The Director, Platform Security Engineering and Operations is a people leader responsible for defining and leading the strategy, governance, and execution of Northern Trust’s enterprise security platforms. This role sets direction for the team, establishes priorities, develops engineering and operations talent, and ensures delivery of secure, resilient and audit-ready platform outcomes. The Director must be able to guide technical strategy, remove execution barriers, influence cross-functional partners and translate complex security engineering work into clear risk, control and business outcomes for senior stakeholders.
What You'll DoLead Security Platform Engineering Teams
- Lead, coach and develop a team of security engineering individual contributors responsible for enterprise security platforms.
- Set technical and operational direction for security tools spanning zero-trust, SASE/SSE, network, vulnerability and exposure management, AI guardrails, and SaaS.
- Establish engineering standards, implementation patterns, operating models and runbook expectations that enable consistent execution across the team.
- Define team goals, maturity models and performance metrics that measure delivery, assurance, compliance and measurable risk reduction.
- Coordinate cross-functional security initiatives across engineering, infrastructure, application, risk, audit and operations teams.
Key Deliverables
- Lead the team accountable for designing, engineering, coordinating and operating:
- Intrusion prevention(IPS) across next-gen firewalls
- Vulnerability scanning platforms and unified vulnerability management(UVM) layer
- Enterprise SASE / SSE security platforms
- Secure web gateway, CASB, and cloud access protection
- SaaS application protection and monitoring
- Secure remote access and internet traffic inspection
- Browser isolation and modern web threat prevention
- AI gateway controls that govern how users and applications consume LLMs and AI services
- ServiceNow integrations (Vulnerability Response, ITSM, CMDB)
- Own team outcomes for platform health, upgrades, capacity, resilience, lifecycle management, vendor management and escalation across the stack.
- Define, review and communicate metrics on coverage, control effectiveness, SLA adherence, tool health, team throughput and measurable risk reduction.
- Ensure audit and regulatory support is delivered with strong evidence quality, traceability, repeatable operations and clear ownership across PCI-DSS, SOX, GLBA, OCC/FFIEC and related expectations.
- Review and approve engineering, operations and executive-ready documentation used by security engineering, operations, risk and audit stakeholders.
- Lead prioritization, investment recommendations, capability evaluations, proofs of concept and tool rationalization decisions based on risk reduction, operational fit, cost and control outcomes.
What You'll Bring
- 15+ years of experience in information technology, cybersecurity, cloud, infrastructure, network security or platform engineering, with +5 years of demonstrated leadership of enterprise-scale security teams or major security engineering programs.
- Proven people leadership capability: setting direction, developing talent, assigning work, managing priorities, coaching senior engineers and creating accountability for delivery and operational excellence.
- Deep expertise in vulnerability scanning, zero trust architecture, network security, SASE / SSE platforms and web security architectures.
- Excellent executive communication skills, including the ability to brief senior stakeholders, explain risk and control tradeoffs, support audit inquiries, and drive alignment across teams and leaders.
- Experience working in a regulated environment with control evidence, operational resilience, risk acceptance, issue management and audit/regulatory response expectations.
- Ability to balance strategic planning, operational execution, team capacity, stakeholder expectations and regulatory commitments in a complex enterprise environment.
Nice to Have
- Prior experience in financial services, banking, asset servicing, wealth management or another highly regulated industry.
- Prior experience leading globally distributed or matrixed engineering teams through platform modernization, tool consolidation or operating model transformation.
Salary Range:
$164,600 - 288,000 USD
Salary range is a good faith estimate of base pay. Northern Trust provides a comprehensive benefits package including retirement benefits (401k and pension), health and welfare benefits (medical, dental, vision, spending accounts and disability), paid time off, parental and caregiver leave, life & accident insurance, and other voluntary and well-being benefits. Northern Trust also provides a discretionary bonus program that may include an equity component.
Work Authorization
Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. Northern Trust will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa).
Working with Us
As a Northern Trust partner, you will be part of a flexible and collaborative work culture, which has a strong history of financial strength and stability. Movement within the organization is encouraged, senior leaders are accessible, and you can take pride in working for a company committed to an inclusive workplace and assisting the communities we serve.
Philanthropy is deeply rooted in Northern Trust’s history and is an essential element of our culture. Employees around the world give their time and talent to work for the greater good of their communities.