Cybersecurity ServiceNow Application Senior Advisor
Job Description
Elevance Health is seeking a Cybersecurity ServiceNow Application Senior Advisor to lead and optimize ServiceNow capabilities that support cybersecurity risk, compliance, third-party risk, and PCI assessment processes. This hybrid role brings the opportunity to work as a ServiceNow subject matter expert and provide technical escalation for complex problems, while helping shape workflows and reporting that support security and compliance outcomes.
Responsibilities
- Act as a ServiceNow subject matter expert for application functionality supporting cybersecurity and PCI assessment processes, including intake, scoping, evidence requests, questionnaire workflows, control mapping, findings management, issue tracking, risk acceptance, approvals, and reporting.
- Design scalable workflows for PCI DSS assessment activities, including ROC, SAQ, AOC, gap assessments, evidence collection, control owner attestations, remediation tracking, compensating control documentation, targeted risk analyses, and assessment readiness activities.
- Lead system and network architecture support for information and network security technologies, and drive risk assessment methodologies aligned to business, regulatory, and technical environments.
- Lead development of requirements, system architecture, and software design for security products and services.
- Develop strategies for discovery, evaluation, and response to new networking attacks, and support creation of security incident response plans.
- Provide trouble resolution and serve as a point of technical escalation on complex problems.
- Create presentations to support IT management approval and acceptance of significant replacements or reconfigurations of major security systems serving the enterprise, and support vendor strategy and direction.
- Serve on project teams as a technical consultant to business partners and developers when assigned.
- Design and engineer comprehensive access management and network security technical solutions based on business requirements and defined technology standards, and work with architecture to update technology direction and strategy.
- Develop management reports supporting strategy and direction, including PCI compliance readiness, control performance, and program maturity.
- May be assigned to serve as technical merger and acquisition lead.
Requirements
BS/BA in information technology or related field of study and a minimum of 8 years of experience across systems administration and security aspects of information systems, including access management and network security technologies. Experience should cover network communications, computer networking, telecommunications, systems development and management, and hardware, software, data, and people. Broad-based experience is required to plan and design highly complex systems.
Preferred Skills, Capabilities, and Experiences
- Security certifications such as CISSP and other advanced technical security certifications (e.g., Information Systems Security Architecture Professional, Information Security Engineering Professional, Certification and Accreditation Professional, or equivalent) are strongly preferred.
- 5+ years of experience in cybersecurity, ServiceNow application development, GRC/IRM systems, IT risk management, compliance operations, audit management, business analysis, workflow automation, or a related field.
- Experience with cybersecurity and compliance frameworks including PCI DSS, NIST CSF, NIST SP 800-53, HIPAA, HITRUST, SOC 2, ISO 27001/27002, CIS Controls, CSA CCM, or similar control frameworks.
- Experience working in regulated industries such as healthcare, insurance, financial services, payment processing, retail, or similar.
- Relevant certifications such as ServiceNow Certified System Administrator, ServiceNow Certified Implementation Specialist, ServiceNow Certified Application Developer, Certified Implementation Specialist - Risk and Compliance, PCI ISA, PCI QSA, CISA, CISSP, CISM, CRISC, Security+, or equivalent cybersecurity, audit, compliance, or ServiceNow certification.
Benefits
- Paid holidays
- Paid Time Off
- Incentive bonus programs (unless covered by a collective bargaining agreement)
- Medical, dental, and vision
- Short and long term disability benefits
- 401(k) + match
- Stock purchase plan
- Life insurance
- Wellness programs
- Financial education resources
Hybrid Work Details
- This role requires associates to be in-office 1 to 2 days per week to support collaboration and connectivity, while maintaining flexibility for productivity and work-life balance.
- Alternate locations may be considered if candidates reside within a commuting distance from an office.
- Per Elevance Health policy, candidates not within a reasonable commuting distance from the posting location(s) will not be considered unless an accommodation is granted as required by law.
Additional Information
- Elevance Health only accepts resumes for compensation from agencies that have a signed agreement with ELE. Unsolicited resumes, including those submitted to hiring managers, are deemed the property of Elevance Health.
- Elevance Health requires all new candidates in certain patient/member-facing roles to become vaccinated against COVID-19 and Influenza. If not vaccinated, an offer will be rescinded unless an acceptable explanation is provided, and Elevance Health will follow applicable federal, state, and local laws.
- Applicants who require accommodation to participate in the job application process may contact [email protected] for assistance.