Information Security Analyst

ServiceNowWest Palm Beach, FL
103d

About The Position

The ServiceNow Security Organization (SSO) delivers world-class, innovative security solutions to reduce risk and protect the company and our customers. We enable our customers to migrate their most sensitive data and workloads to the cloud, accelerating our business so that we are the most trusted SaaS provider. We create an environment where our employees are proud to work and can make a positive impact. We are seeking a detail-oriented and proactive Information Security Analyst to join our Information Security team. In this role, you will play a critical part in supporting various compliance audits and assessments, including SOC 2, ISO 27001, ISMAP, HITRUST, and others. You will work cross-functionally across departments to understand internal controls, coordinate and fulfill audit requests, and ensure timely, accurate evidence collection. Your ability to identify patterns and continuously improve our audit response processes will directly support the effectiveness and maturity of our security and compliance program.

Requirements

  • Minimum of 2+ years of experience as an Information Security Analyst.
  • Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving.
  • Monitor the security tools and systems that defend ServiceNow's production and corporate environment.
  • Determine relationships between seemingly unrelated events through deductive reasoning.
  • Come up with ways to do things faster, better and more effectively.
  • Maintain up-to-date baselines for the secure configuration and operations of all in-place devices.
  • Participate as an escalation contact in the On-Call rotation to ensure that Security Operations can respond to priority incidents.
  • Assist with the deployment, integration and initial configuration of new security solutions.

Responsibilities

  • Coordinate and respond to internal and external audit requests in a timely and organized manner.
  • Work closely with teams across the organization (e.g., IT, HR, Engineering, Legal) to understand processes and identify appropriate audit evidence.
  • Independently gather, validate, and deliver audit evidence in support of compliance requirements (e.g., SOC 2, ISO 27001, ISMAP, HITRUST).
  • Track and manage incoming audit requests using appropriate tools and documentation practices.
  • Analyze audit request data to identify trends, recurring themes, and opportunities for process improvement.
  • Assist in maintaining and organizing evidence repositories and documentation for reuse and efficiency.
  • Collaborate with senior GRC team members to enhance audit readiness and develop best practices for control implementation and evidence collection.
  • Support other information security and GRC initiatives as needed.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service