Senior ServiceNow Security Engineer
CognosanteAbout the role
Security Clearance required:
Public TrustDo you want to make a difference?
Cognosante employees are passionate about improving people’s lives. With an innovative mindset and an unwavering commitment to those we serve, we partner with healthcare, civilian and defense agencies to deliver exceptional public services and programs. Our multi-faceted technology and customer experience (CX) solutions achieve program outcomes, solve critical challenges and create meaningful change. Whether we are helping Veterans access healthcare faster, ensuring that members of the military complete their missions safely, or helping people obtain health insurance, our work touches millions of people. Are you ready to make a difference?
The Senior ServiceNow Security Engineer will play a critical role in leading Hybrid Agile development projects within a Software Development and Support program using ServiceNow’s Enterprise Service Management (ESM) platform for a federal agency. The primary mission of the projects is to modernize IT Service Management for the agency through the adoption of best practices, process optimization, and continual service improvement. Embracing a DevSecOps methodology, the agency leverages various ServiceNow modules including ITSM (IT Service Management), SPM (Strategic Portfolio Management), ITOM (IT Operations Management), Customer Service Management, among other workflows. The ServiceNow Security Engineer's primary role will involve providing development (configuration) support as a member of an Agile Design or Development Scrum team, focusing on the configuration and management of security settings within the ServiceNow platform to ensure the integrity, confidentiality, and availability of information. The Senior ServiceNow Security Engineer will have experience in developing/reviewing security plans, processes, and strategies to identify areas for improvement or update. The Senior ServiceNow Security Engineer will also understand security regulations, directives for organizational and agency level requirements, and experience in designing and implementing security requirements into products and systems.
The Senior Security Engineer is responsible for all activities related to designing, implementing, documenting, and maintaining the appropriate security posture for projects and solutions implemented for state or federal government contracts. Typical tasks associated with this role include specifying and documenting security control requirements, developing system security plans, performing risk assessments, supporting security control assessments, and working with development and implementation team members to ensure that all security requirements are adequately addressed. The Senior Security Engineer also identifies relevant security and privacy standards and regulations applicable to systems under development or in operation and helps ensure compliance with those standards and regulations. This position is contingent upon contract award.
What will I get to do?
- Establishes strategic direction, policies, and procedures for the organizations informatics for information systems.
- Analyze systems, data, and operating environments to determine appropriate security controls
- Produce and manage key authorization package documentation, including System Security Plans, Contingency Plans, Risk Assessment Reports, Security Test Plans, Plans of Action and Milestones, Privacy Impact Assessments, and related artifacts
- Guides the selection, development, and/or implementation of highly complex, technical systems designed to effectively manage clinical information, data, and clinical systems in the healthcare or other specialized fields
- Configures and manage security settings within the ServiceNow platform to safeguard against unauthorized access and data breaches, ensuring alignment with security policies and regulations.
- Develop, implement, and maintain security protocols within the ServiceNow environment, collaborating with other IT teams for secure integration with other enterprise systems.
- Conducts vulnerability assessments of the ServiceNow environment, develop and execute threat mitigation strategies, and promptly respond to security incidents.
- Participates in Agile Scrum meetings, contributing to the continuous improvement of security practices within the development lifecycle.
- Works closely with the DevSecOps team to integrate security practices into the entire software development and deployment lifecycle.
- Provides expertise in ServiceNow security best practices to the development team and stakeholders.
- Leads the development of security documentation, including security plans, incident response plans, and standard operating procedures.
- Leads the development and review of system architecture and system design documentation to identify
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s