Principal Security Engineer - AI & Copilot Data Protection
About Northern Trust
Northern Trust, a Fortune 500 company established in 1889, is a globally recognized and award-winning financial institution. With over 130 years of experience and 22,000+ partners, they provide innovative financial services and guidance to successful individuals, families, and institutions, upholding principles of service, expertise, and integrity. They value an inclusive workplace and offer a flexible, collaborative culture where movement within the organization is encouraged and senior leaders are accessible.
About the Position
Introduction
Northern Trust, a Fortune 500 company and a globally recognized financial institution, is seeking a Principal Security Engineer. This role focuses on leading the secure enablement of Microsoft 365 Copilot and enterprise AI capabilities within the Cyber Team, driving the end-to-end technical strategy, architecture, and operationalization of AI-driven data protection and compliance controls.
Responsibilities
- AI & Copilot Security Architecture:
- Act as a hands-on technical lead and design authority for Copilot and enterprise AI security controls across Microsoft Purview, Defender, and M365.
- Define and evolve the AI data protection reference architecture, mapping controls to AI threat models and regulatory expectations.
- Review and harden Copilot platform configurations, including web grounding and search behaviors, agents, plugins, connectors, permission inheritance, identity context, transcripts, prompt history, and retention models.
- Ensure controls are designed for default-secure behavior, least privilege, and fail-safe operation.
- Control Engineering & Operations:
- Design, implement, and operate AI-related controls spanning Information Protection and labeling strategy, DLP and Endpoint DLP (including AI-specific scenarios), Insider Risk Management and Communication Compliance, Data Lifecycle Management and retention enforcement, and DSPM for AI (exposure detection and oversharing remediation).
- Configure, deploy, troubleshoot, and operate controls across AD and EntraID environments.
- Support production changes through disciplined change management and approved deployment windows.
- AI Risk Detection, Monitoring & Response:
- Define AI-specific risk use cases, signals, and thresholds aligned to data exposure, misuse, and policy violation scenarios.
- Build monitoring, alerting, and automation for abnormal or high-risk AI usage patterns.
- Develop operational runbooks that enable consistent response, investigation, and evidence preservation.
- Ensure solutions are audit-ready, regulator-defensible, and operationally sustainable.
- Governance & Institutionalization:
- Translate AI threat models into policy-aligned, enforceable technical controls.
- Partner with governance stakeholders to support AI risk assessments, control mapping and documentation, decision logs and exception handling, and executive and stakeholder reporting.
- Contribute expert guidance to Copilot readiness, Zero Trust alignment, and broader AI governance initiatives.
- Track delivery and technical debt using Azure DevOps, establishing transparency and accountability.
- Copilot-Focused Control Outcomes:
- Define and enforce Copilot-protected labels for files, groups, sites, and content sources.
- Prevent unauthorized content ingestion and unintended grounding into AI prompts.
- Expand browser and endpoint DLP protections, including copy/paste and screen capture controls, and AI prompt and response handling.
- Operationalize DSPM for AI to continuously reassess exposure and remediate oversharing.
- Establish durable workflows for AI-related insider risk and communication compliance scenarios.
Requirements
- Deep understanding of LLM security fundamentals and threat modeling, including data exposure risks, indirect and chained prompt injection, and model-mediated data exfiltration.
- Practical mitigation strategies for prompt injection, prompt data leakage, over-permissioned grounding sources, and agent and connector misuse.
- Experience securing agentic or tool-augmented AI systems, including least-privilege access and approval models.
- Strong grasp of AI governance concepts, including risk classification, control frameworks, and policy alignment.
- Ability to translate abstract AI risk into concrete, enforceable technical controls.
- Bachelor's degree or equivalent experience in cybersecurity, engineering, or a related field.
- Extensive hands-on experience with Microsoft Purview and Microsoft Defender (including Cloud Apps).
- Strong background in data protection, DLP technologies, and enterprise information security.
- Proven scripting and automation capability (PowerShell, Python, Power Automate).
- Experience operating within formal incident, problem, and change management processes (e.g., ServiceNow).
Nice to Have
- Deep familiarity with M365 services such as SharePoint Online, Teams, Exchange, and Entra ID.
- Experience integrating or operating with Sentinel, Zscaler, Symantec DLP, or comparable platforms.
Benefits
Northern Trust provides a comprehensive benefits package including retirement benefits (401k and pension), health and welfare benefits (medical, dental, vision, spending accounts and disability), paid time off, parental and caregiver leave, life & accident insurance, and other voluntary and well-being benefits. Northern Trust also provides a discretionary bonus program that may include an equity component.
About Company
Northern Trust, a Fortune 500 company established in 1889, is a globally recognized and award-winning financial institution. With over 130 years of experience and 22,000+ partners, they provide innovative financial services and guidance to successful individuals, families, and institutions, upholding principles of service, expertise, and integrity. They value an inclusive workplace and offer a flexible, collaborative culture where movement within the organization is encouraged and senior leaders are accessible.
How to Apply
Build your career with us and apply today. #MadeForGreater. Northern Trust is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation for any part of the employment process, please email their HR Service Center at MyHRHelp@ntrs.com.
Apply Now
Your data is only shared with Northern Trust
Location
Chicago, IL
Type
FULL_TIME
Keywords
Similar Roles
Explore comparable positions
Principal Security Engineer - AI & Copilot Data Protection
Northern Trust