Cybersecurity Sr. Risk Analyst

Spectraforce Technologies

North Chicago (IL)

On-site

USD 90,000 - 130,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Spectraforce Technologies is seeking a Cybersecurity Sr. Risk Analyst to join our onsite team in North Chicago, IL. The role focuses on risk assessment, governance, and ServiceNow-based workflows within a vendor risk program.

You will translate business needs into requirements, develop use cases, and support UAT and testing activities. Responsibilities include evaluating cyber risk, documenting requirements, managing enhancements, and delivering metrics and dashboards to drive risk-informed

Qualifications

  • 3+ years of experience in cybersecurity risk analysis or related field.
  • Bachelor's degree in Information Security, Computer Science, or related field.
  • Experience in business analysis, including requirements gathering and test case development.

Responsibilities

  • Evaluate, assess, and monitor cybersecurity and third-party risk activities.
  • Partner with stakeholders to gather, analyze, and document business requirements for risk processes.
  • Develop use cases, user stories, process maps, and functional requirements for cybersecurity and GRC initiatives.
  • Coordinate and execute system testing activities including UAT and defect tracking.
  • Collaborate with technical teams to support solution design and deployment.
  • Develop metrics, reporting, and dashboards to provide visibility into risk posture.

Skills

ServiceNow
GRC
Risk analysis
UAT
Business analysis
Stakeholder management

Education

Bachelor's degree in Information Security / CS

Tools

ServiceNow

Job description

Title: Cybersecurity Sr. Risk Analyst

Location: North Chicago, IL 60064 (Onsite)

Duration: 12 months

We are seeking a highly skilled Cybersecurity Sr. Risk Analyst / ServiceNow Business Analyst with a unique blend of cybersecurity risk management expertise, ServiceNow platform experience, and strong business analysis capabilities. The ideal candidate will possess demonstrated experience translating business requirements into actionable solutions, developing business use cases, documenting functional requirements, coordinating user acceptance testing (UAT), and driving platform enhancements from concept through implementation.

The successful candidate will have a strong understanding of Governance, Risk, and Compliance (GRC) principles and frameworks, coupled with the ability to analyze business processes, identify opportunities for improvement, and support the optimization of risk management workflows through technology-enabled solutions. This role requires a strategic thinker who can bridge the gap between cybersecurity, business stakeholders, and technical teams to drive informed risk-based decisions and continuous process improvement.

As a member of the Cybersecurity Vendor Risk Management team, this role will evaluate and monitor third-party risks while serving as a key liaison between business stakeholders and technology teams. Responsibilities include gathering and documenting business requirements, developing detailed use cases and process flows, managing enhancement requests, supporting system configuration and testing activities, and ensuring risk management processes are effectively supported through enterprise platforms and tools.

Key Responsibilities:
  • Evaluate, assess, and monitor cybersecurity and third-party risk activities in alignment with organizational risk management objectives.
  • Partner with business stakeholders to gather, analyze, and document business requirements for risk management processes and technology solutions.
  • Develop business use cases, user stories, process maps, and functional requirements to support cybersecurity and GRC initiatives.
  • Manage and prioritize enhancement requests, ensuring business needs are clearly documented and translated into actionable development requirements.
  • Coordinate and execute system testing activities, including test strategy development, test script creation, user acceptance testing (UAT), defect tracking, and validation of implemented solutions.
  • Collaborate with technical teams to support solution design, implementation, and deployment activities.
  • Analyze existing workflows and identify opportunities to improve operational efficiency, data quality, automation, and user experience.
  • Act as a liaison between cybersecurity teams, business stakeholders, and technology partners to ensure successful delivery of enhancements and process improvements.
  • Support data governance and stewardship activities to ensure the integrity, accuracy, and consistency of information used in risk management processes.
  • Develop metrics, reporting, and dashboards to provide visibility into risk posture, operational performance, and program effectiveness.
  • Participate in risk assessments, control evaluations, and remediation tracking activities.
  • Prepare business and technical documentation, including requirements, testing artifacts, training materials, and process documentation.
  • Support audit, compliance, and regulatory activities by providing documentation and evidence related to cybersecurity risk management processes and system controls.
Preferred Qualifications
  • Demonstrated experience as a ServiceNow Analyst, Business Analyst, or Product Owner supporting enterprise workflows and business process improvements.
  • Strong understanding of cybersecurity risk management, third-party risk management, and GRC processes.
  • Experience developing business requirements, use cases, user stories, workflow diagrams, and testing documentation.
  • Proven experience managing enhancement requests and driving projects through the full solution lifecycle, from requirements gathering through testing and implementation.
  • Experience leading or coordinating User Acceptance Testing (UAT) and defect management processes.
  • Strong analytical, problem-solving, communication, and stakeholder management skills.
  • Ability to translate complex business requirements into functional solutions that align with organizational objectives.
  • Experience working in cross-functional environments involving business, cybersecurity, risk, compliance, and technology teams.
Minimum Education/Experience:
  • Bachelor's degree in Information Security, Computer Science, or related field; or equivalent experience.
  • 3+ years of experience in cybersecurity risk analysis or related field.
  • Strong analytical skills, ability to work independently, and collaborative interpersonal skills.
  • Experience in business analysis, including requirements gathering and test case development.
Preferred Experience:
  • Experience with ServiceNow or similar vendor management software.
  • Understanding of procurement and risk processes.
  • Knowledge of information security and risk control frameworks.
  • Familiarity with ISO 27001, SOC 2, HITRUST, FedRAMP, and ISO 22301 standards.
  • Operational experience with GRC toolsets.
  • CISSP/CISM certification (or similar).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Risk & GRC Analyst (ServiceNow)
Senior Cybersecurity Risk & GRC Analyst (ServiceNow)

Spectraforce Technologies • North Chicago (IL)

On-site
USD 90,000 - 130,000
Cybersecurity Risk Analyst & ServiceNow BA (Onsite, 12m)
Cybersecurity Risk Analyst & ServiceNow BA (Onsite, 12m)

Abbott • North Chicago (IL)

On-site
USD 100,000 - 140,000
Medical plan
Dental plan
Vision plan
+5
ServiceNow IRM Senior Developer
ServiceNow IRM Senior Developer

Siri InfoSolutions Inc • Chicago (IL)

On-site
USD 120,000 - 170,000
ServiceNow Business Analyst - IRM/GRC
ServiceNow Business Analyst - IRM/GRC

Veriipro • United States

On-site
USD 110,000 - 160,000
ServiceNow Security & Risk Developer
ServiceNow Security & Risk Developer

Veriipro • United States

On-site
USD 120,000 - 160,000
Senior ServiceNow GRC Architect
Senior ServiceNow GRC Architect

Randstad North America, Inc. • United States

On-site
USD 140,000 - 190,000
Senior ServiceNow GRC Solution Architect
Senior ServiceNow GRC Solution Architect

Veriipro • Washington

On-site
USD 150,000 - 190,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade, LLC. • Oxford (MS)

On-site
USD 110,000 - 160,000
ServiceNow SecOps Senior Developer
ServiceNow SecOps Senior Developer

Siri InfoSolutions Inc • Chicago (IL)

On-site
USD 120,000 - 150,000
ServiceNow GRC Solution Architect
ServiceNow GRC Solution Architect

Net2Source (N2S) • Atlanta (GA)

On-site