Senior Business Systems Analyst

ServiceNow
Summary
Join ServiceNow's Security Organization (SSO) as a Senior Business Systems Analyst focused on Security Programs. Partner with stakeholders across Security, Compliance, IT, and Engineering to enhance security governance, streamline workflows, and strengthen internal controls. Lead complex initiatives to improve the organization's security posture and ensure systems support evolving regulatory and risk requirements. Leverage analytical skills and system thinking to identify opportunities for improvement. This role requires strong collaboration, problem-solving, and experience with security and compliance-related business processes. You will lead cross-functional initiatives and serve as a key liaison between teams. The position involves facilitating user acceptance testing, supporting change management, and acting as a Scrum Master.
Requirements
- Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving. This may include using AI-powered tools, automating workflows, analyzing AI-driven insights, or exploring AI’s potential impact on the function or industry
- Security and Risk Platforms – Familiarity with GRC, IRM, SecOps, or vendor risk tools, ideally within the ServiceNow ecosystem
- Business Process Modeling – Document and optimize security workflows using tools like Visio, Lucid, or Miro
- Requirements Documentation – Write functional specifications, security user stories, and use cases tailored to InfoSec needs
- Data Analysis & Reporting – Use SQL, Excel, Tableau, or Power BI to support risk reporting, compliance KPIs, and audit metrics
- SDLC & Secure Development Awareness – Understand how to embed security into Agile/DevOps cycles and development pipelines
- Process Improvement – Apply Lean or Six Sigma principles to enhance security workflows
- Agile & Scrum – Strong facilitation of sprint planning, backlog grooming, and iterative delivery in a security context
- Strong collaboration between technical and non-technical security stakeholders
- Ability to simplify complex security and compliance concepts for business partners
- High attention to detail in handling audit and risk data
- Critical thinking and problem-solving under evolving security requirements
- Ability to manage ambiguity and balance competing priorities across risk, compliance, and delivery
- 8 or more years of experience in Business Systems Analysis, with at least 3 years supporting security, GRC, or risk/compliance domains
- Demonstrated experience working with InfoSec teams, GRC platforms (ideally ServiceNow), or leading audits and remediation projects
- Experience delivering technical solutions in cross-functional environments, preferably within a SaaS or cloud enterprise
- Proven success as a project or Scrum lead on security or compliance-related initiatives
Responsibilities
- Partner with security and compliance stakeholders to understand objectives, workflows, and pain points; translate these into detailed functional requirements and user stories
- Conduct and facilitate requirements gathering for projects related to risk management, security tooling, audit automation, vendor security, and data protection
- Perform gap analyses and identify opportunities for security process improvements using data and systems expertise
- Conduct data analysis to validate requirements, support metrics, and monitor post-implementation effectiveness (e.g., SLA, security incident volume, audit closure rates)
- Lead cross-functional initiatives that span enterprise systems (e.g., GRC, Risk, Vendor Risk, Policy, IRM, SecOps), ensuring security and compliance requirements are embedded early in the lifecycle
- Coordinate operational activities for multiple security-related projects simultaneously
- Serve as a key liaison between Security, IT, and Engineering teams
- Facilitate User Acceptance Testing for security tooling and workflow changes, guiding testers and resolving technical issues
- Support change management activities, including the creation of training materials, process documentation, and operational support (e.g., office hours)
- Facilitate documentation, update, or deprecation of internal security policies and standards as required
- Track security-related issues, defects, and findings across tools; gather evidence and ensure timely resolution or risk acceptance
- Act as Scrum Master using Agile methodologies, leading sprint ceremonies and tracking delivery of security enhancements
Preferred Qualifications
- Bachelor's degree in information systems, Cybersecurity, Computer Science, or related field
- Industry certifications such as CISA, CRISC, CISSP, CGEIT, or PMP are a plus
- Familiarity with security standards and frameworks (e.g., ISO 27001, NIST, SOC 2, FedRAMP, PCI-DSS)