ServiceNow Security Analyst
Job Category: Security
Time Type: Full time
Minimum Clearance Required to Start: TS/SCI with Polygraph
Employee Type: Regular
Percentage of Travel Required: None
Type of Travel: None
*
The ServiceNow Security Analyst will be responsible for designing, implementing and maintaining solutions for security incident response, vulnerability management, and integrated risk management within the ServiceNow platform. As the subject matter expert, you will guide a team of developers using Agile to implement SecOps, and IRM/CAM modules in ServiceNow. You will collaborate with stakeholders to gather requirements and translate them into technical specifications, streamline process via automation based on best practices. Additional duties include assisting with Risk Management Framework (RMF) implementation and driving security-focused project outcomes in Intelligence Community (IC) and Department of Defense (DoD) environments.
Job Duties and Responsibilities:
Serve as Scrum Master for cybersecurity-focused development teams, facilitating daily stand-ups, sprint planning, retrospectives, and sprint reviews
Remove impediments and blockers that impact team velocity, particularly security-related dependencies and authorization delays
Foster a collaborative environment between security, development, and operations teams to enable DevSecOps practices
Facilitate communication between technical teams and stakeholders, translating security requirements into actionable user stories
Prepare and deliver briefings to leadership on security initiatives, assessment status, and risk posture
Facilitate communication between technical teams and stakeholders, translating security requirements into actionable user stories
Meet with stakeholders to capture and decompose business and functional requirements
Analyze current security processes and provide recommendations
Design and develop workflows, and ensure compliance with security frameworks
Provide risk assessments and executive-level recommendations to Authorizing Officials
Support security authorization activities including Authority to Operate (ATO) processes and continuous ATO modernization initiatives
Develop and maintain System Requirements Traceability Matrices (SRTMs) and Plans of Action & Milestones (POA&Ms)
Required Qualifications
Education & Experience
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field. Master's degree preferred.
Minimum 10 years of experience in information system security, defining cyber policy, and ATO processes.
Minimum 2 years of experience in agile environments, with Scrum Master or similar facilitation experience
Active Top Secret/SCI clearance required
Certifications
Security+ or DoD 8570 Level II compliant certification (required) or similar
Certified Information Security Manager (CISM)
Information Technology Infrastructure Library (ITIL)
Soft Skills & Competencies
Excellent written and verbal communication skills, including ability to translate technical security concepts for diverse audiences
Demonstrated ability to work effectively with users, customers, and leadership at all levels
Strong facilitation and conflict resolution skills
Experience preparing and delivering briefings on security initiatives and risk posture
Proficiency with Microsoft Office suite and collaboration tools
Comfortable leading teams through ambiguity and competing priorities
Desired Qualifications
Advanced Certifications
Certified Information Systems Security Professional (CISSP)
Systems Security Certified Practitioner (SSCP)
Certified Information Security Manager (CISM)
Professional Scrum Master (PSM II), Certified ScrumMaster (CSM), or SAFe Program Consultant (SPC)
Certified Data Privacy Solutions Engineer (CDPSE)
Specialized Experience
Experience with RMF workflow automation and process optimization initiatives
Previous work on Express ATO, Continuous ATO, or other authorization modernization programs
Experience leading mid to large security initiatives and managing small teams
MNCJobz.com will not be responsible for any payment made to a third-party. All Terms of Use are applicable.