Cybersecurity ServiceNow Application Senior Advisor
Anticipated End Date:2026-09-25Position Title:Cybersecurity ServiceNow Application Senior AdvisorJob Description:Cybersecurity ServiceNow Application Senior Advisor ( Information Security Sr. Advisor )Information Security Risk ManagementHybrid 1: This role requires associates to be in-office 1 - 2 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines structured office engagement with the autonomy of virtual work, promoting a dynamic and adaptable workplace.Alternate locations may be considered if candidates reside within a commuting distance from an office.Please note that per our policy on hybrid/virtual work, candidates not within a reasonable commuting distance from the posting location(s) will not be considered for employment, unless an accommodation is granted as required by law.The Information Security Sr. Advisor is responsible for leading the design, development, configuration, enhancement, and ongoing optimization of ServiceNow capabilities that support cybersecurity risk, compliance, third-party risk, and PCI assessment processes. This role develops, recommends, and implements enterprise information security policies, technical standards, guidelines, procedures, and other elements of an infrastructure necessary to support developing and improving ServiceNow workflows, data models, forms, control libraries, evidence collection processes, assessment templates, dashboards, reporting, integrations, and automation capabilities used to support cybersecurity and PCI DSS assessment activities.How you will make an impact:Serve as a subject matter expert for ServiceNow application functionality supporting cybersecurity and PCI assessment processes, including intake, scoping, evidence requests, questionnaire workflows, control mapping, findings management, issue tracking, risk acceptance, approvals, and reporting.Design scalable workflows to support PCI DSS assessment activities, including ROC, SAQ, AOC, gap assessments, evidence collection, control owner attestations, remediation tracking, compensating control documentation, targeted risk analyses, and assessment readiness activities.Leads system and network architecture support for information and network security technologies; leads development and execution of risk assessment methodologies to fit business, regulatory, and technical environment considerations; leads the development of requirements, system architecture, and software design of security products and services; leads the development of strategies for discovery, evaluation and response to new networking attacks; develops security incident response plans and strategies.Provides trouble resolution and serves as point of technical escalation on complex problems.Creates presentations and seeks IT management approval and acceptance of significant replacements or reconfigurations of major security systems serving the Enterprise. Sets ven...