Senior IT Security Analyst
U.S. citizenship is required for this position due to Department of Defense restrictions.
About the role
Our Senior Security Policy Analyst develops, implements, and maintains security policies, standards, and procedures while leveraging ServiceNow to streamline policy management, compliance tracking, and reporting. This role combines deep knowledge of cybersecurity frameworks with hands-on experience in governance, risk, and compliance (GRC) operations, excels at clear communication and high-quality documentation, and actively supports security awareness and responsible AI initiatives.
The base pay offered for this position may vary within the posted range based on your job-related knowledge, skills, and experience. Work location preference is hybrid within Wisconsin, with secondary consideration for remote candidates in Wisconsin, Illinois, Michigan, Minnesota, and Iowa. Non-local candidates should expect frequent monthly travel to WPS Headquarters in Madison, WI.
Responsibilities
- Develop, review, and maintain corporate security policies, standards, procedures, and guidelines in alignment with NIST CSF, regulatory requirements, and industry best practices.
- Integrate and manage security policies, controls, and risk assessments within ServiceNow IRM and Managed Documents.
- Conduct risk assessments, control evaluations, and gap analyses mapped to NIST CSF to support audit readiness and compliance initiatives.
- Collaborate with IT, Risk, Compliance, and Business teams to ensure policy adoption and awareness across the organization.
- Create clear, concise, and actionable security documentation, including policies, procedures, guidance, and reports.
- Monitor compliance with internal policies and external regulatory requirements, identifying gaps and driving remediation efforts.
- Provide reports and analytics on policy adherence, exceptions, and trends using ServiceNow dashboards and workflows.
- Serve as a subject matter expert on security governance, NIST CSF implementation, and risk management best practices.
- Mentor junior analysts and provide guidance on policy development, implementation, and ServiceNow utilization.
- Develop security awareness training programs to educate employees on corporate security policies, procedures, and best practices.
- Support AI governance awareness programs to inform employees about responsible AI use, ethical considerations, and regulatory requirements.
- Maintain and update training materials to reflect changes in policies, regulations, or emerging AI and cybersecurity threats.
- Assess and monitor third-party vendors to ensure compliance with company security policies and industry regulations.
Requirements
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, Network Security, or related field, or equivalent combination of education and experience.
- 5 or more years of experience in security policy, governance, risk, and compliance roles.
- Strong working knowledge of NIST CSF and AI governance principles, as well as other cybersecurity frameworks such as ISO 27001, CIS, or SOC 2.
- Strong knowledge and understanding of cloud security policies, configuration standards, and best practices for AWS, Azure, GCP, or SaaS applications.
- Demonstrated experience with ServiceNow IRM modules, including policy, risk, audit, and compliance workflows.
- Ability to create clear, professional, and actionable security and risk governance documentation.
- Experience developing and delivering security awareness training programs.
- Excellent communication skills, capable of engaging both technical and non-technical stakeholders.
- Demonstrated experience in developing and implementing security policies and standards in a highly regulated environment.
- Strong analytical, organizational, and project management skills, with the ability to drive initiatives independently.
Preferred Qualifications
- Familiarity with KnowBe4 or other security awareness platform tools.
- Familiarity using AI to facilitate automated workflows.
Remote Work Requirements
- High-speed cable or fiber internet connection.
- Minimum of 10 Mbps downstream and at least 1 Mbps upstream (can be checked at speedtest.net).
Pay
Salary Range: $90,000 – $115,000
Benefits
- Remote and hybrid work options available.
- Performance bonus and/or merit increase opportunities.
- 401(k) with a 100% match for the first 3% of your salary and a 50% match for the next 2% (100% vested immediately).
- Competitive paid time off.
- Health insurance, dental insurance, and telehealth services starting on day 1.
- Professional and Leadership Development Programs.
About Us
WPS, a health solutions company, is a leading not-for-profit health insurer and federal government contractor headquartered in Madison, Wisconsin. WPS offers health insurance plans for individuals, families, seniors, and group health plans for small to large businesses. We process claims and provide customer support for Medicare beneficiaries and manage benefits for millions of active-duty and retired military personnel across the U.S. and abroad. WPS has been making healthcare easier for nearly 80 years and is proud to be military and veteran ready.
Culture
WPS’ culture fosters an open and empowering employee experience, recognizing engagement as an investment in our workforce. We leverage diverse perspectives to drive agility and innovation on high-performing teams, encouraging employees to bring their authentic selves to work. Our culture has earned recognition from local and national organizations.