Role: ServiceNow Business Systems Analyst – SecOps or IRM
Location: Houston, TX (Remote)
Position Overview:
Seeking an experienced ServiceNow Business Systems Analyst with expertise in Security Operations (SecOps) and Integrated Risk Management (IRM) to support and enhance enterprise security and risk workflows on the ServiceNow platform.
This role will act as a key liaison between security, risk, compliance, and IT teams, translating complex requirements into scalable ServiceNow solutions that strengthen the organization’s security posture and regulatory compliance—critical within a healthcare environment.
Required Qualifications:
- 5+ years of experience as a Business Systems Analyst in IT or ServiceNow environments
- Hands-on experience with ServiceNow SecOps and/or IRM modules
- Strong understanding of:
- Security operations processes (incident response, vulnerability management)
- Risk and compliance frameworks (e.g., NIST, HIPAA, ISO)
- Experience translating complex security and compliance requirements into system solutions
- Experience working in Agile environments
- Strong analytical, communication, and stakeholder management skills
Preferred Qualifications:
- ServiceNow certifications:
- Certified System Administrator (CSA)
- CIS – Security Operations or IRM
- Experience in healthcare environments (HIPAA compliance highly preferred)
- Familiarity with vulnerability management tools (e.g., Qualys, Tenable, Rapid7)
- Experience with integrations (SIEM tools, identity systems, cloud platforms)
- Knowledge of ITIL and GRC best practices
Ideal Candidate Profile:
- Strong hybrid of business analyst + security domain expertise
- Detail-oriented with a focus on risk mitigation and compliance
- Confident communicator who can bridge technical and non-technical teams
- Proactive and solutions-oriented mindset
Key Responsibilities:
- Gather and translate security and risk-related business requirements into functional and technical specifications
- Serve as the liaison between Cybersecurity, Risk/Compliance, IT, and ServiceNow development teams
- Support implementation and optimization of:
- SecOps (Security Incident Response, Vulnerability Response, Threat Intelligence)
- IRM (Risk Management, Policy & Compliance, Audit Management)
- Design and document end-to-end workflows for incident response, vulnerability remediation, and risk management
- Facilitate workshops, stakeholder meetings, and solution design sessions
- Develop user stories, acceptance criteria, and process flows aligned with Agile delivery
- Support GRC processes, including risk identification, assessment, mitigation, and reporting
- Assist with UAT coordination, test case creation, and validation
- Ensure alignment with ServiceNow best practices, security frameworks, and compliance requirements
- Support reporting and dashboards for risk posture, vulnerabilities, and audit readiness
- Maintain documentation (BRDs, SOPs, process documentation)