Full Job Description
The Senior Lead Validator is accountable for leading the independent validation and effective challenge of material cybersecurity models, analytical tools, detection systems, and AI-enabled security solutions used across the organization. The role serves as a senior subject matter expert at the intersection of Cybersecurity Risk and Model Risk Management, covering threat detection, behavioral and anomaly analytics, identity and access risk, vulnerability and cyber risk scoring, Generative AI, Agentic AI, and other intelligent security solutions.
The role provides strategic direction for cybersecurity model validation, shapes risk-based validation standards, and influences senior management and governance decisions. It also supports the evolution of the Model Risk Management framework to address cybersecurity analytics, adversarial threats, rapidly changing attack patterns, and emerging AI security risks.
The key responsibilities of the role include:
Cybersecurity Model Validation and Independent Challenge
• Lead and oversee independent validations of material cybersecurity models, security analytics, detection systems, machine learning models, Generative AI, Agentic AI, and other intelligent security solutions.
• Determine validation scope and depth using model materiality, cybersecurity impact, level of automation, data sensitivity, adversarial exposure, and potential consequences of model failure.
• Assess conceptual soundness, design, data quality, assumptions, limitations, implementation, performance, monitoring, change management, and governance.
• Provide authoritative challenge to model owners, developers, security engineers, and senior technology stakeholders on methodology, testing, controls, thresholds, residual risk, and fitness for purpose.
• Approve or recommend validation conclusions, risk ratings, limitations, compensating controls, and remediation priorities in accordance with Model Risk Management standards.
• Lead complex or high-risk reviews and provide direction, technical guidance, and quality oversight to other validators.
Cybersecurity Model Risk Assessment
• Evaluate false-positive and false-negative risk, detection gaps, model uncertainty, security telemetry limitations, drift, changing attacker behavior, and alignment between model performance and cybersecurity outcomes.
• Assess adversarial manipulation, model evasion, data poisoning, prompt injection, insecure tool use, excessive agency, and other relevant AI security risks.
• Evaluate explainability, traceability, human oversight, escalation, fallback arrangements, third-party dependencies, and monitoring effectiveness.
• Assess robustness and resilience under degraded, abnormal, and hostile operating conditions, including whether limitations could impair prevention, detection, prioritization, or response decisions.
Framework, Governance, and Thought Leadership
• Own or lead the development of scalable validation methodologies, testing expectations, and review standards for cybersecurity analytics and AI-enabled security systems.
• Advise on the identification, classification, materiality assessment, and risk tiering of cybersecurity models and analytical tools.
• Identify cross-cutting and emerging cybersecurity model risks, communicate portfolio-level themes, and recommend enhancements to governance, monitoring, and control frameworks.
• Monitor regulatory expectations, industry practices, threat developments, and advances in cybersecurity analytics and AI security, translating them into Model Risk Management requirements.
• Provide senior-level guidance on complex judgments, validation disputes, model limitations, and risk acceptance or escalation decisions.
Senior Stakeholder Engagement
• Partner with senior leaders across Model Risk Management, Cyber Risk, Information Security, Security Operations, Technology Risk, AI Risk, Operational Risk, Internal Audit, and Technology.
• Present validation conclusions, material risks, thematic observations, and remediation priorities to senior management and relevant governance committees.
• Influence model owners and technology leaders to address material weaknesses and strengthen cybersecurity model governance.
• Lead support for regulatory examinations, internal audits, and independent reviews involving cybersecurity models and AI-enabled security technologies.
The successful candidate will benefit from having:
Required
• Extensive experience in Model Risk Management, independent model validation, quantitative review, or independent technical risk assessment, including leadership of complex or material reviews.
• Strong knowledge of cybersecurity risk and the use of analytics, machine learning, and AI in security decision-making and control environments.
• Demonstrated ability to evaluate model performance, data quality, uncertainty, drift, explainability, monitoring, resilience, and human oversight.
• Ability to exercise independent judgment, provide credible challenge, resolve complex technical issues, and make risk-based recommendations to senior stakeholders.
• Strong leadership, analytical, written, verbal, and executive communication skills, with the ability to guide validators and influence across functions.
Preferred
• Experience validating cybersecurity models, detection analytics, identity and access risk models, vulnerability or cyber risk scoring, or AI-enabled security solutions.
• Knowledge of Security Operations, threat detection, behavioral analytics, adversarial machine learning, AI security testing, AI red teaming, Generative AI, and Agentic AI.
• Familiarity with security event, authentication, endpoint, network, vulnerability, threat intelligence, and incident data.
• Professional certifications such as FRM, PRM, CFA, CISSP, CISM, CRISC, or relevant AI, cybersecurity, cloud, or technology certifications.
Success Measures
• High-quality, timely, and risk-focused validation of material cybersecurity models and AI-enabled security systems.
• Early identification and effective escalation of material model risks, detection limitations, adversarial vulnerabilities, and control weaknesses.
• Consistent and scalable validation standards for cybersecurity analytics and intelligent security solutions.
• Clear influence on senior risk decisions, remediation priorities, and the strength of cybersecurity model governance.
• Continued enhancement of the Model Risk Management framework in response to evolving cyber threats, AI security risks, and regulatory expectations.
Salary Range:
$137,400 - 233,600 USD
Salary range is a good faith estimate of base pay. Northern Trust provides a comprehensive benefits package including retirement benefits (401k and pension), health and welfare benefits (medical, dental, vision, spending accounts and disability), paid time off, parental and caregiver leave, life & accident insurance, and other voluntary and well-being benefits. Northern Trust also provides a discretionary bonus program that may include an equity component.