Talent.com
Risk Manager
Risk ManagerServiceNow • Addison, TX, United States
No longer accepting applications
Risk Manager

Risk Manager

ServiceNow • Addison, TX, United States
30+ days ago
Job type
  • Full-time
Job description
Company Description

It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today - ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500®. Our intelligent cloud-based platform seamlessly connects people, systems, and processes to empower organizations to find smarter, faster, and better ways to work. But this is just the beginning of our journey. Join us as we pursue our purpose to make the world work better for everyone.

Job Description

As the Risk Manager on the Digital Technology GRC team, you will play a central role in advancing our federal compliance posture and GRC program maturity. You will guide initiatives related to CMMC (Cybersecurity Maturity Model Certification) Level 2 readiness, NIST framework implementation, and enterprise-wide risk assessment across infrastructure, endpoints, identity, cloud, and data protection domains.

You will partner closely with Security Architecture, IT Operations, SecOps, Internal Audit, Legal & Compliance, and Executives to assess risk, implement controls, and ensure our organization meets the rigorous standards required for federal contracting.

You will drive compliance and risk management across key areas such as:
  • CMMC 2.0 Level 2 Assessment Readiness & Certification
  • NIST SP 800-171 / NIST CSF Control Mapping & Implementation
  • Enterprise Risk Assessment & Remediation Planning
  • System Security Plans (SSP) & Plan of Action & Milestones (POA&M)
  • GRC Process Maturity & Automation
  • Federal Compliance Documentation & Evidence Management
  • This is a high-impact, high-visibility role designed for someone who combines deep knowledge of federal cybersecurity frameworks with the ability to translate technical compliance requirements into actionable plans and executive-ready communications.
Risk Assessment & Management
  • Conduct comprehensive risk assessments across infrastructure, endpoints, identity management, data protection, and cloud environments.
  • Identify, document, and track security gaps and remediation activities in the enterprise risk register.
  • Perform control effectiveness testing and support continuous monitoring initiatives to ensure ongoing compliance posture.
  • Cross-Functional Collaboration & Communication
  • Partner with Security Architecture, IT Operations, SecOps, Internal Audit, and Legal & Compliance to align security controls and risk mitigation strategies.
  • Translate complex technical findings and compliance status into executive-ready reports, dashboards, and briefings for senior principals.
  • Act as a subject matter expert for CMMC and NIST compliance across the organization, providing guidance and training to stakeholders.
GRC Program & Process Maturity
  • Support the development and maturation of GRC processes, including policy management, control mapping, audit support, and evidence management workflows.
  • Evaluate and recommend GRC tooling and automation opportunities to increase efficiency and accuracy of compliance operations.
  • Contribute to enterprise-wide assessment campaigns and support regulatory change management activities.
What You Get to Do in This Role

ServiceNow Platform & GRC Tooling
  • Leverage ServiceNow IRM (Integrated Risk Management) modules - including Risk Management, Policy & Compliance Management, Audit Management, and Vendor Risk Management - to manage and operationalize compliance workflows.
  • Utilize ServiceNow SecOps (Security Incident Response, Vulnerability Response), CMDB/APM, ITSM, and IT Asset Management to support integrated security and compliance operations.
  • Build and maintain GRC dashboards, reports, and Performance Data views to provide executive visibility into risk posture, control coverage, and compliance status.
  • Drive workflow automation within the ServiceNow platform to streamline evidence collection, control testing, risk scoring, and remediation tracking.
Risk Assessment & Management
  • Conduct comprehensive risk assessments across infrastructure, endpoints, identity management, data protection, and cloud environments.
  • Identify, document, and track security gaps and remediation activities in the enterprise risk register.
  • Perform control effectiveness testing and support continuous monitoring initiatives to ensure ongoing compliance posture.
  • Cross-Functional Collaboration & Communication
  • Partner with Security Architecture, IT Operations, SecOps, Internal Audit, and Legal & Compliance to align security controls and risk mitigation strategies.
  • Translate complex technical findings and compliance status into executive-ready reports, dashboards, and briefings for senior principals
  • Act as a subject matter expert for CMMC and NIST compliance across the organization, providing guidance and training to stakeholders.
GRC Program & Process Maturity
  • Support the development and maturation of GRC processes including policy management, control mapping, audit support, and evidence management workflows.
  • Evaluate and recommend GRC tooling and automation opportunities to increase efficiency and accuracy of compliance operations.
  • Contribute to enterprise-wide assessment campaigns and support regulatory change management activities.
  • ServiceNow Platform & GRC Tooling
  • Leverage ServiceNow IRM (Integrated Risk Management) modules - including Risk Management, Policy & Compliance Management, Audit Management, and Vendor Risk Management - to manage and operationalize compliance workflows.
  • Utilize ServiceNow SecOps (Security Incident Response, Vulnerability Response), CMDB/APM, ITSM, and IT Asset Management to support integrated security and compliance operations.
  • Build and maintain GRC dashboards, reports, and Performance Data views to provide executive visibility into risk posture, control coverage, and compliance status.
  • Drive workflow automation within the ServiceNow platform to streamline evidence collection, control testing, risk scoring, and remediation tracking.
Qualifications

Required
  • 7-8 years of experience in cybersecurity, information security, GRC, or federal compliance roles.
  • Deep working knowledge of CMMC 2.0, NIST SP 800-171, NIST SP 800-53, and NIST Cybersecurity Framework (CSF).
  • Hands-on experience leading or supporting CMMC assessments, including application scoping, control mapping, gap analysis, and remediation planning.
  • Strong understanding of federal contracting compliance requirements, including DFARS 252.204-7012 and CUI (Controlled Unclassified Information) handling.
  • Experience developing and maintaining SSPs, POA&Ms, and compliance documentation for federal authorization.
  • Proven ability to conduct risk assessments across enterprise environments covering endpoints, identity, cloud, and data protection.
  • Working knowledge of the ServiceNow platform, including familiarity with IRM, SecOps, CMDB, or ITSM modules for managing security and compliance workflows.
  • Excellent written and verbal communication skills with demonstrated ability to present technical findings to executive audiences.
  • Experience working cross-functionally with IT, security, audit, and legal teams in a large enterprise environment.
Preferred
  • Professional certifications such as CISSP, CISM, CISA, CAP (Certified Authorization Professional), or CMMC Registered Practitioner (RP).
  • Hands-on experience with ServiceNow IRM (Integrated Risk Management), including Risk Management, Policy & Compliance Management, Audit Management, and Vendor Risk Management modules.
  • Experience with broader ServiceNow platform capabilities including CMDB/APM, SecOps (Security Incident Response, Vulnerability Response), ITSM, and IT Asset Management for integrated security and compliance workflows.
  • Familiarity with ServiceNow reporting, dashboards, Performance Analytics, and workflow automation to drive GRC program efficiency and executive visibility.
  • Familiarity with FedRAMP, FISMA, FIPS 140-2/3 encryption requirements, and DoD cybersecurity policies.
  • Background in evaluating dual-environment architectures (e.g., O365 commercial vs. GCC High) for compliance alignment.
  • Experience with SIEM, EDR (e.g., CrowdStrike), vulnerability management tools, and security architecture review processes.
  • Knowledge of identity and access management frameworks, including Okta, Active Directory, and SailPoint integrations.
  • Prior experience in enterprise-scale assessment campaigns involving 50+ applications or business units.
  • Experience in building or consuming continuous monitoring, control hygiene, or AI-enabled risk/issue automation workflows (e.g., automated control testing, continuous controls monitoring, risk scoring, AI/ML-driven issue remediation).

For positions in this location, we offer a base pay of $114,200 - $199,900, plus equity (when applicable), variable/incentive compensation and benefits. Sales positions generally offer a competitive On Target Earnings (OTE) incentive compensation structure. Please note that the base pay shown is a guideline, and individual total compensation will vary based on factors such as qualifications, skill level, competencies, and work location. We also offer health plans, including flexible spending accounts, a 401(k) Plan with company match, ESPP, matching donations, a flexible time away plan and family leave programs. Compensation is based on the geographic location in which the role is located and is subject to change based on work location.

Additional Information

Work Personas

We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here. To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.

Equal Opportunity Employer

ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.

Accommodations

We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact globaltalentss@servicenow.com for assistance.

Export Control Regulations

For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.

From Fortune. ©2025 Fortune Media IP Limited. All rights reserved. Used under license.
Create a job alert for this search

Risk Manager • Addison, TX, United States

Similar jobs

Risk Manager

Lincoln Property CompanyDallas, TX, United States
Full-time

The Risk Manager supports executive leadership by developing and implementing insurance solutions for the organization.Successful solutions are based on a deep understanding of the business model o...Show more

 • Promoted

Risk Manager

TradeJobsWorkforce75086 Plano, TX, US
Full-time

Risk Manager job responsibilities: Leads the identification, communication, measurement, and management of company-wide risk.Manages insurance procurement, develops and implements risk management a...Show more

 • Promoted

Risk Appetite, Strategic and Reputation Risk Manager

Busey BankDallas, Texas, United States
Full-time

The Risk Appetite, Strategic, and Reputation Risk Manager supports First Busey Corporation's management team and Board of Directors in the timely identification of Top and Emerging Risks, providing...Show more

 • Promoted

Credit Card Risk and Analytics Manager

First HorizonDallas, TX, United States
Full-time

Credit Card Risk And Analytics Manager.Location: On site at location listed in job posting.Summary: The Credit Card Risk and Analytics Manager will lead, plan, and direct the credit risk modeling a...Show more

 • Promoted

Risk Management- Counterparty Credit Risk- Associate

JPMorgan ChasePlano, TX, United States
Full-time

Risk Management- Counterparty Credit Risk- Associate.Bring your expertise to JPMorgan Chase.As part of Risk Management and Compliance, you are at the center of keeping JPMorgan Chase strong and res...Show more

 • Promoted

Risk Manager

TradeJobsWorkForce75024 Plano, TX, US
Full-time

Risk Manager Job Duties: Leads the identification, communication, measurement, and management of company-wide risk.Manages insurance procurement, develops and implements risk management and c...Show more

 • Promoted

Risk Management Advisor - Experienced

C1 Insurance GroupDallas, TX, United States
Full-time

As an Advisor you are building a book of business starting from zero (with a competitive base salary).Not afraid to prospect, your business grows out of your networks, connections and relationships...Show more

 • Promoted

Senior Engagement Lead - Property Risk Consultant- Digital Infrastructure

Oliver Wyman, LLCDallas, TX, United States
Full-time

We are seeking a talented individual to join our team at Marsh as a qualified Property Risk Consultant for our US Digital Infrastructure team based in the U.Risk Consultants advise client companies...Show more

 • Promoted

Risk Manager

LincolnDallas, TX, United States
Full-time

The Risk Manager supports executive leadership by developing and implementing insurance solutions for the organization.Successful solutions are based on a deep understanding of the business model o...Show more

 • Promoted

Chief Risk Officer — Enterprise Risk Leader (Hybrid)

BestmansolutionsDallas, TX, United States
Full-time

A mid-sized financial services firm is seeking a Chief Risk Officer based in Dallas, Texas, to lead and shape the enterprise risk management framework.This senior role requires substantial leadersh...Show more

 • Promoted

Senior Credit Risk Director — Fintech Growth & Analytics

Varo BankDallas, TX, United States
Full-time

A digital bank based in Texas is seeking a Credit Risk Director to oversee risk management in its lending business.The ideal candidate will have over 6 years of experience in consumer credit risk a...Show more

 • Promoted

Risk Management - Credit Risk Associate - Infrastructure & Green Economy

ChasePlano, TX, United States
Full-time

Bring your expertise to JPMorganChase.As part of Risk Management and Compliance, you are at the center of keeping JPMorgan Chase strong and resilient.You help the firm grow its business in a respon...Show more

 • Promoted

Dir of Audit & Enterprise Risk

North Texas Tollway AuthorityPlano, TX, United States
Full-time

Location: Plano - Corporate Headquarters.Show more

 • Promoted • New!

Audit Manager - Counterparty Credit Risk

CCG Business SolutionsPlano, TX, United States
Full-time

Audit Manager - Counterparty Credit Risk.CCG Talent Management is not only a business solutions company but a company that believes success starts with the individual.CCG Business Solutions has bee...Show more

 • Promoted

Risk, Enterprise Risk (Frameworks), Associate, Dallas

Goldman SachsDallas, TX, United States
Full-time

Enterprise Risk Management - Risk Architecture Associate.The Enterprise Risk Management team is responsible for ensuring that the firm's risks are managed systemically, such that the firm has a reg...Show more

 • Promoted

Senior Associate, Risk Manager- Controls Tester

Capital OnePlano, TX, United States
Full-time +1

Senior Associate, Risk Manager- Controls Tester.As a Sr Risk Associate in the Financial Services Auto Risk Office, you will provide professional risk judgment that enables business partners to tack...Show more

 • Promoted

Manager, Risk and Assurance

Hudson Advisors L.P.Plano, TX, United States
Full-time

Hudson Advisors is seeking a diligent and driven Manager to join our Risk and Assurance team.In this high-visibility role, you will lead and execute operational, financial, and compliance reviews f...Show more

 • Promoted

Credit Risk Director

Varo BankDallas, TX, United States
Full-time

Varo is an entirely new kind of bank.All digital, mission-driven, FDIC insured and designed for the way our customers live their lives.Varo Bank, the first all-digital national bank, is seeking a p...Show more