About Northern Trust
As a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world’s most successful individuals, families, corporations and institutions.
Since 1889, we have aligned our efforts with our three guiding Principles That Endure: Service, Expertise, and Integrity. Together, they reflect the three cornerstones of business conduct which we strive to instill in our employees, whom we call partners, and to provide to our clients and the communities we serve worldwide.
With more than 135 years of financial experience and over 24,000 partners, we serve the world’s most sophisticated clients using leading technology and exceptional service.
The Senior Lead Validator is accountable for leading the independent validation and effective challenge of material cybersecurity models, analytical tools, detection systems, and AI-enabled security solutions used across the organization. The role serves as a senior subject matter expert at the intersection of Cybersecurity Risk and Model Risk Management, covering threat detection, behavioral and anomaly analytics, identity and access risk, vulnerability and cyber risk scoring, Generative AI, Agentic AI, and other intelligent security solutions.
The role provides strategic direction for cybersecurity model validation, shapes risk-based validation standards, and influences senior management and governance decisions. It also supports the evolution of the Model Risk Management framework to address cybersecurity analytics, adversarial threats, rapidly changing attack patterns, and emerging AI security risks.
The key responsibilities of the role include:
Cybersecurity Model Validation and Independent Challenge
- Lead and oversee independent validations of material cybersecurity models, security analytics, detection systems, machine learning models, Generative AI, Agentic AI, and other intelligent security solutions.
- Determine validation scope and depth using model materiality, cybersecurity impact, level of automation, data sensitivity, adversarial exposure, and potential consequences of model failure.
- Assess conceptual soundness, design, data quality, assumptions, limitations, implementation, performance, monitoring, change management, and governance.
- Provide authoritative challenge to model owners, developers, security engineers, and senior technology stakeholders on methodology, testing, controls, thresholds, residual risk, and fitness for purpose.
- Approve or recommend validation conclusions, risk ratings, limitations, compensating controls, and remediation priorities in accordance with Model Risk Management standards.
- Lead complex or high-risk reviews and provide direction, technical guidance, and quality oversight to other validators.
Cybersecurity Model Risk Assessment
- Evaluate false-positive and false-negative risk, detection gaps, model uncertainty, security telemetry limitations, drift, changing attacker behavior, and alignment between model performance and cybersecurity outcomes.
- Assess adversarial manipulation, model evasion, data poisoning, prompt injection, insecure tool use, excessive agency, and other relevant AI security risks.
- Evaluate explainability, traceability, human oversight, escalation, fallback arrangements, third-party dependencies, and monitoring effectiveness.
- Assess robustness and resilience under degraded, abnormal, and hostile operating conditions, including whether limitations could impair prevention, detection, prioritization, or response decisions.
Framework, Governance, and Thought Leadership
- Own or lead the development of scalable validation methodologies, testing expectations, and review standards for cybersecurity analytics and AI-enabled security systems.
- Advise on the identification, classification, materiality assessment, and risk tiering of cybersecurity models and analytical tools.
- Identify cross-cutting and emerging cybersecurity model risks, communicate portfolio-level themes, and recommend enhancements to governance, monitoring, and control frameworks.
- Monitor regulatory expectations, industry practices, threat developments, and advances in cybersecurity analytics and AI security, translating them into Model Risk Management requirements.
- Provide senior-level guidance on complex judgments, validation disputes, model limitations, and risk acceptance or escalation decisions.
Senior Stakeholder Engagement
- Partner with senior leaders across Model Risk Management, Cyber Risk, Information Security, Security Operations, Technology Risk, AI Risk, Operational Risk, Internal Audit, and Technology.
- Present validation conclusions, material risks, thematic observations, and remediation priorities to senior management and relevant governance committees.
- Influence model owners and technology leaders to address material weaknesses and strengthen cybersecurity model governance.
- Lead support for regulatory examinations, internal audits