The ServiceNow Security Organization (SSO)
The ServiceNow Security Organization (SSO) delivers world-class innovative security solutions to reduce risk and protect the company and our customers. We enable our customers to migrate their most sensitive data and workloads to the cloud accelerating our business so that we are the most trusted SaaS provider. We create an environment where our employees are proud to work and can make a positive impact
As a Senior Business Systems Analyst focused on Security Programs you will act as a key partner to stakeholders across Security Compliance IT and Engineering. You will identify opportunities to enhance security governance streamline risk and compliance workflows and strengthen internal controls through scalable system solutions.
This role requires strong analytical skills system thinking and a deep understanding of security and compliance-related business processes. You will lead complex cross-functional initiatives to enhance the organizations security posture and ensure business-critical systems support evolving regulatory and risk requirements.
What you get to do in this role
- Partner with security and compliance stakeholders to understand objectives workflows and pain points; translate these into detailed functional requirements and user stories.
- Conduct and facilitate requirements gathering for projects related to risk management security tooling audit automation vendor security and data protection.
- Perform gap analyses and identify opportunities for security process improvements using data and systems expertise.
- Conduct data analysis to validate requirements support metrics and monitor post-implementation effectiveness (e.g. SLA security incident volume audit closure rates).
- Lead cross-functional initiatives that span enterprise systems (e.g. GRC Risk Vendor Risk Policy IRM SecOps) ensuring security and compliance requirements are embedded early in the lifecycle.
- Coordinate operational activities for multiple security-related projects simultaneously.
- Serve as a key liaison between Security IT and Engineering teams.
- Facilitate User Acceptance Testing for security tooling and workflow changes guiding testers and resolving technical issues.
- Support change management activities including the creation of training materials process documentation and operational support (e.g. office hours).
- Facilitate documentation update or deprecation of internal security policies and standards as required.
- Track security-related issues defects and findings across tools; gather evidence and ensure timely resolution or risk acceptance.
- Act as Scrum Master using Agile methodologies leading sprint ceremonies and tracking delivery of security enhancements.
Technical & Analytical Skills
- Experience in leveraging or critically thinking about how to integrate AI into work processes decision-making or problem-solving. This may include using AI-powered tools automating workflows analyzing AI-driven insights or exploring AIs potential impact on the function or industry.
- Security and Risk Platforms Familiarity with GRC IRM SecOps or vendor risk tools ideally within the ServiceNow ecosystem.
- Business Process Modeling Document and optimize security workflows using tools like Visio Lucid or Miro.
- Requirements Documentation Write functional specifications security user stories and use cases tailored to InfoSec needs.
- Data Analysis & Reporting Use SQL Excel Tableau or Power BI to support risk reporting compliance KPIs and audit metrics.
- SDLC & Secure Development Awareness Understand how to embed security into Agile/DevOps cycles and development pipelines.
- Process Improvement Apply Lean or Six Sigma principles to enhance security workflows.
- Agile & Scrum Strong facilitation of sprint planning backlog grooming and iterative delivery in a security context.
Qualifications :
Soft Skills
- Strong collaboration between technical and non-technical security stakeholders.
- Ability to simplify complex security and compliance concepts for business partners.
- High attention to detail in handling audit and risk data.
- Critical thinking and problem-solving under evolving security requirements.
- Ability to manage ambiguity and balance competing priorities across risk compliance and delivery.
Experience and Education
- 8 or more years of experience in Business Systems Analysis with at least 3 years supporting security GRC or risk/compliance domains.
- Demonstrated experience working with InfoSec teams GRC platforms (ideally ServiceNow) or leading audits and remediation projects.
- Experience delivering technical solutions in cross-functional environments preferably within a SaaS or cloud enterprise.
- Proven success as a project or Scrum lead on security or compliance-related initiatives.
Preferred:
- Bachelors degree in information systems Cybersecurity Computer Science or related field.
- Industry certifications such as CISA CRISC CISSP CGEIT or PMP are a plus.
- Familiarity with security standards and frameworks (e.g. ISO 27001 NIST SOC 2 FedRAMP PCI-DSS).
#SecurityJobs
Additional Information :
Work Personas
We approach our distributed world of work with flexibility and trust. Work personas (flexible remote or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here. To determine eligibility for a work persona ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.
Equal Opportunity Employer
ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race color creed religion sex sexual orientation national origin or nationality ancestry age disability gender identity or expression marital status veteran status or any other category protected by addition all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.
Accommodations
We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process or are unable to use this online application and need an alternative method to apply please contact for assistance.
Export Control Regulations
For positions requiring access to controlled technology subject to export control regulations including the U.S. Export Administration Regulations (EAR) ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.
From Fortune. 2025 Fortune Media IP Limited. All rights reserved. Used under license.
Remote Work :
Yes
Employment Type :
Full-time