Cybersecurity ServiceNow Application Senior Advisor
Role details
Job location
Tech stack
Job description
Hybrid 1: This role requires associates to be i n-office 1 - 2 days per week in the Indianapolis, IN or Atlanta, GA office , fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines structured office engagement with the autonomy of virtual work, promoting a dynamic and adaptable workplace.
- Please note that per our policy on hybrid/virtual work, candidates not within a reasonable commuting distance from the posting location(s) will not be considered for employment, unless an accommodation is granted as required by law.
The Information Security Sr. Advisor is responsible for leading the design, development, configuration, enhancement, and ongoing optimization of ServiceNow capabilities that support cybersecurity risk, compliance, third-party risk, and PCI assessment processes. This role develops, recommends, and implements enterprise information security policies, technical standards, guidelines, procedures, and other elements of an infrastructure necessary to support developing and improving ServiceNow workflows, data models, forms, control libraries, evidence collection processes, assessment templates, dashboards, reporting, integrations, and automation capabilities used to support cybersecurity and PCI DSS assessment activities.
How you will make an impact:
- Serve as a subject matter expert for ServiceNow application functionality supporting cybersecurity and PCI assessment processes, including intake, scoping, evidence requests, questionnaire workflows, control mapping, findings management, issue tracking, risk acceptance, approvals, and reporting.
- Design scalable workflows to support PCI DSS assessment activities, including ROC, SAQ, AOC, gap assessments, evidence collection, control owner attestations, remediation tracking, compensating control documentation, targeted risk analyses, and assessment readiness activities.
- Leads system and network architecture support for information and network security technologies; leads development and execution of risk assessment methodologies to fit business, regulatory, and technical environment considerations; leads the development of requirements, system architecture, and software design of security products and services; leads the development of strategies for discovery, evaluation and response to new networking attacks; develops security incident response plans and strategies.
- Provides trouble resolution and serves as point of technical escalation on complex problems.
- Creates presentations and seeks IT management approval and acceptance of significant replacements or reconfigurations of major security systems serving the Enterprise. Sets vendor strategy and direction.
- May be assigned to project teams for technical consultation to business partners and developers.
- Designs & engineers comprehensive access management and network security technical solutions based on business requirements and defined technology standards; works with architecture to update technology direction & strategy.
- Develops reports supporting strategy and direction for management. including PCI compliance readiness, control performance, and program meturity.
- Capable of serving as technical merger & acquisition lead. .
Requirements
- Requires BS/BA in information Technology or related field of study and a minimum of 8 years experience in systems administration and security aspects of information systems, access management and network security technologies, network communications, computer networking, telecommunications, systems development and management, hardware, software, data, and people; experience with multiple technical and business disciplines required; requires broad-based experience to plan and design highly complex systems; or any combination of education and experience, which would provide an equivalent background., * Security Certifications: CISSP and other advanced technical security certifications (e.g. Information Systems Security Architecture Professional, Information Security Engineering Professional, Certification and Accreditation Professional, or equivalent certifications) strongly preferred.
- 5+ years of experience in cybersecurity, ServiceNow application development, GRC/IRM systems, IT risk management, compliance operations, audit management, business analysis, workflow automation, or a related field.
- Experience with cybersecurity and compliance frameworks such as PCI DSS, NIST CSF, NIST SP 800-53, HIPAA, HITRUST, SOC 2, ISO 27001/27002, CIS Controls, CSA CCM, or similar control frameworks.
- Experience working in healthcare, insurance, financial services, payment processing, retail, or another regulated industry.
- Relevant certification such as ServiceNow Certified System Administrator, ServiceNow Certified Implementation Specialist, ServiceNow Certified Application Developer, Certified Implementation Specialist - Risk and Compliance, PCI ISA, PCI QSA, CISA, CISSP, CISM, CRISC, Security+, or equivalent cybersecurity, audit, compliance, or ServiceNow certification.
Benefits & conditions
At Elevance Health, we are creating a culture that is designed to advance our strategy but will also lead to personal and professional growth for our associates. Our values and behaviors are the root of our culture. They are how we achieve our strategy, power our business outcomes and drive our shared success - for our consumers, our associates, our communities and our business.
We offer a range of market-competitive total rewards that include merit increases, paid holidays, Paid Time Off, and incentive bonus programs (unless covered by a collective bargaining agreement), medical, dental, vision, short and long term disability benefits, 401(k) +match, stock purchase plan, life insurance, wellness programs and financial education resources, to name a few.
Elevance Health operates in a Hybrid Workforce Strategy. Unless specified as primarily virtual by the hiring manager, associates are required to work at an Elevance Health location at least once per week, and potentially several times per week. Specific requirements and expectations for time onsite will be discussed as part of the hiring process.
The health of our associates and communities is a top priority for Elevance Health. We require all new candidates in certain patient/member-facing roles to become vaccinated against COVID-19 and Influenza. If you are not vaccinated, your offer will be rescinded unless you provide an acceptable explanation. Elevance Health will also follow all relevant federal, state and local laws.