About this role
About Northern Trust
As a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world’s most successful individuals, families, corporations and institutions.
Since 1889, we have aligned our efforts with our three guiding Principles That Endure: Service, Expertise, and Integrity. Together, they reflect the three cornerstones of business conduct which we strive to instill in our employees, whom we call partners, and to provide to our clients and the communities we serve worldwide.
With more than 135 years of financial experience and over 24,000 partners, we serve the world’s most sophisticated clients using leading technology and exceptional service.
Join a global leader in Cyber innovation where your expertise will give you the opportunity to shape the future of cyber defense for a global financial organisation. This is an exciting role responsible for leading Cyber solution development, lead complex cyber incident investigations and provide technical leadership to the team.
This role offers a unique platform to make a visible and lasting impact, combining hands-on leadership with strategic influence, while mentoring and developing the next generation of cybersecurity professionals.
You will work at the intersection of operations, innovation, and governance, partnering with senior stakeholders, security architects, and industry-leading technology providers to deliver next-generation security capabilities.
This role will serve as a senior escalation point for security incidents and function as an Incident Response Commander for significant cybersecurity events.
Job Responsibilities
· Lead strategic cybersecurity initiatives that enhance Security Operations and Incident Response capabilities. Such as driving improvements in cyber posture using Microsoft solutions.
· Lead in responding and protecting against identity-related threats, including emerging AI threats.
· Provide advanced technical analysis of security events and emerging threats.
· Act as the primary or deputy Incident Commander during major cyber security incidents.
· Guide analysts through complex investigations using SIEM, EDR, identity, cloud, and network telemetry.
· Partner with Detection Engineering to identify monitoring gaps and improve detection coverage across MITRE ATT&CK tactics and techniques.
· Evaluate new security products, capabilities, and emerging technologies.
· Challenge vendors on detection effectiveness, operational performance, roadmap priorities, and service delivery.
Team Leadership & Mentoring
· Act as a senior technical mentor for Tier 1, Tier 2, and Tier 3 analysts.
· Provide quality reviews of investigations, incident reports, and post-incident analyses.
· Identify opportunities for automation, orchestration, and workflow optimization.
· Promote consistency in investigative methodologies and operational excellence.
· Lead cyber exercises/training, tabletop simulations, and post-incident reviews.
· Validate investigative findings and response recommendations before escalation to leadership.
· Develop and maintain incident response playbooks, runbooks, and operating procedures.
· Drive lessons learned activities following major incidents.
Stakeholder Engagement
· Act as the Security Operations lead representative within technology governance processes. Review proposed technology solutions, architectures, cloud services, and third-party integrations to ensure alignment with Security Operations processes.
· Partner with Cyber Threat Intelligence, Threat Hunting, Detection Engineering, Infrastructure, IAM, Cloud Security, and Risk teams.
· Provide executive-ready updates during major cyber incidents.
· Support and drive metric collection and reporting for operational and leadership review.
Ideal Qualifications and Skills
· Proven experience leading technical investigations and developing Cyber defence capabilities.
· Strong understanding of:
o Malware Analysis
o Threat Hunting
o Identity Security
o Endpoint Detection and Response
o Cloud Security (Azure/AWS)
o Network Security
o Digital Forensics
· Bachelor's degree in Cybersecurity, Information Security, Computer Science, or related field. Relevant Industry certifications.
· Experience with triage and developing detections on SIEM and XDR platforms. such as Microsoft Sentinel, Defender XDR, Splunk, CrowdStrike, or equivalent.
· Experience with developing automation/AI and SOAR platforms.
· Familiarity with MITRE ATT&CK, threat intelligence, and detection engineering.
Work Authorization
Applicants must have the right to work in Ireland at the time of application and for the duration of employment.
Please note that Northern Trust is unable to provide employment permit sponsorship for this role. This includes Critical Skills Employment Permits, General Employment Permits, Intra-Company Transfer Employment Permits, Stamp 1G permissions, and other employment permits under Irish immigration frameworks.
Working with Us
As a Northern Trust partner, you will be part of a flexible and collaborative work culture, which has a strong history of financial strength and stability. Movement within the organization is encouraged, senior leaders are accessible, and you can take pride in working for a company committed to an inclusive workplace and assisting the communities we serve.
Philanthropy is deeply rooted in Northern Trust’s history and is an essential element of our culture. Employees around the world give their time and talent to work for the greater good of their communities.
Reasonable Accommodation
Northern Trust is committed to working with and providing adjustments to individuals with health conditions and disabilities. If you need a reasonable accommodation for any part of the employment process, please email our HR Service Center at [email protected] , or alternatively you can discuss your individual requirements with the recruiter you are working with.