Government Careers
  • Sr. Associate, Threat and Vulnerability

  • Northern Trust
  • Chicago, Illinois 60601 United States View Map

Summary

Threat & Vulnerability Analyst

The Threat & Vulnerability Analyst is responsible for identifying and assessing cyber threats, vulnerabilities, and exposures that may impact Northern Trust's business operations, technology platforms, and regulatory obligations. The role partners withVulnerability Management, Security Operations, Threat Intelligence, Infrastructure, Cloud Security, Application Security, and Risk teams to ensure vulnerabilities are prioritized and remediated based on risk. The successful candidate will transform vulnerability data into actionable recommendations,helping the organization proactively reduce cyber risk.

Vulnerability Management

  • Analyze vulnerability scanning results across infrastructure, cloud, endpoints, applications, and container environments.
  • Assess new vulnerabilities, CVEs, and security advisories to determine organizational exposure.
  • Prioritize remediation using CVSS, exploitability, threat intelligence, business criticality, and asset context.
  • Track remediation activities and provide reporting on vulnerability reduction initiatives.
  • Support validation and verification of remediation efforts.

Exposure Management

  • Identify and assess attack paths and security weaknesses across the enterprise environment.
  • Support Continuous Threat Exposure Management (CTEM) activities and exposure reduction programs.
  • Analyze internal and external attack surface risks.
  • Assist with developing and maintaining threat-informed vulnerability remediation strategies.
  • Monitor and assess emerging cyber threats, adversary activity, and industry trends relevant to the financial services sector.
  • Evaluate threat intelligence feeds, industry reports, and vulnerability disclosures.
  • Analyze threat actor tactics, techniques, and procedures (TTPs) and determine potential impact to Northern Trust.

Collaboration

  • Work closely with SOC, Threat Intelligence, Penetration Testing, Infrastructure, Cloud Engineering, Application Security, and Risk teams.
  • Support remediation discussions with technology owners and business stakeholders.
  • Participate in cyber security projects and continuous improvement initiatives.

Required Qualifications

  • Bachelor's degree in Cyber Security, Computer Science, Information Technology, or related discipline.
  • 3-5 years of experience in cyber security, vulnerability management, threat intelligence, security operations, or related fields.
  • Experience analyzing vulnerabilities and security risks within large enterprise environments.
  • Understanding of common attack methodologies and cyber threat actor behaviors.
  • Familiarity with vulnerability scoring methodologies such as CVSS.
  • Experience with vulnerability management platforms such as Zafran, Qualys, Microsoft Defender Vulnerability Management, or equivalent.
  • Understanding of cloud security principles across Azure, AWS, or Google Cloud.
  • Strong analytical, problem-solving, and communication skills.

Salary Range: $88,900 - 151,100 USD

Salary range is a good faith estimate of base pay. Northern Trust provides a comprehensive benefits package including retirement benefits (401k and pension), health and welfare benefits (medical, dental, vision, spending accounts and disability), paid time off, parental and caregiver leave, life & accident insurance, and other voluntary and well-being benefits. Northern Trust also provides a discretionary bonus program that may include an equity component.

Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. Northern Trust will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa).

As a Northern Trust partner, you will be part of a flexible and collaborative work culture, which has a strong history of financial strength and stability. Movement within the organization is encouraged, senior leaders are accessible, and you can take pride in working for a company committed to an inclusive workplace and assisting the communities we serve.

Philanthropy is deeply rooted in Northern Trust's history and is an essential element of our culture. Employees around the world give their time and talent to work for the greater good of their communities.

Northern Trust is committed to working with and providing adjustments to individuals with health conditions and disabilities. If you need a reasonable accommodation for any part of the employment process, please email our HR Service Center at MyHRHelp@ntrs.com, or alternatively you can discuss your individual requirements with the recruiter you are working with.

Job Description

Threat & Vulnerability Analyst

The Threat & Vulnerability Analyst is responsible for identifying and assessing cyber threats, vulnerabilities, and exposures that may impact Northern Trust's business operations, technology platforms, and regulatory obligations. The role partners withVulnerability Management, Security Operations, Threat Intelligence, Infrastructure, Cloud Security, Application Security, and Risk teams to ensure vulnerabilities are prioritized and remediated based on risk. The successful candidate will transform vulnerability data into actionable recommendations,helping the organization proactively reduce cyber risk.

Vulnerability Management

  • Analyze vulnerability scanning results across infrastructure, cloud, endpoints, applications, and container environments.
  • Assess new vulnerabilities, CVEs, and security advisories to determine organizational exposure.
  • Prioritize remediation using CVSS, exploitability, threat intelligence, business criticality, and asset context.
  • Track remediation activities and provide reporting on vulnerability reduction initiatives.
  • Support validation and verification of remediation efforts.

Exposure Management

  • Identify and assess attack paths and security weaknesses across the enterprise environment.
  • Support Continuous Threat Exposure Management (CTEM) activities and exposure reduction programs.
  • Analyze internal and external attack surface risks.
  • Assist with developing and maintaining threat-informed vulnerability remediation strategies.
  • Monitor and assess emerging cyber threats, adversary activity, and industry trends relevant to the financial services sector.
  • Evaluate threat intelligence feeds, industry reports, and vulnerability disclosures.
  • Analyze threat actor tactics, techniques, and procedures (TTPs) and determine potential impact to Northern Trust.

Collaboration

  • Work closely with SOC, Threat Intelligence, Penetration Testing, Infrastructure, Cloud Engineering, Application Security, and Risk teams.
  • Support remediation discussions with technology owners and business stakeholders.
  • Participate in cyber security projects and continuous improvement initiatives.

Required Qualifications

  • Bachelor's degree in Cyber Security, Computer Science, Information Technology, or related discipline.
  • 3-5 years of experience in cyber security, vulnerability management, threat intelligence, security operations, or related fields.
  • Experience analyzing vulnerabilities and security risks within large enterprise environments.
  • Understanding of common attack methodologies and cyber threat actor behaviors.
  • Familiarity with vulnerability scoring methodologies such as CVSS.
  • Experience with vulnerability management platforms such as Zafran, Qualys, Microsoft Defender Vulnerability Management, or equivalent.
  • Understanding of cloud security principles across Azure, AWS, or Google Cloud.
  • Strong analytical, problem-solving, and communication skills.

Salary Range: $88,900 - 151,100 USD

Salary range is a good faith estimate of base pay. Northern Trust provides a comprehensive benefits package including retirement benefits (401k and pension), health and welfare benefits (medical, dental, vision, spending accounts and disability), paid time off, parental and caregiver leave, life & accident insurance, and other voluntary and well-being benefits. Northern Trust also provides a discretionary bonus program that may include an equity component.

Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. Northern Trust will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa).

As a Northern Trust partner, you will be part of a flexible and collaborative work culture, which has a strong history of financial strength and stability. Movement within the organization is encouraged, senior leaders are accessible, and you can take pride in working for a company committed to an inclusive workplace and assisting the communities we serve.

Philanthropy is deeply rooted in Northern Trust's history and is an essential element of our culture. Employees around the world give their time and talent to work for the greater good of their communities.

Northern Trust is committed to working with and providing adjustments to individuals with health conditions and disabilities. If you need a reasonable accommodation for any part of the employment process, please email our HR Service Center at MyHRHelp@ntrs.com, or alternatively you can discuss your individual requirements with the recruiter you are working with.

Government Careers

Government Careers

Government jobs offer stability, competitive benefits, and the chance to make a meaningful impact on your community and country.

Whether you’re starting your career or seeking new opportunities, these roles provide pathways for growth, security, and service.

Explore positions across a wide range of fields and take the first step toward a rewarding future in public service.

Show more

MORE JOBS