Senior Lead, Technology Risk & Controls - SOX / SOC Programs

Koitecc Solutions

Chicago, Northern (IL, KY)

Hybrid

USD 96,000 - 162,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Northern Trust is seeking a Senior Lead, Technology Risk & Controls to oversee global SOX and SOC programs. You will partner with Technology leadership, Compliance, Audit, and 2LOD to ensure effective control design, monitoring, and remediation across complex environments.

You will drive audit readiness, maturity assessments, and remediation strategies, influencing risk-informed decisions at the senior technology level.

Qualifications

  • Demonstrated SOX, SOC 1 & 2 program expertise in complex tech environments.
  • Experience with ITGCs, access control, change mgmt, SDLC and cloud controls.
  • Strong communication and executive presentation skills for governance forums.
  • Proven ability to lead cross-functional remediation efforts and audits.
  • Familiarity with COSO, COBIT, NIST frameworks and risk-based decision making.

Responsibilities

  • Represent Technology SOX/SOC governance, ensuring audit readiness and regulatory compliance.
  • Serve as SME for ITGCs and control domains across technology stacks.
  • Lead risk and control assessments for applications, infra, cybersecurity, and cloud.
  • Drive control design reviews, maturity evaluations, and optimization initiatives.
  • Collaborate with technology leaders to remediate control deficiencies and audit findings.
  • Advise on remediation programs, root cause analysis, and action plans.
  • Coordinate with External/Internal Audit, Compliance, and 2LOD for evidence and responses.
  • Monitor SOX/SOC scoping, onboarding, and new requirement implementation.
  • Support control officers with reporting, issue tracking, and risk indicators.
  • Review risk documentation and testing results prepared by teams and vendors.
  • Foster a risk-aware culture and continuous improvement in controls.

Skills

SOX/SOC expertise
Risk assessments
ITGC knowledge
Executive storytelling
Communication skills
Tech risk frameworks
External/Internal audit liaisons
Remediation leadership
COSO/COBIT/NIST
GRC tooling

Education

Bachelor's degree in CS/IS/Cybersecurity/Accounting/Finance

Tools

Archer
ServiceNow
AuditBoard
Power BI

Job description

About Northern Trust

As a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world's most successful individuals, families, corporations and institutions.

Since 1889, we have aligned our efforts with our three guiding Principles That Endure: Service, Expertise, and Integrity. Together, they reflect the three cornerstones of business conduct which we strive to instill in our employees, whom we call partners, and to provide to our clients and the communities we serve worldwide.

With more than 135 years of financial experience and over 24,000 partners, we serve the world's most sophisticated clients using leading technology and exceptional service.

Senior Lead, Technology Risk & Controls - SOX / SOC Programs
Summary:

You will join Northern Trust's Technology Risk and Control team as a leader responsible for overseeing the Technology SOX and SOC (SOC 1 / SOC 2) control programs across a global technology environment. This role partners closely with Technology leadership, Control Officers, Compliance, Internal Audit, External Audit, and Second Line of Defense (2LOD) partners to ensure the design, implementation, monitoring, and continuous improvement of technology controls supporting regulatory, financial reporting, and client assurance requirements.

As a trusted advisor to senior technology executives, you will provide subject matter expertise on IT General Controls (ITGCs), technology risk management, control maturity, audit readiness, and remediation strategies. You will drive enterprise-wide control excellence, lead interactions with external auditors, oversee complex remediation initiatives, and influence risk-informed decision-making across the global technology organization.

You will be part of a dedicated and high-performing team committed to strengthening control awareness, operational resilience, and risk governance throughout Northern Trust's technology environments.

Responsibilities:
  • Represent the Technology organization as liaison for the global SOX and SOC report issuance , ensuring effective governance, control execution, audit readiness, and regulatory compliance.
  • Serve as the subject matter expert for Information Technology General Controls (ITGCs), including Access Management, Privileged Access Management, Change Management, System Development Lifecycle (SDLC), Information Produced by the Entity (IPE), Technology Operations, Automated Controls, and Cloud and Infrastructure Controls.
  • Lead and perform technology risk and control assessments across critical applications, infrastructure platforms, cybersecurity processes, cloud environments, and technology-enabled business services.
  • Drive control design reviews, control effectiveness assessments, maturity evaluations, and control optimization initiatives to improve the overall technology control environment.
  • Partner with technology executives, application owners, and control owners to identify , assess, and remediate control deficiencies, audit findings, and regulatory issues through sustainable corrective action plans.
  • Advis e on complex remediation programs, including root cause analysis, corrective action planning, issue governance, and validation of remediation effectiveness.
  • Serve as the primary liaison for External Audit, Internal Audit, Compliance, and Risk Management functions by coordinating audit activities, leading walkthroughs, challenging audit observations when appropriate , and ensuring timely delivery of evidence and management responses.
  • Monitor and advise on SOX and SOC scoping activities, application onboarding, impact assessments, control changes, and implementation of new regulatory or audit requirements.
  • Support Control Officers in executive reporting, issue tracking and resolution, key risk indicator reporting, and risk appetite monitoring.
  • Review and challenge risk assessments, control documentation, management assertions, testing results, and deliverables prepared by team members and third-party partners.
  • Influence behaviors to reduce risk and foster a strong technology risk management culture throughout the enterprise.
  • Identify opportunities to enhance control monitoring, analytics, automation, and continuous assurance capabilities.
Your Knowledge and Skills:
  • Deep expertise in SOX, SOC 1, and SOC 2 compliance programs within complex technology environments.
  • Significant experience executing risk assessments, control effectiveness assessments, inherent risk evaluations, and residual risk assessments.
  • Significant experience evaluating and testing controls across technology domains including Identity and Access Management, Cloud Governance, Change Management, Software Development Lifecycle, Cybersecurity Operations, Vendor Risk Management, Technology Governance, Infrastructure and Platform Services, Information Security, and IT Asset Management.
  • Excellent executive presentation skills, including preparation and delivery of materials for senior leadership, governance committees, and regulatory audiences.
  • Excellent written and verbal communication skills with the ability to influence and challenge senior stakeholde rs.
  • Significant experience developing and implementing Technology Risk and Control Frameworks, Risk and Control Matrices, and control monitoring programs.
  • Extensive experience managing relationships with External Auditors, Internal Audit, Compliance, and 2LOD Risk Management functions.
  • Proven ability to lead large-scale remediation initiatives, including root cause analysis, corrective action planning, and sustainable control implementation.
  • Strong understanding of industry frameworks and standards including COSO, COBIT, NIST, SOX, SOC 1, and SOC 2.
  • Experience leveraging governance, risk, and compliance (GRC) platforms and workflow tools such as Archer, ServiceNow, AuditBoard , Power BI, or equivalent technologies.
Knowledge:

Recognized subject matter expert in Technology Risk Management, IT Controls, Audit, and Regulatory Compliance. Possesses extensive knowledge of technology control frameworks, financial reporting controls, information security principles, and risk management practices.

Demonstrates exceptional leadership, consultative, analytical, and communication capabilities with a proven ability to influence senior executives, technology leadership, auditors, regulators, and business stakeholders. Exercises independent judgment and leads highly visible, complex initiatives with enterprise-wide impact.

Experience:
  • Bachelor's degree in Computer Science , Information Systems, Cybersecurity, Accounting, Finance, or a related discipline.
  • Minimum 10 years of progressive experience in Technology Risk Management, IT Audit, Information Security Risk Management, SOX / SOC Compliance, Technology Controls, or related fields.
  • Minimum 5 years of experience leading enterprise-wide SOX, SOC, IT Controls, or Technology Risk programs within highly regulated organizations, preferably in financial services.
  • Demonstrated experience influencing senior technology executives and driving risk-based decision-making across large organizations.
  • Significant experience serving as the primary liaison with external auditors, including KPMG, PwC, EY, Deloitte, or equivalent, and leading audit readiness and remediation activities.
  • Proven track record leading complex, cross-functional remediation programs involving senior stakeholders and executive visibility.
  • Experience managing global teams, consultants, and third-party service providers.
Certifications:
  • Relevant industry recognized certification preferred, such as : Certified Information Systems Auditor (CISA ) ; Certified Information Systems Security Professional (CISSP) ; Certified in Risk and Information Systems Control (CRISC); Certified Internal Auditor (CIA); Certified Public Accountant (CPA)
Salary Range:

$95,600 - 162,400 USD

Salary range is a good faith estimate of base pay. Northern Trust provides a comprehensive benefits package including retirement benefits (401k and pension), health and welfare benefits (medical, dental, vision, spending accounts and disability), paid time off, parental and caregiver leave, life & accident insurance, and other voluntary and well-being benefits. Northern Trust also provides a discretionary bonus program that may include an equity component.

Work Authorization

Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. Northern Trust will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa).

Working with Us

As a Northern Trust partner, you will be part of a flexible and collaborative work culture, which has a strong history of financial strength and stability. Movement within the organization is encouraged, senior leaders are accessible, and you can take pride in working for a company committed to an inclusive workplace and assisting the communities we serve.

Philanthropy is deeply rooted in Northern Trust's history and is an essential element of our culture. Employees around the world give their time and talent to work for the greater good of their communities.

Reasonable Accommodation

Northern Trust is committed to working with and providing adjustments to individuals with health conditions and disabilities. If you need a reasonable accommodation for any part of the employment process, please email our HR Service Center at MyHRHelp@ntrs.com , or alternatively you can discuss your individual requirements with the recruiter you are working with.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Lead, Technology Risk & Controls - SOX / SOC Programs
Senior Lead, Technology Risk & Controls - SOX / SOC Programs

Northern Trust • Chicago (IL)

On-site
USD 140,000 - 230,000
Retirement benefits (401k)
Health and welfare benefits
Paid time off
+3
Strategy and Reporting Lead - Global Financial Controls
Strategy and Reporting Lead - Global Financial Controls

Northern Trust • Chicago (IL)

Hybrid
USD 115,000 - 195,000
Senior Lead, Technology Risk & Controls - SOX / SOC Programs
Senior Lead, Technology Risk & Controls - SOX / SOC Programs

Northern Trust Corp • Chicago (IL)

Hybrid
USD 95,000 - 163,000
2LOD Control Testing Senior Associate
2LOD Control Testing Senior Associate

Koitecc Solutions • Tempe (AZ), Northern (KY)

Hybrid
USD 70,000 - 120,000
2LOD Control Testing Senior Associate
2LOD Control Testing Senior Associate

Northern Trust • Tempe (AZ)

On-site
USD 70,000 - 120,000
401k and pension
Medical, dental, vision benefits
Paid time off and parental leave
Senior Lead, Technology Risk and Control
Senior Lead, Technology Risk and Control

Northern Trust Corp • Chicago (IL), Northern (KY)

Hybrid
USD 96,000 - 162,000
401(k) plan and pension
Health care (medical, dental, vision)
Paid time off
+3
Head of Operations - NTAM Technology
Head of Operations - NTAM Technology

Koitecc Solutions • Chicago (IL), Northern (KY)

Hybrid
USD 206,000 - 360,000
Senior Lead, Technology Risk and Control
Senior Lead, Technology Risk and Control

Northern Trust • Chicago (IL)

On-site
USD 96,000 - 162,000
Discretionary bonus
Equity component
Principal, GRC Cyber Risk Management
Principal, GRC Cyber Risk Management

Koitecc Solutions • Tempe (AZ), Northern (KY)

Hybrid
USD 109,000 - 185,000
Director, Finance Technology
Director, Finance Technology

Northern Trust • Chicago (IL)

On-site
USD 165,000 - 288,000
401(k) and pension benefits
Comprehensive health coverage
Paid time off and parental leave