ServiceNow Logo

ServiceNow

Risk Manager

Posted 4 Hours Ago
Be an Early Applicant
Remote or Hybrid
Hiring Remotely in Chicago, IL
114K-200K Annually
Senior level
Remote or Hybrid
Hiring Remotely in Chicago, IL
114K-200K Annually
Senior level
The Risk Manager will advance federal compliance and GRC program maturity, conduct risk assessments, and collaborate with multiple teams to ensure compliance with cybersecurity frameworks.
The summary above was generated by AI
Company Description
It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today - ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500®. Our intelligent cloud-based platform seamlessly connects people, systems, and processes to empower organizations to find smarter, faster, and better ways to work. But this is just the beginning of our journey. Join us as we pursue our purpose to make the world work better for everyone.
Job Description
As the Risk Manager on the Digital Technology GRC team, you will play a central role in advancing our federal compliance posture and GRC program maturity. You will guide initiatives related to CMMC (Cybersecurity Maturity Model Certification) Level 2 readiness, NIST framework implementation, and enterprise-wide risk assessment across infrastructure, endpoints, identity, cloud, and data protection domains.
You will partner closely with Security Architecture, IT Operations, SecOps, Internal Audit, Legal & Compliance, and Executives to assess risk, implement controls, and ensure our organization meets the rigorous standards required for federal contracting.
You will drive compliance and risk management across key areas such as:
  • CMMC 2.0 Level 2 Assessment Readiness & Certification
  • NIST SP 800-171 / NIST CSF Control Mapping & Implementation
  • Enterprise Risk Assessment & Remediation Planning
  • System Security Plans (SSP) & Plan of Action & Milestones (POA&M)
  • GRC Process Maturity & Automation
  • Federal Compliance Documentation & Evidence Management
  • This is a high-impact, high-visibility role designed for someone who combines deep knowledge of federal cybersecurity frameworks with the ability to translate technical compliance requirements into actionable plans and executive-ready communications.

Risk Assessment & Management
  • Conduct comprehensive risk assessments across infrastructure, endpoints, identity management, data protection, and cloud environments.
  • Identify, document, and track security gaps and remediation activities in the enterprise risk register.
  • Perform control effectiveness testing and support continuous monitoring initiatives to ensure ongoing compliance posture.
  • Cross-Functional Collaboration & Communication
  • Partner with Security Architecture, IT Operations, SecOps, Internal Audit, and Legal & Compliance to align security controls and risk mitigation strategies.
  • Translate complex technical findings and compliance status into executive-ready reports, dashboards, and briefings for senior principals.
  • Act as a subject matter expert for CMMC and NIST compliance across the organization, providing guidance and training to stakeholders.

GRC Program & Process Maturity
  • Support the development and maturation of GRC processes, including policy management, control mapping, audit support, and evidence management workflows.
  • Evaluate and recommend GRC tooling and automation opportunities to increase efficiency and accuracy of compliance operations.
  • Contribute to enterprise-wide assessment campaigns and support regulatory change management activities.

What You Get to Do in This Role
ServiceNow Platform & GRC Tooling
  • Leverage ServiceNow IRM (Integrated Risk Management) modules - including Risk Management, Policy & Compliance Management, Audit Management, and Vendor Risk Management - to manage and operationalize compliance workflows.
  • Utilize ServiceNow SecOps (Security Incident Response, Vulnerability Response), CMDB/APM, ITSM, and IT Asset Management to support integrated security and compliance operations.
  • Build and maintain GRC dashboards, reports, and Performance Data views to provide executive visibility into risk posture, control coverage, and compliance status.
  • Drive workflow automation within the ServiceNow platform to streamline evidence collection, control testing, risk scoring, and remediation tracking.

Risk Assessment & Management
  • Conduct comprehensive risk assessments across infrastructure, endpoints, identity management, data protection, and cloud environments.
  • Identify, document, and track security gaps and remediation activities in the enterprise risk register.
  • Perform control effectiveness testing and support continuous monitoring initiatives to ensure ongoing compliance posture.
  • Cross-Functional Collaboration & Communication
  • Partner with Security Architecture, IT Operations, SecOps, Internal Audit, and Legal & Compliance to align security controls and risk mitigation strategies.
  • Translate complex technical findings and compliance status into executive-ready reports, dashboards, and briefings for senior principals
  • Act as a subject matter expert for CMMC and NIST compliance across the organization, providing guidance and training to stakeholders.

GRC Program & Process Maturity
  • Support the development and maturation of GRC processes including policy management, control mapping, audit support, and evidence management workflows.
  • Evaluate and recommend GRC tooling and automation opportunities to increase efficiency and accuracy of compliance operations.
  • Contribute to enterprise-wide assessment campaigns and support regulatory change management activities.
  • ServiceNow Platform & GRC Tooling
  • Leverage ServiceNow IRM (Integrated Risk Management) modules - including Risk Management, Policy & Compliance Management, Audit Management, and Vendor Risk Management - to manage and operationalize compliance workflows.
  • Utilize ServiceNow SecOps (Security Incident Response, Vulnerability Response), CMDB/APM, ITSM, and IT Asset Management to support integrated security and compliance operations.
  • Build and maintain GRC dashboards, reports, and Performance Data views to provide executive visibility into risk posture, control coverage, and compliance status.
  • Drive workflow automation within the ServiceNow platform to streamline evidence collection, control testing, risk scoring, and remediation tracking.

Qualifications
Required
  • 7-8 years of experience in cybersecurity, information security, GRC, or federal compliance roles.
  • Deep working knowledge of CMMC 2.0, NIST SP 800-171, NIST SP 800-53, and NIST Cybersecurity Framework (CSF).
  • Hands-on experience leading or supporting CMMC assessments, including application scoping, control mapping, gap analysis, and remediation planning.
  • Strong understanding of federal contracting compliance requirements, including DFARS 252.204-7012 and CUI (Controlled Unclassified Information) handling.
  • Experience developing and maintaining SSPs, POA&Ms, and compliance documentation for federal authorization.
  • Proven ability to conduct risk assessments across enterprise environments covering endpoints, identity, cloud, and data protection.
  • Working knowledge of the ServiceNow platform, including familiarity with IRM, SecOps, CMDB, or ITSM modules for managing security and compliance workflows.
  • Excellent written and verbal communication skills with demonstrated ability to present technical findings to executive audiences.
  • Experience working cross-functionally with IT, security, audit, and legal teams in a large enterprise environment.

Preferred
  • Professional certifications such as CISSP, CISM, CISA, CAP (Certified Authorization Professional), or CMMC Registered Practitioner (RP).
  • Hands-on experience with ServiceNow IRM (Integrated Risk Management), including Risk Management, Policy & Compliance Management, Audit Management, and Vendor Risk Management modules.
  • Experience with broader ServiceNow platform capabilities including CMDB/APM, SecOps (Security Incident Response, Vulnerability Response), ITSM, and IT Asset Management for integrated security and compliance workflows.
  • Familiarity with ServiceNow reporting, dashboards, Performance Analytics, and workflow automation to drive GRC program efficiency and executive visibility.
  • Familiarity with FedRAMP, FISMA, FIPS 140-2/3 encryption requirements, and DoD cybersecurity policies.
  • Background in evaluating dual-environment architectures (e.g., O365 commercial vs. GCC High) for compliance alignment.
  • Experience with SIEM, EDR (e.g., CrowdStrike), vulnerability management tools, and security architecture review processes.
  • Knowledge of identity and access management frameworks, including Okta, Active Directory, and SailPoint integrations.
  • Prior experience in enterprise-scale assessment campaigns involving 50+ applications or business units.
  • Experience in building or consuming continuous monitoring, control hygiene, or AI-enabled risk/issue automation workflows (e.g., automated control testing, continuous controls monitoring, risk scoring, AI/ML-driven issue remediation).

For positions in this location, we offer a base pay of $114,200 - $199,900, plus equity (when applicable), variable/incentive compensation and benefits. Sales positions generally offer a competitive On Target Earnings (OTE) incentive compensation structure. Please note that the base pay shown is a guideline, and individual total compensation will vary based on factors such as qualifications, skill level, competencies, and work location. We also offer health plans, including flexible spending accounts, a 401(k) Plan with company match, ESPP, matching donations, a flexible time away plan and family leave programs. Compensation is based on the geographic location in which the role is located and is subject to change based on work location.
Additional Information
Work Personas
We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here . To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.
Equal Opportunity Employer
ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.
Accommodations
We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact [email protected] for assistance.
Export Control Regulations
For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.
From Fortune. ©2025 Fortune Media IP Limited. All rights reserved. Used under license.

Top Skills

Cmmc
Edr
Fedramp
Fisma
Irm
Nist Sp 800-171
Nist Sp 800-53
Secops
Servicenow

ServiceNow Los Angeles, California, USA Office

Los Angeles, CA, United States, 92660

Similar Jobs at ServiceNow

6 Days Ago
Remote or Hybrid
140K-245K Annually
Senior level
140K-245K Annually
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
The Senior Manager, Audience Planning drives audience strategies for global Risk & Security marketing through data insights, collaboration with teams, and regional adaptation.
Top Skills: Claude AiGwiPower BIWorkfront
4 Hours Ago
Remote or Hybrid
173K-238K Annually
Expert/Leader
173K-238K Annually
Expert/Leader
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
The AI Product Portfolio Director leads the integration of AI in marketing processes, defines strategic roadmaps, and evaluates AI tools to enhance productivity and decision-making, while aligning cross-functional stakeholders to achieve measurable growth and operational efficiency.
Top Skills: AIMartech
4 Hours Ago
Remote or Hybrid
149K-233K Annually
Senior level
149K-233K Annually
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
The CRM Strategic Partnerships Technical Program Manager will oversee partner advisory boards, provide technical advisory on CRM integrations, and manage partner enablement programs to enhance product features in collaboration with the service teams.
Top Skills: AIAPIsConfigurable Product & Guided SellingCRMCustomer Service ManagementField Service ManagementSaaSSales And Order ManagementSales Force AutomationServicenow

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account