Cybersecurity Service and Change Management Lead
About the role
The Cybersecurity Service and Change Management Lead role at 3M is designed for professionals with experience in Cybersecurity, IT Service Management, or Change/Release Management. This position focuses on driving excellence within the Cybersecurity organization by designing, implementing, and continuously improving the Cybersecurity service catalog, service management processes, and change management framework.
Responsibilities
Cybersecurity service catalog development and maintenance
Establish and maintain process for catalog changes, including review, and approval, versioning and changelog
Coordinate service owners to update and maintain service management tools in alignment with service catalogue to enable accurate request routing, reporting, and portfolio visibility
Publish and socialize the catalog to improve discoverability and adoption; capture feedback for continuous improvement
Cybersecurity Change Management Process Design and Improvement
Design, document, and continuously improve the Cybersecurity change management process aligned to ITIL/ISO 27001/NIST CSF and the IT change management process
Facilitate process-mapping and optimization workshops across Cybersecurity functions
Understand and enforce criteria for Tier 4 Cybersecurity changes
Drive risk assessment, impact analysis and executive-level approvals for Tier 4 changes; ensure cross-functional sign-offs
Orchestrate readiness reviews, test plans, back-out strategies, and stakeholder communications for Tier 4 changes
Present and champion Cybersecurity changes at the Tier 4 IT CAB
Change Request Review and Enforcement
Review change requests for completeness, risk rating, operational impact, and required artifacts (test evidence, rollback plan, approver list)
Enforce process requirements, SLAs, and quality standards; reject or remediate inadequate change requests
Maintain segregation of duties, least privilege, and production access controls during change execution
Lead post-implementation reviews (PIRs) and root-cause analysis of failed changes
IT Change Management Alignment
Act as Cybersecurity POC for enterprise IT Change Management
Drive alignment with IT definitions for standard/normal/emergency changes and integrate with IT release management, incident, and problem management
Requirements
- Bachelor’s degree in Information Systems, Cybersecurity, Computer Science, Business or technology field (completed and verified prior to start)
- Seven (7) years of experience in Cybersecurity, IT Service Management, or Change/Release Management in a private, public, government or military environment
- Deep knowledge of ITIL Change Enablement, Service Management, NIST CSF, and ISO/IEC 27001 frameworks
- Experience managing enterprise change and service management processes including CAB leadership and service catalog development
- Proficiency with enterprise change, workflow, and GRC tools
- Strong understanding of cybersecurity domains such as IAM, network/cloud security, SIEM/SOAR, and vulnerability management
- Proven ability to assess risk, manage stakeholder communication, and coordinate complex, high-impact changes across global teams
- ITIL 4 Managing Professional or Change Enablement certification
- Cybersecurity certification such as CISSP or CISPM
- MP, PRINCE2, or Prosci certification (nice to have)
Qualifications
- Work location: On-site at the 3M Center in Maplewood, MN, with at least four days a week commitment. May include up to 5% domestic travel.
- Relocation: Authorization may be provided.
- Must be legally authorized to work in country of employment without sponsorship for employment visa status (e.g., H1B status).
Benefits
Pay & Benefits Overview: https://www.3m.com/3M/en_US/careers-us/working-at-3M/benefits/