About Northern Trust :
Northern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution that has been in continuous operation since 1889.
Northern Trust is proud to provide innovative financial services and guidance to the world’s most successful individuals, families, and institutions by remaining true to our enduring principles of service, expertise, and integrity. With more than 130 years of financial experience and over 22,000 partners, we serve the world’s most sophisticated clients using leading technology and exceptional service.
Title : Lead Security Architect
Description
- Serve as subject matter expert in Application Security Architecture space
- Partner with Application teams and provide consultation that can help secure their CI / CD implementation
- As an SME in DevSecOps space, provide security architecture guidance in selection of appropriate tools
- Provide security guidance that can help accelerate the application migrations to cloud
- Partner with application teams to ensure ‘secure by design’ principles are followed as they modernize their applications
- Carries out complex initiatives involving multiple disciplines and / or ambiguous projects
- Evaluates and selects from existing and emerging technologies those options best fitting business / project needs
- Promotes sharing of expertise through consulting, presentations, and documentations, etc.
- Thoroughly understands decision process issues of technology choice, such as design, data security, client server communication, etc.
- Experienced, functional expert with technical and / or business knowledge and functional expertise
- Guides the development, specification and communication of application or infrastructure architectures used by multiple business or application systems.
Qualifications
Bachelor's degree and experience in information security, or an equivalent combination of education and work experience.Excellent consultative and communication skills, and the ability to work effectively with client, partner, and IT management and staff.Six years of industry experience with the combination of main stream Information Security role and application development is preferredCISSP, CISM, or Security+ certification preferredStrong collaboration skills and analytical abilityDeep knowledge of application or infrastructure systems architecture, usually having experience with multiple system technologies.Requirements / Responsibilities -
Experience related to application development and DevOpsVery good understanding of CI / CD pipeline and secure application development methodologiesExperience with security tools related to DevSecOps- SAST, DAST, IASTIn-depth knowledge of various cybersecurity frameworks, standards, and SSDLCExperience related to vulnerability management is big plusMust have very good understanding related to OWASP top vulnerabilities and knowledge related to MITRE frameworkKnowledge related to WAF, App Proxy, and CDNVery good understanding of zero-trust architecture and working experience with relevant tools / technologiesGood understanding related to IPS / IDS, Network load balancer, firewalls, Z-Scaler, and networking technologiesKnowledge related AI / ML, DevSecOps, CI / CD Pipeline, IaC, and relevant toolsExperience in dealing with threat vectors and develop relevant plans to protect the organization from cyber threatsLead the security architecture reviews and provide analysis with the observations and findingsExperience in providing security consultation to application teamsKnowledge of network architecture concepts including topology, protocols, and componentsUnderstanding related to SEIM and experience related to Microsoft Defender, Entra, KQL, APIM, endpoint protection, scripting, CoPilotKnowledge related to Privilege access management, Threat hunting, data protection, encryption, Authentication / Authorization, Vulnerability management systems, Cloud Security Posture Management.Very good understanding of concepts related to docker, container, serverless computing, and KubernetesMust be able to represent the security architecture team in technical discussions and drive towards deliverables with minimal guidance