Senior Lead, Cyber Security Encryption & API Engineer - Northern Trust
Senior Lead, Cyber Security Encryption & API Engineer - Northern Trust

Senior Lead, Cyber Security Encryption & API Engineer - Northern Trust

London Full-Time 48000 - 84000 £ / year (est.) No home office possible
Go Premium
N

At a Glance

  • Tasks: Join our team to design and implement cutting-edge security solutions in a dynamic environment.
  • Company: Northern Trust is a Fortune 500 financial institution with over 130 years of experience.
  • Benefits: Enjoy flexible working options, a collaborative culture, and opportunities for career growth.
  • Why this job: Be part of a mission-driven company that values innovation and community impact.
  • Qualifications: Ideal candidates have a background in networking, data security, and cloud technologies.
  • Other info: We offer reasonable accommodations for individuals with disabilities and value an inclusive workplace.

The predicted salary is between 48000 - 84000 £ per year.

Job Description

About Northern Trust:

Northern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution that has been in continuous operation since 1889.

Northern Trust is proud to provide innovative financial services and guidance to the world's most successful individuals, families, and institutions by remaining true to our enduring principles of service, expertise, and integrity. With more than 130 years of financial experience and over 22,000 partners, we serve the world's most sophisticated clients using leading technology and exceptional service.

Role/ Department:

Seeking a dynamic engineer who is passionate for cloud and security technologies to be part of a team that develops enterprise security solutions. As an architect in our Data Protection team, you will be responsible for designing, implementing, integrating, testing and deploying features and components in a large-scale system. We expect you to drive improvements to code quality, performance, and team processes while leveraging modern web technologies and tools. The successful candidate will be able to debug problems arising as a result of implementing data protection technologies and be able to understand the implications of those implementations.

Develops and administers the solutions that meet system expectations relative to scalability, performance, fault tolerance, usability, and data integrity. Delivers solutions that meet end user expectations relative to performance, usability and security for the Data Protection Engineering and Architecture function.

Uses specific knowledge of a discipline to achieve goals through own work. Has specific knowledge or expertise typically gained through formal education or equivalent experience. Uses expertise to provide guidance to others as a project manager or consultant. Requires in-depth conceptual and practical knowledge in own job discipline and basic knowledge of related job disciplines. Solves complex problems. Works independently; receives minimal guidance. Will lead projects or project steps within a broader project or may have accountability for on-going activities or objectives. Acts as a resource for colleagues with less experience

The key responsibilities of the role include:

  • Setting up Encryption using Technologies such as Voltage, Secupi, Protegrity, or Microsoft Purview
  • Understanding Key Management framework and best practices around Bring Your Own Key and Hold Your Own Key.
  • Design, configure, and deploy Layer 7 gateways (API Gateway).
  • Implement and manage policies for throttling, routing, caching, and request/response transformation.
  • Apply secure authentication and authorization mechanisms such as OAuth2, JWT, and SAML.
  • Configure and maintain Web Application Firewalls (WAFs) to protect against OWASP Top 10 threats like SQL injection, XSS, CSRF.
  • Monitor API traffic and logs for anomalies, performance issues, and security incidents.
  • Integrate Layer 7 logs with SIEM tools (e.g., Splunk, Azure ) for real-time threat detection and incident response.
  • Implement data encryption at rest and in transit using industry-standard protocols (e.g., AES-256, TLS 1.2/1.3).
  • Manage and rotate encryption keys using centralized key management systems (e.g., AWS KMS, Azure Key Vault, HashiCorp Vault).
  • Enforce key lifecycle policies including key generation, rotation, archival, and revocation.
  • Ensure secure storage and access control of keys, certificates, and secrets.
  • Design and maintain PKI (Public Key Infrastructure) for certificate issuance and validation.
  • Integrate encryption practices into applications, APIs, and databases with minimal performance impact.
  • Setting up DLP Policies in Microsoft Defender for Cloud Apps (CASB) , Microsoft Defender for Endpoint and Microsoft Purview
  • Assisting the Implementation of Data Loss Prevention and guide on unit testing, and support documentation;
  • Determining operational feasibility by evaluating, analyzing, problem definition, requirements, solution development, and proposing solutions.
  • Collaborating with Enterprise Architecture organization as needed.
  • Reviewing documentation, processes or procedures, and recommends where automation or improvements can be implemented
  • Operating independently; has in-depth knowledge of business unit/function; Accomplishes engineering and organization mission by completing related results as needed.
  • As subject area expert, provides comprehensive, in-depth consulting and leadership to team and partners.
  • Create and maintain access control policies including IP whitelisting, blacklisting, and header validation.
  • Ensure secure API lifecycle management including onboarding, versioning, governance, and documentation.
  • Analyze and respond to cyber threats, vulnerabilities, and attack vectors.
  • Lead incident response processes, including detection, containment, eradication, and recovery.
  • Perform regular risk assessments, threat modeling, and security reviews of systems and applications.
  • Implement identity and access management (IAM) practices using SSO, RBAC, and federated identity solutions.

Skills/ Qualifications:

  • Excellent teammate skills, effectiveness both in independent and collaborative work.
  • Ability to learn and use new technologies.
  • Background in networking, data security and cloud-based applications.
  • Experience with distributed computing platforms for high-scale systems.
  • Experience with Azure services and eco-system.
  • Experience with Microsoft and Linux-based environments.
  • Experience with continuous integration and deployment tools.
  • Conduct internal security audits and assist with external security assessments and certifications..
  • Educate development and operations teams on secure coding practices and security awareness.
  • Integrate security tools and practices into CI/CD pipelines (DevSecOps approach).
  • Use vulnerability scanners (e.g., Nessus, Qualys) and static analysis tools (e.g., Fortify, SonarQube).
  • Automate security testing, monitoring, and reporting with scripting (e.g., Python, Bash) and infrastructure-as-code tools.
  • Stay up to date on latest cybersecurity threats, technologies, and mitigation strategies.

Working with Us:

As a Northern Trust partner, greater achievements await. You will be part of a flexible and collaborative work culture in an organization where financial strength and stability is an asset that emboldens us to explore new ideas.

Movement within the organization is encouraged, senior leaders are accessible, and you can take pride in working for a company committed to assisting the communities we serve! Join a workplace with a greater purpose.

We'd love to learn more about how your interests and experience could be a fit with one of the world's most admired and sustainable companies! Build your career with us and apply today. #MadeForGreater

Reasonable accommodation

Northern Trust is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation for any part of the employment process, please email our HR Service Center at MyHRHelp@ntrs.com .

We hope you're excited about the role and the opportunity to work with us. We value an inclusive workplace and understand flexibility means different things to different people.

Apply today and talk to us about your flexible working requirements and together we can achieve greater.

Senior Lead, Cyber Security Encryption & API Engineer - Northern Trust employer: Northern Trust

Northern Trust is an exceptional employer that fosters a flexible and collaborative work culture, encouraging innovation and personal growth. With over 130 years of financial expertise, employees benefit from a stable environment that prioritises community engagement and offers numerous opportunities for career advancement. Join a team where your contributions are valued, and you can take pride in being part of a globally recognised institution committed to excellence and integrity.
N

Contact Detail:

Northern Trust Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Senior Lead, Cyber Security Encryption & API Engineer - Northern Trust

✨Tip Number 1

Familiarise yourself with the specific technologies mentioned in the job description, such as Voltage, Secupi, and Microsoft Purview. Having hands-on experience or projects that showcase your skills with these tools can set you apart from other candidates.

✨Tip Number 2

Network with current or former employees of Northern Trust on platforms like LinkedIn. Engaging in conversations about their experiences can provide valuable insights into the company culture and expectations, which you can leverage during interviews.

✨Tip Number 3

Stay updated on the latest trends in cyber security and encryption technologies. Being able to discuss recent developments or case studies during your interview will demonstrate your passion and commitment to the field.

✨Tip Number 4

Prepare to discuss your experience with incident response processes and risk assessments. Be ready to share specific examples of how you've handled security incidents or improved security measures in previous roles, as this aligns closely with the responsibilities of the position.

We think you need these skills to ace Senior Lead, Cyber Security Encryption & API Engineer - Northern Trust

Cloud Security Technologies
Encryption Technologies (e.g., Voltage, Secupi, Protegrity, Microsoft Purview)
Key Management Frameworks
API Gateway Design and Deployment
Authentication and Authorisation Mechanisms (e.g., OAuth2, JWT, SAML)
Web Application Firewalls (WAFs)
Data Encryption Protocols (e.g., AES-256, TLS 1.2/1.3)
Centralised Key Management Systems (e.g., AWS KMS, Azure Key Vault)
Public Key Infrastructure (PKI) Management
Data Loss Prevention (DLP) Policies
Incident Response Processes
Risk Assessments and Threat Modelling
Identity and Access Management (IAM)
Continuous Integration and Deployment Tools
Scripting for Automation (e.g., Python, Bash)
Vulnerability Scanning and Static Analysis Tools
Collaboration and Teamwork Skills
Networking and Data Security Knowledge
Experience with Azure Services
Linux and Microsoft Environment Proficiency

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights relevant experience in cyber security, encryption technologies, and API management. Use keywords from the job description to demonstrate that you meet the specific requirements of the role.

Craft a Compelling Cover Letter: Write a cover letter that showcases your passion for cloud and security technologies. Mention specific projects or experiences that align with the responsibilities outlined in the job description, such as implementing data protection solutions or managing encryption keys.

Showcase Technical Skills: In your application, emphasise your technical skills related to the role, such as experience with Azure services, knowledge of secure coding practices, and familiarity with tools like SIEM and vulnerability scanners. This will help demonstrate your fit for the position.

Highlight Team Collaboration: Since teamwork is essential for this role, include examples of how you've successfully collaborated with others in previous positions. Discuss any leadership roles you've taken on and how you've contributed to team success in engineering projects.

How to prepare for a job interview at Northern Trust

✨Showcase Your Technical Expertise

Be prepared to discuss your experience with encryption technologies and API management. Highlight specific projects where you've implemented security measures, such as OAuth2 or WAFs, and be ready to explain the challenges you faced and how you overcame them.

✨Demonstrate Problem-Solving Skills

Expect to encounter scenario-based questions that assess your ability to solve complex problems. Use the STAR method (Situation, Task, Action, Result) to structure your responses, showcasing how you approached issues related to data protection and security.

✨Understand the Company’s Values

Northern Trust prides itself on service, expertise, and integrity. Familiarise yourself with these values and think of examples from your past experiences that align with them. This will show your potential employer that you are a good cultural fit.

✨Prepare Questions for Your Interviewers

Have insightful questions ready to ask your interviewers about the team dynamics, current projects, and future goals of the Data Protection team. This not only shows your interest in the role but also helps you gauge if the company is the right fit for you.

Senior Lead, Cyber Security Encryption & API Engineer - Northern Trust
Northern Trust
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

N
  • Senior Lead, Cyber Security Encryption & API Engineer - Northern Trust

    London
    Full-Time
    48000 - 84000 £ / year (est.)

    Application deadline: 2027-08-06

  • N

    Northern Trust

Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>