1

Director Technology Risk Management Jobs in Oswego, IL

Essential Functions * Assist Sr. Risk Managers and LOD1 Director if meeting departmental goals and objectives. * Build and manage the business line's centralized LOD1 function; act as business-line ...

Chief Risk Officer

Chicago, IL ยท On-site

$150 - $200/hr

... technology, alongside a superior customer experience. We believe the foundation to our success is ... Senior risk leader with 7+ years of senior experience in risk management, ideally within ...

Showing results 21-40

Director Technology Risk Management information

See Oswego, IL salary details

$51.4K

$136.2K

$247.3K

How much do director technology risk management jobs pay per year?

As of Aug 8, 2026, the average yearly pay for director technology risk management in Oswego, IL is $136,187.00, according to ZipRecruiter salary data. Most workers in this role earn between $100,300.00 and $159,300.00 per year, depending on experience, location, and employer.

What does a director of technology risk management do?

A Director of Technology Risk Management is responsible for identifying, assessing, and mitigating technology-related risks within an organization. They develop and implement policies, frameworks, and strategies to ensure that IT systems and processes comply with regulatory requirements and best practices. Their work helps protect the company's data, assets, and reputation from threats such as cyberattacks, data breaches, and system failures. They also collaborate with other departments to promote a culture of risk awareness and provide guidance on risk-related matters.

How does a director of technology risk management typically collaborate with other departments to ensure effective risk mitigation?

A Director of Technology Risk Management works closely with IT, compliance, legal, and business operations teams to identify and address technology risks. This involves leading cross-functional risk assessments, facilitating communication between technical and non-technical stakeholders, and ensuring that risk mitigation strategies align with organizational goals. Regular meetings, workshops, and reporting structures are established to maintain transparency and drive a culture of risk awareness across departments. Effective collaboration is essential for implementing controls and responding proactively to emerging threats.

What are the key skills and qualifications needed to thrive as a director of technology risk management, and why are they important?

To excel as a Director of Technology Risk Management, a strong background in information security, risk assessment, regulatory compliance, and a relevant degree such as in computer science or information systems is essential. Familiarity with risk management frameworks (such as NIST, ISO 27001), GRC (Governance, Risk, and Compliance) platforms, and certifications like CISSP or CISM are commonly required. Leadership, strategic thinking, and effective communication skills are vital for driving risk initiatives and collaborating across business units. These competencies ensure robust risk mitigation, regulatory adherence, and alignment of technology strategies with organizational goals.

What is the difference between Director Technology Risk Management vs Cybersecurity Manager?

AspectDirector Technology Risk ManagementCybersecurity Manager
Primary FocusOverseeing technology risk strategies and enterprise risk mitigationManaging cybersecurity operations and security measures
CertificationsCRISC, CISSP, CISMCISSP, CISA, CEH
Work EnvironmentStrategic, cross-departmental, executive levelOperational, technical teams, security operations centers
Industry UsageFinancial, healthcare, large enterprisesIT security firms, corporate IT departments

The main difference is that the Director Technology Risk Management focuses on broad technology risk strategies across the organization, while the Cybersecurity Manager concentrates on implementing and managing cybersecurity measures. Both roles require similar certifications but differ in scope and strategic versus operational responsibilities.

What job categories do people searching Director Technology Risk Management jobs in Oswego, IL look for? The top searched job categories for Director Technology Risk Management jobs in Oswego, IL are:
What cities near Oswego, IL are hiring for Director Technology Risk Management jobs? Cities near Oswego, IL with the most Director Technology Risk Management job openings:
Infographic showing various Director Technology Risk Management job openings in Oswego, IL as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 13% Part Time, and 3% Contract. Highlights an 87% Physical, 3% Hybrid, and 10% Remote job distribution, with an average salary of $136,187 per year, or $65.5 per hour.

Senior Lead, Technology Risk & Controls - SOX / SOC Programs

001 The Northern Trust Company

Chicago, IL โ€ข On-site

$83K - $102K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

This job post hasย expired today.ย Applications are no longer accepted.


Job description

Senior Lead, Technology Risk & Controls โ€“ SOX / SOC Programs Senior Lead, Technology Risk & Controls โ€“ SOX / SOC Programs. You will join Northern Trust's Technology Risk and Control team as a leader responsible for overseeing the Technology SOX and SOC (SOC 1 / SOC 2) control programs across a global technology environment. This role partners closely with Technology leadership, Control Officers, Compliance, Internal Audit, External Audit, and Second Line of Defense (2LOD) partners to ensure the design, implementation, monitoring, and continuous improvement of technology controls supporting regulatory, financial reporting, and client assurance requirements. Responsibilities Represent the Technology organization as the liaison for global SOX and SOC report issuance, ensuring effective governance, control execution, audit readiness, and regulatory compliance. Serve as the subjectโ€matter expert for Information Technology General Controls (ITGCs) across key domains such as Access Management, Privileged Access Management, Change Management, SDLC, IPE, Technology Operations, Automated Controls, Cloud, and Infrastructure Controls. Lead and perform technology risk and control assessments across critical applications, infrastructure platforms, cybersecurity processes, cloud environments, and technologyโ€enabled business services. Drive control design reviews, effectiveness assessments, maturity evaluations, and optimization initiatives to improve the overall technology control environment. Partner with technology executives, application owners, and control owners to identify, assess, and remediate control deficiencies, audit findings, and regulatory issues through sustainable correctiveโ€action plans. Advise on complex remediation programs, including rootโ€cause analysis, corrective action planning, issue governance, and validation of remediation effectiveness. Serve as the primary liaison for External Audit, Internal Audit, Compliance, and Risk Management functions by coordinating audit activities, leading walkthroughs, challenging audit observations, and ensuring timely delivery of evidence and management responses. Monitor and advise on SOX and SOC scoping activities, application onboarding, impact assessments, control changes, and implementation of new regulatory or audit requirements. Support Control Officers in executive reporting, issue tracking and resolution, key risk indicator reporting, and riskโ€appetite monitoring. Review and challenge risk assessments, control documentation, management assertions, testing results, and deliverables prepared by team members and thirdโ€party partners. Influence behaviors to reduce risk and foster a strong technology riskโ€management culture throughout the enterprise. Identify opportunities to enhance control monitoring, analytics, automation, and continuous assurance capabilities. Knowledge & Skills Deep expertise in SOX, SOC1, and SOC2 compliance programs within complex technology environments. Significant experience executing risk assessments, controlโ€effectiveness assessments, inherent risk evaluations, and residual risk assessments. Extensive experience evaluating and testing controls across technology domains including Identity and Access Management, Cloud Governance, Change Management, Software Development Lifecycle, Cybersecurity Operations, Vendor Risk Management, Technology Governance, Infrastructure and Platform Services, Information Security, and IT Asset Management. Excellent executive presentation skills, including preparation and delivery of materials for senior leadership, governance committees, and regulatory audiences. Exceptional written and verbal communication skills with the ability to influence and challenge senior stakeholders. Proven ability to develop and implement Technology Risk and Control Frameworks, Risk and Control Matrices, and control monitoring programs. Strong understanding of industry frameworks and standards including COSO, COBIT, NIST, SOX, SOC1, and SOC2. Experience leveraging governance, risk, and compliance (GRC) platforms and workflow tools such as Archer, ServiceNow, AuditBoard, PowerBI, or equivalent technologies. Experience & Education Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Accounting, Finance, or a related discipline. Minimum 10 years of progressive experience in Technology Risk Management, IT Audit, Information Security Risk Management, SOX / SOC Compliance, Technology Controls, or related fields. Minimum 5 years of experience leading enterpriseโ€wide SOX, SOC, IT Controls, or Technology Risk programs within highly regulated organizations, preferably in financial services. Demonstrated experience influencing senior technology executives and driving riskโ€based decisionโ€making across large organizations. Significant experience serving as the primary liaison with external auditors (KPMG, PwC, EY, Deloitte, or equivalent) and leading audit readiness and remediation activities. Proven track record leading complex, crossโ€functional remediation programs involving senior stakeholders and executive visibility. Experience managing global teams, consultants, and thirdโ€party service providers. Certifications Certified Information Systems Auditor (CISA) Certified Information Systems Security Professional (CISSP) Certified in Risk and Information Systems Control (CRISC) Certified Internal Auditor (CIA) Certified Public Accountant (CPA) Salary Range $95,600 โ€“ $162,400 USD (base pay). Benefits Retirement benefits: 401(k) and pension. Health and welfare benefits: medical, dental, vision, spending accounts, and disability insurance. Paid time off, parental and caregiver leave. Life & accident insurance and other voluntary wellโ€being benefits. Discretionary bonus program that may include an equity component. Work Authorization Applicants must be authorized to work in the U.S. without the need for employmentโ€based visa sponsorship now or in the future. Northern Trust will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for Hโ€1B, Lโ€1, TN, Oโ€1, Eโ€3, Hโ€1B1, Fโ€1, Jโ€1, OPT, CPT or any other employmentโ€based visa). Equal Employment Opportunity It is the policy and practice of Northern Trust to provide equal employment opportunities to all employees and applicants. Northern Trust does not discriminate on the basis of race, colour, religion, belief, nationality, ethnic or national origin, sex, marital status, sexual orientation, disability, or age. All employment decisions are made in a nonโ€discriminatory manner in accordance with applicable laws and codes of practice. #J-18808-Ljbffr