Senior Lead, Technology Risk & Controls โ SOX / SOC Programs Senior Lead, Technology Risk & Controls โ SOX / SOC Programs. You will join Northern Trust's Technology Risk and Control team as a leader responsible for overseeing the Technology SOX and SOC (SOC 1 / SOC 2) control programs across a global technology environment. This role partners closely with Technology leadership, Control Officers, Compliance, Internal Audit, External Audit, and Second Line of Defense (2LOD) partners to ensure the design, implementation, monitoring, and continuous improvement of technology controls supporting regulatory, financial reporting, and client assurance requirements. Responsibilities Represent the Technology organization as the liaison for global SOX and SOC report issuance, ensuring effective governance, control execution, audit readiness, and regulatory compliance. Serve as the subjectโmatter expert for Information Technology General Controls (ITGCs) across key domains such as Access Management, Privileged Access Management, Change Management, SDLC, IPE, Technology Operations, Automated Controls, Cloud, and Infrastructure Controls. Lead and perform technology risk and control assessments across critical applications, infrastructure platforms, cybersecurity processes, cloud environments, and technologyโenabled business services. Drive control design reviews, effectiveness assessments, maturity evaluations, and optimization initiatives to improve the overall technology control environment. Partner with technology executives, application owners, and control owners to identify, assess, and remediate control deficiencies, audit findings, and regulatory issues through sustainable correctiveโaction plans. Advise on complex remediation programs, including rootโcause analysis, corrective action planning, issue governance, and validation of remediation effectiveness. Serve as the primary liaison for External Audit, Internal Audit, Compliance, and Risk Management functions by coordinating audit activities, leading walkthroughs, challenging audit observations, and ensuring timely delivery of evidence and management responses. Monitor and advise on SOX and SOC scoping activities, application onboarding, impact assessments, control changes, and implementation of new regulatory or audit requirements. Support Control Officers in executive reporting, issue tracking and resolution, key risk indicator reporting, and riskโappetite monitoring. Review and challenge risk assessments, control documentation, management assertions, testing results, and deliverables prepared by team members and thirdโparty partners. Influence behaviors to reduce risk and foster a strong technology riskโmanagement culture throughout the enterprise. Identify opportunities to enhance control monitoring, analytics, automation, and continuous assurance capabilities. Knowledge & Skills Deep expertise in SOX, SOC1, and SOC2 compliance programs within complex technology environments. Significant experience executing risk assessments, controlโeffectiveness assessments, inherent risk evaluations, and residual risk assessments. Extensive experience evaluating and testing controls across technology domains including Identity and Access Management, Cloud Governance, Change Management, Software Development Lifecycle, Cybersecurity Operations, Vendor Risk Management, Technology Governance, Infrastructure and Platform Services, Information Security, and IT Asset Management. Excellent executive presentation skills, including preparation and delivery of materials for senior leadership, governance committees, and regulatory audiences. Exceptional written and verbal communication skills with the ability to influence and challenge senior stakeholders. Proven ability to develop and implement Technology Risk and Control Frameworks, Risk and Control Matrices, and control monitoring programs. Strong understanding of industry frameworks and standards including COSO, COBIT, NIST, SOX, SOC1, and SOC2. Experience leveraging governance, risk, and compliance (GRC) platforms and workflow tools such as Archer, ServiceNow, AuditBoard, PowerBI, or equivalent technologies. Experience & Education Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Accounting, Finance, or a related discipline. Minimum 10 years of progressive experience in Technology Risk Management, IT Audit, Information Security Risk Management, SOX / SOC Compliance, Technology Controls, or related fields. Minimum 5 years of experience leading enterpriseโwide SOX, SOC, IT Controls, or Technology Risk programs within highly regulated organizations, preferably in financial services. Demonstrated experience influencing senior technology executives and driving riskโbased decisionโmaking across large organizations. Significant experience serving as the primary liaison with external auditors (KPMG, PwC, EY, Deloitte, or equivalent) and leading audit readiness and remediation activities. Proven track record leading complex, crossโfunctional remediation programs involving senior stakeholders and executive visibility. Experience managing global teams, consultants, and thirdโparty service providers. Certifications Certified Information Systems Auditor (CISA) Certified Information Systems Security Professional (CISSP) Certified in Risk and Information Systems Control (CRISC) Certified Internal Auditor (CIA) Certified Public Accountant (CPA) Salary Range $95,600 โ $162,400 USD (base pay). Benefits Retirement benefits: 401(k) and pension. Health and welfare benefits: medical, dental, vision, spending accounts, and disability insurance. Paid time off, parental and caregiver leave. Life & accident insurance and other voluntary wellโbeing benefits. Discretionary bonus program that may include an equity component. Work Authorization Applicants must be authorized to work in the U.S. without the need for employmentโbased visa sponsorship now or in the future. Northern Trust will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for Hโ1B, Lโ1, TN, Oโ1, Eโ3, Hโ1B1, Fโ1, Jโ1, OPT, CPT or any other employmentโbased visa). Equal Employment Opportunity It is the policy and practice of Northern Trust to provide equal employment opportunities to all employees and applicants. Northern Trust does not discriminate on the basis of race, colour, religion, belief, nationality, ethnic or national origin, sex, marital status, sexual orientation, disability, or age. All employment decisions are made in a nonโdiscriminatory manner in accordance with applicable laws and codes of practice. #J-18808-Ljbffr