Global Director of Application Security
Northern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution with over 130 years of experience. We provide innovative financial services to sophisticated clients using leading technology and exceptional service.
About The Role
Northern Trust is seeking a Global Director of Application Security to lead the enterprise strategy, governance, and modernization of application security. This leader will define policies and standards, embed security into modern development practices, and drive the transition from traditional application security models to AI-enabled, post-AI security capabilities. This is a highly visible leadership role requiring a hands-on, technically credible leader who can partner with engineering and security teams.
Responsibilities
- Own the Application Security Strategy: Define and execute the enterprise Application Security vision, roadmap, and operating model aligned to business and technology priorities.
- Establish Governance & Standards: Develop and enforce application security policies, standards, and controls across the software development lifecycle (SDLC), including APIs, CI/CD pipelines, and software supply chain.
- Lead the AI Security Transformation: Shape how the organization evolves from traditional development security to AI-assisted and AI-generated development models, including guardrails, validation, and governance.
- Drive Secure DevSecOps Practices: Partner with engineering and platform teams to embed security into CI/CD pipelines using scalable, automated, developer-friendly approaches (SAST, DAST, SCA, IaC, secrets, etc.).
- Lead and Scale a High-Impact Team: Manage an initial team of 4 direct reports (North America) and ~10 contractors, building a high-performing, technically strong organization.
- Engage and Influence Leadership: Act as a senior advisor to cybersecurity and technology leadership, communicating risk, strategy, and progress to executive stakeholders.
- Deliver Measurable Risk Reduction: Define KPIs and drive improvements in vulnerability management, remediation velocity, and overall application security posture.
Requirements
- 10+ years in application security, cybersecurity, or software engineering
- 5+ years leading application security or DevSecOps programs at enterprise scale
- Experience defining and enforcing security policies, standards, and governance
- Strong technical depth in secure software development and modern SDLC practices
- Proven ability to influence engineering teams and senior stakeholders
- Experience leading small, high-impact teams including contractors
Qualifications
- Hands-on experience developing software in large enterprises with mature DevOps / CI/CD pipelines
- Background in software engineering, architecture, or platform engineering
- Experience with SAST, DAST, SCA
- Software supply chain security
- API and cloud-native application security
- CI/CD pipeline security and automation
- Familiarity with AI-assisted development and its security implications
- Financial services or regulated industry experience
Why This Role Matters
You will define the future of Application Security at Northern Trust—modernizing how secure software is built and governed while positioning the organization for the next generation of AI-driven development and risk management.
Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future.
Pay
Salary range is $164,600 - 288,000 USD. Northern Trust provides a discretionary bonus program that may include an equity component.
Benefits
- Retirement benefits (401k and pension)
- Health and welfare benefits (medical, dental, vision, spending accounts, and disability)
- Paid time off, parental and caregiver leave
- Life & accident insurance
- Other voluntary and well-being benefits
Schedule
Northern Trust values an inclusive workplace and understands flexibility means different things to different people. Flexible working requirements will be discussed during the application process.