Senior Lead, Security Engineering and Operations

Northern TrustChicago, IllinoisOn-siteFull-timeSenior, 5–8 yearsListed 1 hour ago

Apply now

About this role

About Northern Trust

As a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world’s most successful individuals, families, corporations and institutions.

Since 1889, we have aligned our efforts with our three guiding Principles That Endure: Service, Expertise, and Integrity. Together, they reflect the three cornerstones of business conduct which we strive to instill in our employees, whom we call partners, and to provide to our clients and the communities we serve worldwide.

With more than 135 years of financial experience and over 24,000 partners, we serve the world’s most sophisticated clients using leading technology and exceptional service.

The Senior Lead, Security Engineer is an experienced individual contributor responsible for engineering and operationalizing enterprise security platforms across Northern Trust. This role combines hands-on platform delivery with technical ownership for reliable, auditable and scalable security capabilities. It suits an engineer who can work across architecture discussions, implementation planning, operational support and deep technical troubleshooting while partnering effectively with engineering, infrastructure, application and risk stakeholders.

What You'll Do

Security Platform Engineering Across Key Domains

- Contribute technical expertise to security platform engineering decisions and operational governance.

- Design, engineer and operate security tools spanning zero-trust, SASE/SSE, network, vulnerability & exposure management, AI guardrails, and SaaS.

- Apply engineering patterns, implementation standards and operational runbooks that support consistent adoption across business units and technology teams.

- Develop maturity models and metrics to measure assurance and compliance.
- Partner with engineering, infrastructure and application teams on cross-functional security initiatives

Key Deliverables

- Design, Engineer, Coordinate and Operate:

- Intrusion prevention(IPS) across next-gen firewalls

- Vulnerability scanning platforms and unified vulnerability management(UVM) layer

- Enterprise SASE / SSE security platforms

- Secure web gateway, CASB, and cloud access protection

- SaaS application protection and monitoring

- Secure remote access and internet traffic inspection

- Browser isolation and modern web threat prevention

- AI gateway controls that govern how users and applications consume LLMs and AI services

- ServiceNow integrations (Vulnerability Response, ITSM, CMDB)

###

- Support technical outcomes for platform health, upgrades, capacity, resilience, lifecycle management and vendor escalations across the stack.

- Define and publish metrics on coverage, control effectiveness, SLA adherence, tool health, control performance and measurable risk reduction.

- Support audits and regulatory exams (PCI-DSS, SOX, GLBA, OCC/FFIEC) by ensuring controls are designed for evidence quality, traceability and repeatable operation.

- Author runbooks and executive-ready documentation that can be used by engineering, operations, risk and audit stakeholders.

- Evaluate new capabilities, proofs of concept and tool rationalization opportunities, with recommendations based on risk reduction, operational fit, cost and control outcomes.

What You'll Bring

- Typically 12+ years of experience in information technology, cybersecurity, cloud, infrastructure, network security or platform engineering, with hands-on experience supporting enterprise-scale security platforms.
- Ability to operate as an experienced technical contributor: making sound tradeoffs across security, reliability, usability and compliance while helping drive alignment on technical decisions.

- Deep hands-on experience with at least one SSE/SASE platform, including ZTNA, secure web gateway policy, segmentation, connector architecture and operating model design.

- Working knowledge of IPS/next-gen firewall platforms and signature tuning.

- Strong networking fundamentals: TCP/IP, routing, DNS, TLS/PKI, proxies and tunneling (IPsec/GRE), and segmentation.

- Experience with vulnerability management tooling.

- Familiarity with identity integration: SAML/OIDC, Entra ID, conditional access.

- Scripting and API skills (Python, PowerShell, REST/JSON).

- Experience integrating security tools with ServiceNow, SIEM platforms and enterprise reporting workflows.

- Strong communication skills, including the ability to document technical decisions, support audit inquiries and collaborate with stakeholders across engineering, operations, risk and audit.

- Experience working in a regulated environment with control evidence, operational resilience, risk acceptance, issue management and audit/regulatory response expectations.

#

Nice to Have

- Exposure to AI/LLM security controls:

- AI gateways

- Prompt-injection defenses

- OWASP Top 10 for LLM Applications

- MITRE ATLAS

- ServiceNow Vulnerability Response or USEM implementation experience.

- Low-code automation or Terraform/IaC.

Salary Range:
$114,500 - 194,700 USD

Salary range is a good faith estimate of base pay. Northern Trust provides a comprehensive benefits package including retirement benefits (401k and pension), health and welfare benefits (medical, dental, vision, spending accounts and disability), paid time off, parental and caregiver leave, life & accident insurance, and other voluntary and well-being benefits. Northern Trust also provides a discretionary bonus program that may include an equity component.

Work Authorization

Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. Northern Trust will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa).

Working with Us

As a Northern Trust partner, you will be part of a flexible and collaborative work culture, which has a strong history of financial strength and stability. Movement within the organization is encouraged, senior leaders are accessible, and you can take pride in working for a company committed to an inclusive workplace and assisting the communities we serve.

Philanthropy is deeply rooted in Northern Trust’s history and is an essential element of our culture. Employees around the world give their time and talent to work for the greater good of their communities.

Reasonable Accommodation

Northern Trust is committed to working with and providing adjustments to individuals with health conditions and disabilities. If you need a reasonable accommodation for any part of the employment process, please email our HR Service Center at [email protected] , or alternatively you can discuss your individual requirements with the recruiter you are working with.