Senior Information Security Analyst
ServiceNow
Dublin, Ireland
Job Description
Responsibilities on the role:
- Represent security organization in customer-facing Security Incidents, cases, Security findings, tasks and questions and calls related to Security & Privacy.
- Own, triage, investigate and respond to security matters of ServiceNow platform, ensuring timely communication, resolution and enhance customer experience and processes.
- Act as the primary point of contact for all security-related matters in ServiceNow, supporting both internal and external stakeholders.
- Facilitate the efficient workflow/triage of security-related incidents/cases by collaborating with customers and other internal ServiceNow teams.
- Build and maintain a high level of customer trust and confidence through exceptional service and communication.
- Customer Outreach Communications on Security & escalation handling.
- Understand and deliver excellent capability maturity models to fine tune Security processes.
- Create and enhance documentation and processes to strengthen security maturity and operational excellence.
- Develop and deliver training/enablement programs on Security, for internal and external customers on security awareness and best practices.
- Develop AI Solutions for automating repetitive activities & design new solutions leveraging AI.
- Work with Legal on security/privacy-related matters & a global team spread across different time zones, so flexibility of times is required.
- Provide support and be available as a responsible resource for the On-Call rotation (weekends, public holidays, and after hours) as rostered.
Qualifications
To be successful in this role, you have:
- Experience: A minimum of 3-5+ years of professional experience in information security or application security roles.
- Certifications: Relevant certifications are highly preferred, including but not limited to:
- Required: ServiceNow Certified System Administrator (CSA).
- Preferred (Two or more): Azure AI Fundamentals, AWS Certified AI Practitioner, Offensive Security Web Assessor (OSWA), GIAC Web Application Penetration Tester (GWAPT), GIAC Security Essentials Certification (GSEC), GIAC Certified Incident Handler (GCIH), CISSP, CISM.
Skills & Competencies
- Technical Skills:
- Solid understanding of cloud computing models and major hyperscaler cloud models.
- Hands-on experience with using and understanding security tools and technologies, including: SIEM solutions, logging tools, load balancers, firewalls, WAFs, IDS/IPS, vulnerability management platforms, encryption techniques etc.
- Basic to Intermediate-level programming knowledge in Java/JavaScript with the ability to read, interpret & understand to explain code effectively.
- Intermediate to Advanced proficiency in using web proxy tools for security testing and assessments.
- Application Security: In-depth understanding of web application vulnerabilities (e.g., OWASP Top Ten) and corresponding mitigation strategies.
- Risk Management: Ability to clearly explain security risks to non-technical stakeholders using straightforward, non-technical language.
- Compliance & Regulatory Knowledge: Good knowledge of key compliance and regulatory frameworks including: NIST, CIS, GDPR, HIPAA, PCI DSS, ISO standards etc.
- Artificial Intelligence: Experience working with AI technologies and designing AI-based solutions.
- Analytical Thinking: Strong analytical and problem-solving capabilities, with the ability to evaluate and address complex security challenges.
- Communication: Excellent verbal and written communication skills, with the ability to convey technical information to non-technical audience.
- Team Collaboration: Demonstrated ability to thrive in a team-oriented, collaborative environment working in a follow the sun model.
- Security Concepts: Good understanding of Security concepts and articulating Security and risk in simple terms without using jargons and make sense to customers.
- Education: Bachelor’s degree in computer science or information security or relevant information security experience.
- Preferred Additional Experience: Hands-on experience with web-based vulnerability exploitation and experience is a strong plus to succeed in this role.
Don't forget to mention EuroTechJobs when applying.