About the company
ServiceNow is the AI control tower for business reinvention. Our ServiceNow AI platform brings together any AI, any data, and any workflow— helping 85% of the Fortune 500® work smarter, faster, and better.
Responsibilities
- Orchestration of response and remediation of incident response for highest criticality security events.
- Take ownership and lead response to critical incidents within the company.
- Establish and mature documentation surrounding protocols and procedures governing the security incident command team.
- Prepare and deliver communications, including executive summaries and incident briefings, to key stakeholders during and after incident response.
- Conduct rapid response, mitigation, and investigations on the highest priority cases impacting ServiceNow and user data.
- Partner with the team members across multiple regions to drive response and investigations globally.
- Organization and facilitation of scenario-based exercises to test and improve incident management and response strategies.
- Maintenance of existing playbooks and procedures, as well as developing new ones, to further standardize SIC and its partners' responses when verifying MSIs.
- Contribute to the organization and completion of Post-Incident Reviews (PIRs) and Root Cause Analyses (RCAs) following major security incidents.
- Identify new ways to simplify, integrate, automate and refine the major security incident process to better support internal and external stakeholders.
Requirements
- Experience in security incident response and management.
- Strong communication and leadership skills.
- Ability to coordinate multiple response workstreams.
- Experience with tabletop exercises and playbook development.
- Knowledge of security frameworks and best practices.