Cybersecurity Sr. Risk Analyst / ServiceNow Business Analyst
Why This Role Stands Out
This hybrid role offers a fantastic opportunity to leverage your cybersecurity risk and ServiceNow expertise within a reputable, CMMI ML3-certified firm. You'll thrive here if you're a proactive analyst eager to contribute to impactful projects and develop your skills in a supportive environment. Apply today to explore this exciting career path!
Quick Overview
Job Description
DivIHN (pronounced “divine”) is a CMMI ML3-certified Technology and Talent solutions firm. Driven by a unique Purpose, Culture, and Value Delivery Model, we enable meaningful connections between talented professionals and forward-thinking organizations. Since our formation in 2002, organizations across commercial and public sectors have been trusting us to help build their teams with exceptional temporary and permanent talent.
Visit us at to learn more and view our open positions.
Duration: 12 Months
Location: Abbott Park, IL
- We are seeking a highly skilled Cybersecurity Sr. Risk Analyst / ServiceNow Business Analyst with a unique blend of cybersecurity risk management expertise, ServiceNow platform experience, and strong business analysis capabilities. The ideal candidate will possess demonstrated experience translating business requirements into actionable solutions, developing business use cases, documenting functional requirements, coordinating user acceptance testing (UAT), and driving platform enhancements from concept through implementation.
- The successful candidate will have a strong understanding of Governance, Risk, and Compliance (GRC) principles and frameworks, coupled with the ability to analyze business processes, identify opportunities for improvement, and support the optimization of risk management workflows through technology-enabled solutions. This role requires a strategic thinker who can bridge the gap between cybersecurity, business stakeholders, and technical teams to drive informed risk-based decisions and continuous process improvement.
- As a member of the Cybersecurity Vendor Risk Management team, this role will evaluate and monitor third-party risks while serving as a key liaison between business stakeholders and technology teams. Responsibilities include gathering and documenting business requirements, developing detailed use cases and process flows, managing enhancement requests, supporting system configuration and testing activities, and ensuring risk management processes are effectively supported through enterprise platforms and tools.
- Evaluate, assess, and monitor cybersecurity and third-party risk activities in alignment with organizational risk management objectives.
- Partner with business stakeholders to gather, analyze, and document business requirements for risk management processes and technology solutions.
- Develop business use cases, user stories, process maps, and functional requirements to support cybersecurity and GRC initiatives.
- Manage and prioritize enhancement requests, ensuring business needs are clearly documented and translated into actionable development requirements.
- Coordinate and execute system testing activities, including test strategy development, test script creation, user acceptance testing (UAT), defect tracking, and validation of implemented solutions.
- Collaborate with technical teams to support solution design, implementation, and deployment activities.
- Analyze existing workflows and identify opportunities to improve operational efficiency, data quality, automation, and user experience.
- Act as a liaison between cybersecurity teams, business stakeholders, and technology partners to ensure successful delivery of enhancements and process improvements.
- Support data governance and stewardship activities to ensure the integrity, accuracy, and consistency of information used in risk management processes.
- Develop metrics, reporting, and dashboards to provide visibility into risk posture, operational performance, and program effectiveness.
- Participate in risk assessments, control evaluations, and remediation tracking activities.
- Prepare business and technical documentation, including requirements, testing artifacts, training materials, and process documentation.
- Support audit, compliance, and regulatory activities by providing documentation and evidence related to cybersecurity risk management processes and system controls.
- Demonstrated experience as a ServiceNow Analyst, Business Analyst, or Product Owner supporting enterprise workflows and business process improvements.
- Strong understanding of cybersecurity risk management, third-party risk management, and GRC processes.
- Experience developing business requirements, use cases, user stories, workflow diagrams, and testing documentation.
- Proven experience managing enhancement requests and driving projects through the full solution lifecycle, from requirements gathering through testing and implementation.
- Experience leading or coordinating User Acceptance Testing (UAT) and defect management processes.
- Strong analytical, problem-solving, communication, and stakeholder management skills.
- Ability to translate complex business requirements into functional solutions that align with organizational objectives.
- Experience working in cross-functional environments involving business, cybersecurity, risk, compliance, and technology teams.
- Bachelor’s degree in Information Security, Computer Science, or related field; or equivalent experience.
- 3+ years of experience in cybersecurity risk analysis or related field.
- Strong analytical skills, ability to work independently, and collaborative interpersonal skills.
- Experience in business analysis, including requirements gathering and test case development.
- Experience with ServiceNow or similar vendor management software.
- Understanding of procurement and risk processes.
- Knowledge of information security and risk control frameworks.
- Familiarity with ISO 27001, SOC 2, HITRUST, FedRAMP, and ISO 22301 standards.
- Operational experience with GRC toolsets.
- CISSP/CISM certification (or similar).
DivIHN is an equal opportunity employer. DivIHN does not and shall not discriminate against any employee or qualified applicant on the basis of race, color, religion (creed), gender, gender expression, age, national origin (ancestry), disability, marital status, sexual orientation, or military status.
Skills
Similar jobs
Risk Manager
BOOZ, ALLEN & HAMILTON, INC. · El Segundo, United States
2 hours ago$77.6k - $176k/yrAsc Cybersecurity Gov&Risk Analyst - Intern/Co-op Conversion 2027 (Souza)
Duke Energy · Charlotte, United States
8 hours agoSr. AI Risk Analyst
BCD Travel · Columbia, United States
14 hours agoSenior Risk Analyst (Data and Technology Risk)
Navy Federal Credit Union · Winchester, United States
19 hours agoData Validation Risk - Senior Associate
PricewaterhouseCoopers LLP · New York, United States
22 hours ago$77k - $202k/yrQuantitative Risk Analyst
ISite Technologies Inc · United States
Yesterday