- Salary
- $70k – $120k
- Location
- Tempe, AZ, United States of America
- Type
- Full-time
- Seniority
- Entry
- Experience
- 5+ years
- Education
- Master
- Visa
- Not sponsored
- Source
- Workday
Description
About Northern Trust
As a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world’s most successful individuals, families, corporations and institutions.
Since 1889, we have aligned our efforts with our three guiding Principles That Endure: Service, Expertise, and Integrity. Together, they reflect the three cornerstones of business conduct which we strive to instill in our employees, whom we call partners, and to provide to our clients and the communities we serve worldwide.
With more than 135 years of financial experience and over 24,000 partners, we serve the world’s most sophisticated clients using leading technology and exceptional service.
The Second Line of Defense (2LOD) Controls Testing partner within Enterprise Risk Management (ERM) will work closely with peers, stakeholders, and their manager on the Second Line’s Controls Testing Program focused on Enterprise Risk Management (ERM), Entity Level Controls (ELCs), Cyber, Technology, and Non-Technology Controls.
The role is responsible for performing independent review and challenge activities across the Enterprise Risk Management Framework, assessing the effectiveness of risk management processes and controls, evaluating Entity Level Controls (ELCs), and providing independent assurance over the organization’s risk and control environment.
The key responsibilities of the role include:
- Test, validate, and assert to Business and Application Owners the control testing methodology and test procedures, ensuring that all documentation is accurate and complete.
- Perform 2LOD validation work, including plan preparation, maintenance of workpapers, identification of findings, and reporting results to risk committees.
- Assess Enterprise Risk Management (ERM) programs, processes, and activities across the ERM lifecycle, including risk identification, assessment, monitoring, reporting, treatment, governance, and risk appetite management.
- Evaluate the design and operating effectiveness of Entity Level Controls (ELCs), including governance and oversight activities, risk reporting processes, issue management programs, policy governance, committee structures, and other enterprise-wide control environment activities.
- Manage day-to-day risk issues related to the design and implementation of new controls, working with various teams to ensure proper execution.
- Examine cyber, technology, operational, and enterprise-level controls, including ELCs, evaluate their design and operational effectiveness, determine exposure to risk, and partner with the business to develop remediation strategies.
- Assess risk as a Second Line governance function through Risk and Control Testing, Risk Identification, Change Initiative Risk Assessments, and other Enterprise Risk Management activities, as applicable.
- Perform independent review and challenge activities over risk management processes and control environments to assess alignment with Enterprise Risk Management Framework requirements, regulatory expectations, and industry standards.
- Provide Second Line risk and control testing findings to Risk Management leadership and risk committees, ensuring timely communication of identified issues.
- Demonstrate understanding of the Three Lines of Defense governance model and apply it consistently throughout testing activities.
- Demonstrate understanding of Enterprise Risk Management principles and apply ERM concepts consistently throughout testing and review activities.
- Assess governance structures, management oversight activities, risk reporting processes, and enterprise-wide control environments to identify opportunities for improvement and enhance organizational resilience.
- Effectively communicate operational and technical findings and control issues to executive and business leadership using language relevant to and understandable by the business.
- Apply strong risk assessment framework knowledge and experience to identify key risks and controls, performing thorough risk assessments.
- Exhibit strong project management skills, adapting to change quickly, managing multiple tasks, and demonstrating flexibility in prioritization.
- Maintain a strong working knowledge of banking and financial regulatory requirements to ensure appropriate levels of testing.
- Support continuous improvement efforts related to ERM programs, controls testing methodologies, governance processes, reporting capabilities, and quality assurance activities.
Qualifications:
- 5-7 years of experience in Internal Audit, IT Audit, Risk Management, Enterprise Risk Management, Operational Risk, Compliance, Cybersecurity, IT Risk and Control, or related disciplines.
- Experience assessing Enterprise Risk Management (ERM) programs, governance processes, risk management activities, and control environments.
- Familiarity with Entity Level Controls (ELCs), Risk and Control Self-Assessments (RCSAs), issue management programs, risk governance activities, and risk reporting processes.
- Strong understanding of Enterprise Risk Management frameworks, governance structures, and the Three Lines of Defense model.
- CISSP, CISM, CISA, CRISC, CIA, or equivalent certifications highly preferred.
- Strong working knowledge of inherent cyber risks within the financial services industry.
- Cloud, MFA, password vaulting (e.g., CyberArk), Secure SDLC, and technology control concepts preferred.
- Analytical and communication skills required to summarize and analyze complex information.
- Organizational skills required to coordinate risk-related activities with peers and senior executives.
- Advanced Microsoft Office 365 skills and familiarity with risk management and GRC platforms (e.g., ServiceNow, Fusion) to track, manage, and report control testing results, issues, and remediation activities.
This position resides within Enterprise Risk Management (ERM) and is responsible for providing independent review and challenge over risk management activities, Entity Level Controls (ELCs), governance processes, and the overall effectiveness of the organization’s risk and control environment.
Salary Range:
$70,490 - 119,890 USDSalary range is a good faith estimate of base pay. Northern Trust provides a comprehensive benefits package including retirement benefits (401k and pension), health and welfare benefits (medical, dental, vision, spending accounts and disability), paid time off, parental and caregiver leave, life & accident insurance, and other voluntary and well-being benefits. Northern Trust also provides a discretionary bonus program that may include an equity component.
Work Authorization
Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. Northern Trust will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa).
Working with Us
As a Northern Trust partner, you will be part of a flexible and collaborative work culture, which has a strong history of financial strength and stability. Movement within the organization is encouraged, senior leaders are accessible, and you can take pride in working for a company committed to an inclusive workplace and assisting the communities we serve.
Philanthropy is deeply rooted in Northern Trust’s history and is an essential element of our culture. Employees around the world give their time and talent to work for the greater good of their communities.
Reasonable Accommodation
Northern Trust is committed to working with and providing adjustments to individuals with health conditions and disabilities. If you need a reasonable accommodation for any part of the employment process, please email our HR Service Center at [email protected], or alternatively you can discuss your individual requirements with the recruiter you are working with.