Risk & Security Solution Designer - ServiceNow

2 weeks ago


Oklahoma City, OK, United States KPMG Full time

Known for being a great place to work and build a career, KPMG provides audit, tax and advisory services for organizations in today's most important industries. Our growth is driven by delivering real results for our clients. It's also enabled by our culture, which encourages individual development, embraces an inclusive environment, rewards innovative excellence and supports our communities. With qualities like those, it's no wonder we're consistently ranked among the best companies to work for by Fortune Magazine, Consulting Magazine, Seramount, Fair360 and others. If you're as passionate about your future as we are, join our team.

KPMG is currently seeking a Risk & Security Solution Designer - ServiceNow to join our Digital Nexus technology organization. This is a hybrid work opportunity.

Responsibilities:
  • Collaborate with stakeholders across Risk, Compliance, Audit, and Security to understand business needs and design scalable, secure, and maintainable solutions across the ServiceNow IRM and Security portfolios
  • Lead the architecture and delivery of ServiceNow's integrated risk and security solutions, including IRM modules (Policy and Compliance, Risk Management, Audit Management, Vendor Risk), Security Operations (SecOps), Business Continuity (BCM), and custom security applications (CSI, FSW, and more)
  • Build integrations between ServiceNow (IRM and Security modules) and external GRC platforms, security tools, data lakes, and enterprise systems using APIs, MID servers, and iPaaS tools such as Mulesoft
  • Provide technical guidance and support to development teams throughout the risk and security solution lifecycle, including risk scoring models, automated control testing, and workflow design
  • Partner with Enterprise Architecture to ensure IRM and Security solutions align with broader platform strategy and regulatory requirements (such as SOX, GDPR, NIST, ISO); serve as an escalation point for complex IRM and Security issues, collaborating with ServiceNow support and internal teams to resolve critical technical challenges
  • Create and maintain comprehensive technical documentation including architecture diagrams, configuration standards, and governance models specific to IRM and Security implementations; Stay current with the ServiceNow platform roadmap (including IRM and SecOps), risk frameworks (such as COSO, COBIT, FAIR), and emerging technologies relevant to integrated risk management
  • Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
Qualifications:
  • Minimum eight years of recent experience in ServiceNow solution architecture; minimum three years of recent experience focused on IRM, GRC, and Security Operations implementations
  • Bachelor's degree from an accredited college or university is preferred; ServiceNow Certified Application Developer (CAD) and Certified Implementation Specialist- IRM required; CIS - Security Operations, CTA, or CMA is strongly preferred
  • Extensive experience designing and supporting ServiceNow modules such as Security Operations, Business Continuity (BCM), Policy and Compliance, Risk Management, and Vendor Risk
  • Strong understanding of risk and security frameworks (such as, COSO, COBIT, FAIR, NIST, ISO) and how they map to ServiceNow capabilities; proven experience supporting ServiceNow solutions from a developer or administrator perspective, including upgrades, integrations, and operational support
  • Familiarity with interconnected ServiceNow modules and core data structures across the platform
  • Excellent communication and collaboration skills, with the ability to influence risk and security strategy through technology
  • Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future; KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa)

KPMG LLP and its affiliates and subsidiaries ("KPMG") complies with all local/state regulations regarding displaying salary ranges. If required, the ranges displayed below or via the URL below are specifically for those potential hires who will work in the location(s) listed. Any offered salary is determined based on relevant factors such as applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications and market considerations. In addition, KPMG is proud to offer a comprehensive, competitive benefits package, with options designed to help you make the best decisions for yourself, your family, and your lifestyle. Available benefits are based on eligibility. Our Total Rewards package includes a variety of medical and dental plans, vision coverage, disability and life insurance, 401(k) plans, and a robust suite of personal well-being benefits to support your mental health. Depending on job classification, standard work hours, and years of service, KPMG provides Personal Time Off per fiscal year. Additionally, each year KPMG publishes a calendar of holidays to be observed during the year and provides eligible employees two breaks each year where employees will not be required to use Personal Time Off; one is at year end and the other is around the July 4th holiday. Additional details about our benefits can be found towards the bottom of our KPMG US Careers site at Benefits & How We Work.
Follow this link to obtain salary ranges by city outside of CA:
https://kpmg.com/us/en/how-we-work/pay-transparency.html/?id=6687_9_25

KPMG offers a comprehensive compensation and benefits package. KPMG is an equal opportunity employer. KPMG complies with all applicable federal, state and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other category protected by applicable federal, state or local laws. The attached link contains further information regarding KPMG's compliance with federal, state and local recruitment and hiring laws. No phone calls or agencies please.
KPMG recruits on a rolling basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) for which they are qualified that is also of interest to them.
Los Angeles County applicants: Material job duties for this position are listed above. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, and safeguard business operations and company reputation. Pursuant to the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers, Fair Chance Initiative for Hiring Ordinance, and San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

  • Oklahoma City, OK, United States CompuCom Full time

    Compucom Systems, Inc. provides end-to-end IT managed services to enable the digital workplace for enterprise, midsize and small businesses. To enable our clients to focus on what matters most, we employ a customer-centric, hard-working, and talented group of people that Act Like an Owner, Do the Right Thing, and Have Fun Doing It! We're looking for a Sr....


  • Oklahoma City, OK, United States 532 Group LLC Full time

    "Government Services, As They Should Be" 532 Group exists to make change happen. We are a federal consulting firm dedicated to making government services effective, extensible, scalable, and secure. Our knowledge and experience allow us to see beyond the superficial and dig deep into the underlying cause of a problem - developing innovative solutions that...


  • Oklahoma City, OK, United States Cayuse Holdings Full time

    Overview Job Title: ServiceNow Implementation Consultant Location: Remote (US) Job Type: Independent Contractor Pay Rate: $40-$50 per hour About Cayuse Commercial Cayuse Commercial Services (CCS) delivers fresh solutions to business challenges in the technology and business services environment. Services available are application development, business...


  • Oklahoma City, OK, United States MidFirst Bank Full time

    Description The Security Risk and Compliance Analyst is a member of the information security team and works closely with the other members of the team, the business, and other IT staff to develop and manage security for one or more IT functional area (e.g., data, systems, network, and physical) across the enterprise. The candidate will be able to effectively...


  • Oklahoma City, OK, United States MidFirst Bank Full time

    Description The Security Risk and Compliance Analyst is a member of the information security team and works closely with the other members of the team, the business, and other IT staff to develop and manage security for one or more IT functional area (e.g., data, systems, network, and physical) across the enterprise. The candidate will be able to effectively...


  • Oklahoma City, OK, United States MidFirst Bank Full time

    Description The Security Risk and Compliance Analyst is a member of the information security team and works closely with the other members of the team, the business, and other IT staff to develop and manage security for one or more IT functional area (e.g., data, systems, network, and physical) across the enterprise. The candidate will be able to effectively...


  • Oklahoma City, OK, United States MidFirst Bank Full time

    Description The Security Risk and Compliance Analyst is a member of the information security team and works closely with the other members of the team, the business, and other IT staff to develop and manage security for one or more IT functional area (e.g., data, systems, network, and physical) across the enterprise. The candidate will be able to effectively...


  • Oklahoma City, OK, United States TWO95 International Full time

    Title: Information Security Risk Analyst Location: Oklahoma City, OK Type: Full-time Salary: DOE Requirement: Under senior staff supervision, assist in information security policy development, maintenance and auditing; security policy education, training, and awareness activities; monitor compliance with security policy and applicable law. Participate in...


  • Oklahoma City, OK, United States TWO95 International Full time

    Title: Information Security Risk Analyst Location: Oklahoma City, OK Type: Full-time Salary: DOE Requirement: Under senior staff supervision, assist in information security policy development, maintenance and auditing; security policy education, training, and awareness activities; monitor compliance with security policy and applicable law. Participate in...


  • Oklahoma City, OK, United States Acrisure LLC Full time

    Department:Information Security Reports to: Senior Director, Information Security Role Summary You will be a hands-on engineer responsible for securing and managing endpoints across a modern, hybrid enterprise. You'll design and enforce endpoint security baselines, automate compliance, and leverage Microsoft Intune to maintain strong, measurable protection....