and oversight activities, risk reporting processes, issue management programs, policy governance, committee structures, and other enterprise-wide control environment activities.
- Manage day-to-day risk issues related to the design and implementation of new controls, working with various teams to ensure proper execution.
- Examine cyber, technology, operational, and enterprise-level controls, including ELCs, evaluate their design and operational effectiveness, determine exposure to risk, and partner with the business to develop remediation strategies.
- Assess risk as a Second Line governance function through Risk and Control Testing, Risk Identification, Change Initiative Risk Assessments, and other Enterprise Risk Management activities, as applicable.
- Perform independent review and challenge activities over risk management processes and control environments to assess alignment with Enterprise Risk Management Framework requirements, regulatory expectations, and industry standards.
- Provide Second Line risk and control testing findings to Risk Management leadership and risk committees, ensuring timely communication of identified issues.
- Demonstrate understanding of the Three Lines of Defense governance model and apply it consistently throughout testing activities.
- Demonstrate understanding of Enterprise Risk Management principles and apply ERM concepts consistently throughout testing and review activities.
- Assess governance structures, management oversight activities, risk reporting processes, and enterprise-wide control environments to identify opportunities for improvement and enhance organizational resilience.
- Effectively communicate operational and technical findings and control issues to executive and business leadership using language relevant to and understandable by the business.
- Apply strong risk assessment framework knowledge and experience to identify key risks and controls, performing thorough risk assessments.
- Exhibit strong project management skills, adapting to change quickly, managing multiple tasks, and demonstrating flexibility in prioritization.
- Maintain a strong working knowledge of banking and financial regulatory requirements to ensure appropriate levels of testing.
- Support continuous improvement efforts related to ERM programs, controls testing methodologies, governance processes, reporting capabilities, and quality assurance activities.
Qualifications:
- 5-7 years of experience in Internal Audit, IT Audit, Risk Management, Enterprise Risk Management, Operational Risk, Compliance, Cybersecurity, IT Risk and Control, or related disciplines.
- Experience assessing Enterprise Risk Management (ERM) programs, governance processes, risk management activities, and control environments.
- Familiarity with Entity Level Controls (ELCs), Risk and Control Self-Assessments (RCSAs), issue management programs, risk governance activities, and risk reporting processes.
- Strong understanding of Enterprise Risk Management frameworks, governance structures, and the Three Lines of Defense model.
- CISSP, CISM, CISA, CRISC, CIA, or equivalent certifications highly preferred.
- Strong working knowledge of inherent cyber risks within the financial services industry.
- Cloud, MFA, password vaulting (e.g., CyberArk), Secure SDLC, and technology control concepts preferred.
- Analytical and communication skills required to summarize and analyze complex information.
- Organizational skills required to coordinate risk-related activities with peers and senior executives.
- Advanced Microsoft Office 365 skills and familiarity with risk management and GRC platforms (e.g., ServiceNow, Fusion) to track, manage, and report control testing results, issues, and remediation activities.
This position resides within Enterprise Risk Management (ERM) and is responsible for providing independent review and challenge over risk management activities, Entity Level Controls (ELCs), governance processes, and the overall effectiveness of the organization’s risk and control environment.
Salary Range:
$70,490 - 119,890 USDSalary range is a good faith estimate of base pay. Northern Trust provides a comprehensive benefits package including retirement benefits (401k and pension), health and welfare benefits (medical, dental, vision, spending accounts and disability), paid time off, parental and caregiver leave, life & accident insurance, and other voluntary and well-being benefits. Northern Trust also provides a discretionary bonus program that may include an equity component.
Work Authorization
Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. Northern Trust will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa).
Working with Us
As a Northern Trust partner, you will be part of a flexible and collaborative work culture, which has a strong history of financial strength and stability. Movement within the organization is encouraged, senior leaders are accessible, and you can take pride in working for a company committed to an inclusive workplace and assisting the communities we serve.
Philanthropy is deeply rooted in Northern Trust’s history and is an essential element of our culture. Employees around the world give their time and talent to work for the greater good of their communities.
Reasonable Accommodation
Northern Trust is committed to working with and providing adjustments to individuals with health conditions and disabilities. If you need a reasonable accommodation for any part of the employment process, please email our HR Service Center at [email protected], or alternatively you can discuss your individual requirements with the recruiter you are working with.
Skills Required
- 5-7 years of experience in Internal Audit, IT Audit, Risk Management, ERM, Operational Risk, Compliance, Cybersecurity, IT Risk and Control, or related disciplines.
- Experience assessing ERM programs, governance processes, risk management activities, and control environments.
- Familiarity with Entity Level Controls (ELCs), Risk and Control Self-Assessments (RCSAs), issue management programs, risk governance, and risk reporting processes.
- Strong understanding of Enterprise Risk Management frameworks, governance structures, and the Three Lines of Defense model.
- CISSP, CISM, CISA, CRISC, CIA, or equivalent certifications.
- Strong working knowledge of inherent cyber risks within the financial services industry.
- Knowledge of Cloud, MFA, password vaulting (e.g., CyberArk), Secure SDLC, and technology control concepts.
- Analytical and communication skills to summarize and analyze complex information.
- Organizational skills to coordinate risk-related activities with peers and senior executives.
- Advanced Microsoft Office 365 skills and familiarity with risk management and GRC platforms (e.g., ServiceNow, Fusion).
- Authorized to work in the U.S. without the need for employment-based visa sponsorship.
- Strong working knowledge of banking and financial regulatory requirements.
Northern Trust Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Northern Trust and has not been reviewed or approved by Northern Trust.
-
Retirement Support — A 401(k) with company match alongside an employer‑funded defined‑benefit pension is highlighted in employer‑verified materials and filings, setting the retirement package apart from many private employers.
-
Leave & Time Off Breadth — PTO is portrayed as solid overall, and two paid volunteer days per year are clearly documented across corporate materials.
-
Parental & Family Support — Company sources and postings reference paid parental and caregiver leave and recent enhancements to parental benefits, indicating meaningful family support within the package.
Northern Trust Insights
What We Do
As a global leader in innovative wealth management, asset servicing and investment solutions, Northern Trust (Nasdaq: NTRS) is proud to guide the world’s most successful individuals, families and institutions by remaining true to our enduring principles of service, expertise and integrity. A globally recognized Fortune 500 Company in continuous operation since 1889, we’ve built a legacy of empowering clients to reach their goals with confidence. Since our roots as a trust bank, we’ve grown to a global presence with more than 24,000 employees in more than 20 countries and across six core business units: Wealth Management Asset Management Asset Servicing Technology Corporate Functions Enterprise Operations Join a Team That’s Achieving Greater At Northern Trust, we refer to our employees as partners – with good reason. We understand that relationships are the key to our success. Here you’ll join a diverse and inclusive team of innovators with the drive to challenge the way things have always been done. Instead of choosing between a dynamic career and work-life balance, enjoy working with a team that supports your goals in the office and at home. We’ll help you get where you want to go without sacrificing what matters most to you. Delivering value and adhering to our enduring principles What are enduring principles? Since our founding, they have guided our strategy and success. Thanks to the dedication of our partners, Northern Trust continues to thrive by adhering to three enduring principles: service, expertise and integrity . What does this mean? Service Northern Trust has a relentless drive to provide exceptional service to our clients, our partners and our communities. We set new standards and go above and beyond in our commitment to delivering greater results. Expertise Expertise is at the core of who we are. We focus sharply on what we do well. From expanding our capabilities, to hiring talented professionals to developing innovative solutions, our expertise is why we continue to be a trusted advisor for generations of families and institutions. Integrity Operating with uncompromising ethics is central to Northern Trust’s heritage. As a result, our clients, partners and communities know they can rely on us. For more than 130 years, our integrity has been our guide – and that will never change.
Why Work With Us
At Northern Trust, we go further because we go together. We embrace flexibility, encourage balance, and prioritize inclusion at all levels, working together to keep you connected. We are committed to our employees—all 24,000 of them. Whether this is a first step or a bold new leap in your career, we’re here to help you move forward.
Gallery








