Senior ServiceNow Cyber Risk Architect
Lumen Solutions Group Inc. · Washington, DC · 2 wk ago
RemoteRemoteOTHRContract
About the role
We are seeking a Senior ServiceNow Cyber Risk Architect to lead the design and implementation of an enterprise Cyber Risk Register within ServiceNow. This role will establish a scalable and auditable solution for cyber-risk intake, assessment, ownership, remediation, workflow automation, and executive reporting.
Key Responsibilities
- Architect and implement an enterprise Cyber Risk Register using ServiceNow IRM/GRC
- Design end-to-end risk workflows covering intake, assessment, scoring, approvals, remediation, exceptions, and closure
- Develop ServiceNow data models, forms, workflows, dashboards, reports, notifications, roles, and integrations
- Define risk documentation for inherent/residual risk, controls, treatment plans, evidence, and remediation status
- Partner with Cybersecurity, Risk, Compliance, Audit, IT, and business stakeholders to translate requirements into scalable solutions
- Lead solution design, testing, deployment, documentation, and knowledge transfer
- Identify integration opportunities with CMDB, vulnerability management, security operations, controls, audit, and asset data
Required Qualifications
- Strong senior-level ServiceNow architecture and implementation experience
- Hands-on experience with ServiceNow IRM/GRC or enterprise risk-management solutions
- Strong understanding of cyber risk management, risk scoring, risk acceptance, remediation, controls, and audit evidence
- Experience with ServiceNow workflows, data models, reporting, dashboards, integrations, and role-based access
- Strong stakeholder management and ability to lead requirements and solution-design sessions
Preferred
- ServiceNow IRM/GRC, Security Operations, or Vulnerability Response experience
- ServiceNow CSA, CAD, CIS-Risk and Compliance, or CIS-Security Operations certification
- Knowledge of NIST CSF, NIST 800-53, ISO 27001, CIS Controls, FAIR, or similar frameworks
- Experience in large, regulated or complex enterprise environments