xelys jobs xelys jobs

Senior Information Security Analyst

ServiceNow

full-remoteseniorpermanentsecurity Full remote - Santa Clara, CA, US Today via WTTJ

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

Information SecurityIncident ResponseApplication SecurityOWASP Top TenSIEMVulnerability ManagementWeb Application Penetration TestingCompliance (NIST, CIS, GDPR, HIPAA, PCI DSS, ISO)OWASPCloud Security

About the role

Role Overview

Join ServiceNow’s Security Organization (SSO) as a Senior Information Security Analyst. You will triage and investigate security matters for the ServiceNow platform and act as a key interface with internal teams and customers on security and privacy topics.

Responsibilities

  • Represent Security in customer-facing security incidents, cases, security findings, tasks, questions, and calls related to Security & Privacy.
  • Own, triage, investigate, and respond to security matters across the ServiceNow platform, ensuring timely communication and resolution.
  • Serve as the primary point of contact for security-related matters for both internal and external stakeholders.
  • Manage customer outreach communications and improve customer security experience and processes.
  • Develop security awareness training and best-practice programs.

Requirements

  • 3–5+ years professional experience in information security or application security (or equivalent via education).
  • CISSP (required).
  • Strong analytical and problem-solving skills to evaluate complex security challenges.
  • Ability to explain security risks to non-technical stakeholders in plain language.
  • Solid understanding of cloud computing models and major hyperscaler cloud models.
  • Experience with AI technologies and designing AI-based solutions.
  • In-depth knowledge of web application vulnerabilities (e.g., OWASP Top Ten) and mitigations.
  • Familiarity with compliance frameworks and regulations including NIST, CIS, GDPR, HIPAA, PCI DSS, ISO.
  • Hands-on understanding of security tooling such as SIEM, logging, load balancers, firewalls, WAFs, IDS/IPS, vulnerability management, encryption.
  • Intermediate-to-advanced ability with web proxy tools for security testing and assessments.
  • Basic-to-intermediate programming knowledge in Java/JavaScript (read/interpret code and explain effectively).
  • Strong communication skills (verbal and written) for both technical and non-technical audiences.
  • Ability to work in a follow-the-sun team model.

Preferred / Nice to Have

  • Two or more preferred certifications, including combinations such as: CISM, GCIH (GIAC Incident Handler), OSWA, GSEC, GWAPT, OSWA, GIAC Security Essentials, and ServiceNow Certified System Administrator (CSA).
  • Hands-on experience with web-based vulnerability exploitation.

About ServiceNow

ServiceNow is a leading SaaS provider offering enterprise workflow and platform solutions. The company operates in the cloud software space and delivers tools that help organizations manage operations, IT, and customer service at scale, including security and privacy capabilities.

Scraped 8/1/2026