Back to jobs

    About Northern Trust

    Northern Trust, a Fortune 500 company established in 1889, is a globally recognized and award-winning financial institution. With over 130 years of experience and 22,000+ partners, they provide innovative financial services and guidance to successful individuals, families, and institutions, upholding principles of service, expertise, and integrity. They value an inclusive workplace and offer a flexible, collaborative culture where movement within the organization is encouraged and senior leaders are accessible.

    About the Position

    Introduction

    Northern Trust, a Fortune 500 company and a globally recognized financial institution, is seeking a Principal Security Engineer. This role focuses on leading the secure enablement of Microsoft 365 Copilot and enterprise AI capabilities within the Cyber Team, driving the end-to-end technical strategy, architecture, and operationalization of AI-driven data protection and compliance controls.

    Responsibilities

    • AI & Copilot Security Architecture:
      • Act as a hands-on technical lead and design authority for Copilot and enterprise AI security controls across Microsoft Purview, Defender, and M365.
      • Define and evolve the AI data protection reference architecture, mapping controls to AI threat models and regulatory expectations.
      • Review and harden Copilot platform configurations, including web grounding and search behaviors, agents, plugins, connectors, permission inheritance, identity context, transcripts, prompt history, and retention models.
      • Ensure controls are designed for default-secure behavior, least privilege, and fail-safe operation.
    • Control Engineering & Operations:
      • Design, implement, and operate AI-related controls spanning Information Protection and labeling strategy, DLP and Endpoint DLP (including AI-specific scenarios), Insider Risk Management and Communication Compliance, Data Lifecycle Management and retention enforcement, and DSPM for AI (exposure detection and oversharing remediation).
      • Configure, deploy, troubleshoot, and operate controls across AD and EntraID environments.
      • Support production changes through disciplined change management and approved deployment windows.
    • AI Risk Detection, Monitoring & Response:
      • Define AI-specific risk use cases, signals, and thresholds aligned to data exposure, misuse, and policy violation scenarios.
      • Build monitoring, alerting, and automation for abnormal or high-risk AI usage patterns.
      • Develop operational runbooks that enable consistent response, investigation, and evidence preservation.
      • Ensure solutions are audit-ready, regulator-defensible, and operationally sustainable.
    • Governance & Institutionalization:
      • Translate AI threat models into policy-aligned, enforceable technical controls.
      • Partner with governance stakeholders to support AI risk assessments, control mapping and documentation, decision logs and exception handling, and executive and stakeholder reporting.
      • Contribute expert guidance to Copilot readiness, Zero Trust alignment, and broader AI governance initiatives.
      • Track delivery and technical debt using Azure DevOps, establishing transparency and accountability.
    • Copilot-Focused Control Outcomes:
      • Define and enforce Copilot-protected labels for files, groups, sites, and content sources.
      • Prevent unauthorized content ingestion and unintended grounding into AI prompts.
      • Expand browser and endpoint DLP protections, including copy/paste and screen capture controls, and AI prompt and response handling.
      • Operationalize DSPM for AI to continuously reassess exposure and remediate oversharing.
      • Establish durable workflows for AI-related insider risk and communication compliance scenarios.

    Requirements

    • Deep understanding of LLM security fundamentals and threat modeling, including data exposure risks, indirect and chained prompt injection, and model-mediated data exfiltration.
    • Practical mitigation strategies for prompt injection, prompt data leakage, over-permissioned grounding sources, and agent and connector misuse.
    • Experience securing agentic or tool-augmented AI systems, including least-privilege access and approval models.
    • Strong grasp of AI governance concepts, including risk classification, control frameworks, and policy alignment.
    • Ability to translate abstract AI risk into concrete, enforceable technical controls.
    • Bachelor's degree or equivalent experience in cybersecurity, engineering, or a related field.
    • Extensive hands-on experience with Microsoft Purview and Microsoft Defender (including Cloud Apps).
    • Strong background in data protection, DLP technologies, and enterprise information security.
    • Proven scripting and automation capability (PowerShell, Python, Power Automate).
    • Experience operating within formal incident, problem, and change management processes (e.g., ServiceNow).

    Nice to Have

    • Deep familiarity with M365 services such as SharePoint Online, Teams, Exchange, and Entra ID.
    • Experience integrating or operating with Sentinel, Zscaler, Symantec DLP, or comparable platforms.

    Benefits

    Northern Trust provides a comprehensive benefits package including retirement benefits (401k and pension), health and welfare benefits (medical, dental, vision, spending accounts and disability), paid time off, parental and caregiver leave, life & accident insurance, and other voluntary and well-being benefits. Northern Trust also provides a discretionary bonus program that may include an equity component.

    About Company

    Northern Trust, a Fortune 500 company established in 1889, is a globally recognized and award-winning financial institution. With over 130 years of experience and 22,000+ partners, they provide innovative financial services and guidance to successful individuals, families, and institutions, upholding principles of service, expertise, and integrity. They value an inclusive workplace and offer a flexible, collaborative culture where movement within the organization is encouraged and senior leaders are accessible.

    How to Apply

    Build your career with us and apply today. #MadeForGreater. Northern Trust is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation for any part of the employment process, please email their HR Service Center at MyHRHelp@ntrs.com.

    Apply Now

    Your data is only shared with Northern Trust

    Location

    Chicago, IL

    Type

    FULL_TIME

    Keywords

    Security Engineering
    AI
    Copilot
    Microsoft 365
    Data Protection
    Cybersecurity
    Microsoft Purview
    Microsoft Defender
    DLP
    LLM Security
    Threat Modeling
    Risk Management
    Azure DevOps
    PowerShell
    Python
    Power Automate
    Verified Company

    Principal Security Engineer - AI & Copilot Data Protection

    Northern Trust