Prepin
Log in
Northern Trust

engineering opportunity

Principal Security Engineer – AI & Copilot Data Protection

This role involves serving as a hands-on technical lead to design, implement, and operate data protection and compliance controls for Microsoft 365 Copilot and enterprise AI capabilities using Microsoft Purview and Defender. Key duties include configuring controls across Information Protection, DLP, Insider Risk, and operationalizing DSPM for AI reporting while ensuring audit readiness.

Chicago, Illinois, United StateshybridFULL_TIME

Posted

About the role

What will you do at Northern Trust?

About Northern Trust

Northern Trust, a Fortune 500 company, is a globally

recognized, award-winning financial institution that has been in continuous

operation since 1889. Northern Trust is proud to provide innovative financial

services and guidance to the world’s most successful individuals, families, and

institutions by remaining true to our enduring principles of service, expertise,

and integrity. With more than 130 years of financial experience and over 22,000

partners, we serve the world’s most sophisticated clients using leading

technology and exceptional service. Role Summary Seeking a Principal‑level

individual contributor to lead the secure enablement of Microsoft 365 Copilot

and enterprise AI capabilities within Northern Trust's Cyber Team. This role

owns the end‑to‑end technical strategy, architecture, and operationalization of

AI‑driven data protection and compliance controls across Microsoft Purview,

Defender, and M365 security services. The Principal serves as the organization’s

deep technical authority on AI data protection, shaping control strategy,

influencing platform configuration decisions, and institutionalizing durable

safeguards that reduce AI‑driven data risk while enabling productivity at

enterprise scale. This is a hands‑on role with architect‑level accountability:

designing systems that will stand up to audit, regulatory scrutiny, and

adversarial pressure as AI usage scales. Scope of Accountability (Principal

Expectations) This role is expected to: Own the technical vision and control

strategy for AI and Copilot data protection, not just implement features. Define

durable, repeatable patterns for securing LLM‑enabled workflows that other teams

can adopt. Operate with wide autonomy, minimal oversight, and direct influence

across Security, Compliance, Privacy, M365, and Risk. Anticipate risk before

incidents occur, translating emerging AI threats into preventive controls. Serve

as escalation point and design authority for complex or ambiguous AI security

decisions.

Key Responsibilities

  • AI & Copilot Security Architecture Act as
  • hands‑on technical lead and design authority for Copilot and enterprise AI
  • security controls across Microsoft Purview, Defender, and M365. Define and
  • evolve the AI data protection reference architecture, mapping controls to AI
  • threat models and regulatory expectations. Review and harden Copilot platform
  • configurations, including: Web grounding and search behaviors Agents, plugins,
  • and connectors Permission inheritance and identity context Transcripts, prompt
  • history, and retention models Ensure controls are designed for default‑secure
  • behavior, least privilege, and fail‑safe operation. Control Engineering &
  • Operations Design, implement, and operate AI‑related controls spanning:
  • Information Protection and labeling strategy DLP and Endpoint DLP (including
  • AI‑specific scenarios) Insider Risk Management and Communication Compliance Data
  • Lifecycle Management and retention enforcement DSPM for AI, including exposure
  • detection and oversharing remediation Configure, deploy, troubleshoot, and
  • operate controls across AD and EntraID environments. Support production changes
  • through disciplined change management and approved deployment windows. AI Risk
  • Detection, Monitoring & Response Define AI‑specific risk use cases, signals, and
  • thresholds aligned to data exposure, misuse, and policy violation scenarios.
  • Build monitoring, alerting, and automation for abnormal or high‑risk AI usage
  • patterns. Develop operational runbooks that enable consistent response,
  • investigation, and evidence preservation. Ensure solutions are audit‑ready,
  • regulator‑defensible, and operationally sustainable. Governance &
  • Institutionalization Translate AI threat models into policy‑aligned, enforceable
  • technical controls. Partner with governance stakeholders to support: AI risk
  • assessments Control mapping and documentation Decision logs and exception
  • handling Executive and stakeholder reporting Contribute expert guidance to
  • Copilot readiness, Zero Trust alignment, and broader AI governance initiatives.
  • Track delivery and technical debt using Azure DevOps, establishing transparency
  • and accountability. Copilot‑Focused Control Outcomes Define and enforce
  • Copilot‑protected labels for files, groups, sites, and content sources. Prevent
  • unauthorized content ingestion and unintended grounding into AI prompts. Expand
  • browser and endpoint DLP protections, including: Copy/paste and screen capture
  • controls AI prompt and response handling Operationalize DSPM for AI to
  • continuously reassess exposure and remediate oversharing. Establish durable
  • workflows for AI‑related insider risk and communication compliance scenarios.
  • Required AI Security Expertise Deep understanding of LLM security fundamentals
  • and threat modeling, including: Data exposure risks Indirect and chained prompt
  • injection Model‑mediated data exfiltration Practical mitigation strategies for:
  • Prompt injection and prompt data leakage Over‑permissioned grounding sources
  • Agent and connector misuse Experience securing agentic or tool‑augmented AI
  • systems, including least‑privilege access and approval models. Strong grasp of
  • AI governance concepts, including risk classification, control frameworks, and
  • policy alignment. Ability to translate abstract AI risk into concrete,
  • enforceable technical controls.

Qualifications

  • Bachelor’s degree or equivalent
  • experience in cybersecurity, engineering, or a related field. Extensive hands‑on
  • experience with Microsoft Purview and Microsoft Defender (including Cloud Apps).
  • Strong background in data protection, DLP technologies, and enterprise
  • information security. Proven scripting and automation capability (PowerShell,
  • Python, Power Automate). Experience operating within formal incident, problem,
  • and change management processes (e.g., ServiceNow). Preferred Experience &
  • Certifications Deep familiarity with M365 services such as SharePoint Online,
  • Teams, Exchange, and Entra ID. Experience integrating or operating with
  • Sentinel, Zscaler, Symantec DLP, or comparable platforms. Applicants must be
  • authorized to work in the U.S. without the need for employment-based visa
  • sponsorship now or in the future. Northern Trust will not sponsor applicants for
  • U.S. work visa status for this opportunity (no sponsorship is available for
  • H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based
  • visa) Salary Range: $137,400 - 233,600 USD Salary range is a good faith estimate
  • of base pay. Northern Trust provides a comprehensive benefits package including
  • retirement benefits (401k and pension), health and welfare benefits (medical,
  • dental, vision, spending accounts and disability), paid time off, parental and
  • caregiver leave, life & accident insurance, and other voluntary and well-being
  • benefits. Northern Trust also provides a discretionary bonus program that may
  • include an equity component. Working with Us: As a Northern Trust partner,
  • greater achievements await. You will be part of a flexible and collaborative
  • work culture in an organization where financial strength and stability is an
  • asset that emboldens us to explore new ideas. Movement within the organization
  • is encouraged, senior leaders are accessible, and you can take pride in working
  • for a company committed to assisting the communities we serve! Join a workplace
  • with a greater purpose. We’d love to learn more about how your interests and
  • experience could be a fit with one of the world’s most admired and sustainable
  • companies! Build your career with us and apply today. #MadeForGreater Reasonable
  • accommodation Northern Trust is committed to working with and providing
  • reasonable accommodations to individuals with disabilities. If you need a
  • reasonable accommodation for any part of the employment process, please email
  • our HR Service Center at [email protected]. We hope you’re excited about the
  • role and the opportunity to work with us. We value an inclusive workplace and
  • understand flexibility means different things to different people. Apply today
  • and talk to us about your flexible working requirements and together we can
  • achieve greater. Looking for greater? You found it. A global financial leader
  • with more than 22,000 employees in 23 locations worldwide, Northern Trust
  • empowers our employees to achieve more than just business goals. Our focus on
  • work-life balance, career mobility and unique opportunities are just a few of
  • the reasons we’ve been named one of the world’s most admired companies. Terms
  • and Conditions Candidate Privacy Notice California Applicant Privacy Notice Pay
  • Transparency Nondiscrimination Provision (U.S) Transparency in Coverage
  • Disclosure – North America Northern Trust is committed to working with and
  • providing reasonable accommodations to individuals with disabilities. If,
  • because of a medical condition or disability, you need a reasonable
  • accommodation for any part of the employment process, please email our HR
  • Service Center or call 1-800-807-0302 (North America), +630-276-5353 (Asia
  • Pacific), 1800-425-0333 (India), +44(0)207 982 4357 (Europe, Middle East and
  • Africa) and let us know the nature of your request and your contact information.
  • APAC/INDIA EEO STATEMENT It is the policy and practice of Northern Trust to
  • provide equal employment opportunities to all employees and applicants. Northern
  • Trust does not discriminate on the basis of race, colour, religion or belief,
  • nationality, ethnic or national origin, sex, marital status, sexual orientation,
  • disability or age. All employment decisions will be made in a non-discriminatory
  • manner in accordance with our obligations under the law and codes of practice.
  • This includes human resources’ decisions relating to recruitment, terms and
  • conditions of employment, transfers, promotions and access to learning and
  • development. Canada EEO STATEMENT Northern Trust is an Equal Opportunity
  • Employer. Hiring and other employment decisions at Northern Trust are made
  • without regard to race, colour, religion, sex, ancestry, national origin, ethnic
  • origin, age, disability, citizenship, veteran status, sexual orientation, record
  • of offences, marital status, family status, or any other characteristic
  • protected by federal, provincial, or local law, regulation, or ordinance. EMEA
  • EEO STATEMENT It is the policy and practice of Northern Trust to provide equal
  • employment opportunities to all employees and applicants. Northern Trust does
  • not discriminate on the basis of race, colour, religion or belief, nationality,
  • ethnic or national origin, sex, marital status, sexual orientation, disability
  • or age. All employment decisions will be made in a non-discriminatory manner in
  • accordance with our obligations under the law and codes of practice. This
  • includes human resources’ decisions relating to recruitment, terms and
  • conditions of employment, transfers, promotions and access to learning and
  • development. USA EEO STATEMENT It is the policy of The Northern Trust Company to
  • afford equal opportunity in all phases of employment without regard to an
  • individual's age, race, color, religion, creed, gender, national origin,
  • citizenship status, marital status, pregnancy, sexual orientation, gender
  • identity, gender expression, genetic tests and information, physical or mental
  • disability, protected veteran status or any other legally protected status. EEO
  • Know Your Rights (U.S.)

Which skills does this role require?

Microsoft PurviewMicrosoft DefenderM365 Security ServicesLLM SecurityThreat ModelingPrompt Injection MitigationAgent Risk ManagementAI GovernanceInformation Protection LabelingEndpoint DLPInsider RiskCommunication ComplianceDSPM for AIPowerShellPythonCybersecurity EngineeringMicrosoft 365 CopilotEnterprise AIData ProtectionCompliance ControlsPrompt InjectionAzure DevOpsZero TrustPower AutomateServiceNowAzureLLMs

Make your next move

Build a shortlist and prepare

Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.

Review the responsibilities and requirements before adding an opening to your shortlist.

Role information can change. Confirm current details on the original application page.

Product

AI Candidate AgentCompaniesBrowse JobsDeep ProfileSkill AssessmentOpportunity Matching
Prepin.ai

© 2026 Prepin | All rights reserved.