Risk Manager

ServiceNow

Risk Manager

Chicago, IL
Full Time
Paid
  • Responsibilities

    Job Description

    What you get to do in this role:

    • Deployment and configuration of vulnerability management solutions (Tenable/Qualys/Nexpose)
    • Assess security risks and impact of issues pertaining to ServiceNow.
    • Work with stakeholders to provide triage and remediation recommendations.
    • Partner with Compliance teams to ensure proper validation is being performed.
    • Develop and implement innovations on the ServiceNow platform.
  • Qualifications

    Qualifications

    To be successful in this role you have:

    • 7–8 years of experience in cybersecurity, information security, GRC, or federal compliance roles.

    • Deep working knowledge of CMMC 2.0, NIST SP 800-171, NIST SP 800-53, and NIST Cybersecurity Framework (CSF).

    • Hands-on experience leading or supporting CMMC assessments, including application scoping, control mapping, gap analysis, and remediation planning.

    • Strong understanding of federal contracting compliance requirements, including DFARS 252.204-7012 and CUI (Controlled Unclassified Information) handling.

    • Experience developing and maintaining SSPs, POA&Ms, and compliance documentation for federal authorization.

    • Proven ability to conduct risk assessments across enterprise environments covering endpoints, identity, cloud, and data protection.

    • Working knowledge of the ServiceNow platform, including familiarity with IRM, SecOps, CMDB, or ITSM modules for managing security and compliance workflows.

    • Excellent written and verbal communication skills with demonstrated ability to present technical findings to executive audiences.

    • Experience working cross-functionally with IT, security, audit, and legal teams in a large enterprise environment.

    • ** Preferred**

    • Professional certifications such as CISSP, CISM, CISA, CAP (Certified Authorization Professional), or CMMC Registered Practitioner (RP).

    • Hands-on experience with ServiceNow IRM (Integrated Risk Management), including Risk Management, Policy & Compliance Management, Audit Management, and Vendor Risk Management modules.

    • Experience with broader ServiceNow platform capabilities including CMDB/APM, SecOps (Security Incident Response, Vulnerability Response), ITSM, and IT Asset Management for integrated security and compliance workflows.

    • Familiarity with ServiceNow reporting, dashboards, Performance Analytics, and workflow automation to drive GRC program efficiency and executive visibility.

    • Familiarity with FedRAMP, FISMA, FIPS 140-2/3 encryption requirements, and DoD cybersecurity policies.

    • Background in evaluating dual-environment architectures (e.g., O365 commercial vs. GCC High) for compliance alignment.

    • Experience with SIEM, EDR (e.g., CrowdStrike), vulnerability management tools, and security architecture review processes.

    • Knowledge of identity and access management frameworks, including Okta, Active Directory, and SailPoint integrations.

    • Prior experience in enterprise-scale assessment campaigns involving 50+ applications or business units.

    • Experience in building or consuming continuous monitoring, control hygiene, or AI-enabled risk/issue automation workflows (e.g., automated control testing, continuous controls monitoring, risk scoring, AI/ML-driven issue remediation).

    Additional Information

    Work Personas

    We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here. To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.

    Equal Opportunity Employer

    ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.

    Accommodations

    We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact globaltalentss@servicenow.com for assistance.

    Export Control Regulations

    For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.

    From Fortune. ©2025 Fortune Media IP Limited. All rights reserved. Used under license.