Senior Technical Consultant - Risk & Security -ServiceNow (Global Role)
Mexico City, MX Mexico City, MX
Atos is the Atos Group brand dedicated to AI-powered, secure, end-to-end digital services. Atos designs, develops, and operates critical digital environments that drive performance, resilience and sovereignty, helping public and private organizations worldwide retain control over their data and infrastructures, while meeting regulatory requirements.
With more than 54,000 employees serving over 4,500 clients across 54 countries, Atos helps modernize core IT systems, accelerate cloud and data transformation, strengthen cybersecurity, and deliver secure digital workplace environments to support its clients, its employees and society. Atos also provides consulting and advisory services through its Atos Amplify brand.
A trusted partner in operating complex and mission-critical environments, Atos supports organizations across highly regulated and sovereign contexts.
About Atos Group
Atos Group is a global leader in digital transformation with c. 56,000 employees and annual revenue of c. €7.2 billion (at the go-forward perimeter), operating in 54 countries under two brands - Atos for services and Eviden for products and systems. European number one in cybersecurity and a leader in cloud, Atos Group is committed to a secure and decarbonized future and provides tailored AI-powered, end-to-end solutions for all industries. Atos Group is listed on Euronext Paris.
Senior Technical Consultant - Risk & Security -ServiceNow (Global role)
Role Summary
We are looking for an experienced ServiceNow Risk and Security Engineer who will be responsible for the technical design, configuration, implementation, integration and continuous improvement of enterprise ServiceNow GRC/IRM and Security Operations solutions. The role translates risk, regulatory, compliance, cybersecurity, incident response, vulnerability management and operational requirements into secure, scalable, supportable and upgrade-safe ServiceNow designs.
In this global role, you will design and deliver next-generation AI-powered solutions, intelligent workflows, and reusable accelerators that strengthen our ServiceNow portfolio and help shape the future of digital transformation.
The candidate must communicate credibly with senior executives, CISOs, risk and compliance leaders, internal audit, control owners, legal and security teams, SOC leadership, incident response teams, vulnerability management teams, architects and technical delivery resources. Excellent written and verbal communication skills in English are mandatory.
Key Responsibilities
- Implementation and solution delivery
- Lead technical delivery from discovery and requirements through design, configuration, testing, deployment, hypercare and transition to support.
- Configure ServiceNow GRC/IRM capabilities including Policy and Compliance Management, Risk Management, Audit Management, Operational Risk, Regulatory Change, issues and remediation, indicators, attestations, evidence and control testing.
- Configure ServiceNow SecOps capabilities including Security Incident Response, Vulnerability Response, Threat Intelligence, Major Security Incident Management, phishing response and relevant cloud, application, infrastructure and operational technology vulnerability capabilities.
- Configure authority documents, policies, controls, risks, entities, profiles, scoring models, vulnerable items, remediation tasks, response tasks, investigation workflows, prioritization rules, exceptions, deferrals, dashboards, workspaces and executive reporting.
- Apply ServiceNow product guidance, platform standards, secure development practices, data-protection requirements and upgrade-safe configuration principles.
- Design and architecture support
- Provide detailed technical and product design input to Solution, Technical, Enterprise, Security and Integration Architects.
- Recommend appropriate GRC/IRM and SecOps capabilities, data structures, workflow designs, integrations, access controls, security models and implementation patterns, balancing out-of-the-box functionality, configuration, orchestration, low-code and custom development.
- Contribute to solution designs, configuration workbooks, data models, interface specifications, deployment plans, estimates, architecture decisions and technical risk assessments.
- Assess interactions with the wider cybersecurity, risk, compliance and IT operations ecosystem, identifying product constraints, licensing considerations, dependencies, risks and design trade-offs.
- Challenge requirements that introduce unnecessary customization, duplicate tooling, technical debt, security weaknesses, data risk or upgrade complexity.
- Stakeholder and requirements management
- Lead or support workshops with senior executives, CISOs, SOC leaders, risk and compliance teams, internal audit, legal, cybersecurity, process owners, control owners, incident responders, vulnerability managers, threat intelligence teams, IT operations, application owners, infrastructure teams and technical stakeholders.
- Translate strategic risk, compliance, cybersecurity and operational objectives into functional and technical requirements, user stories, acceptance criteria, process flows, data requirements, integration requirements and non-functional requirements.
- Assess existing processes, tools, queues, spreadsheets, integrations and manual activities to identify opportunities for standardization, automation, risk reduction and improved reporting.
- Explain ServiceNow capabilities, limitations, dependencies, costs, risks and design implications clearly to executive and technical audiences and facilitate timely design decisions.
- Technical configuration, integration and data
- Perform advanced ServiceNow configuration using tables, forms, fields, workspaces, roles, groups, access controls, Flow Designer, playbooks, business rules, client scripts, UI policies, notifications and scheduled processes.
- Develop or configure integrations using JavaScript, Glide APIs, REST/SOAP services, IntegrationHub, import sets, transform maps, authentication methods and event-driven integration patterns.
- Integrate with identity, security, vulnerability, CMDB, asset, ERP, HR, document, regulatory-content, third-party risk, reporting, SIEM, SOAR, vulnerability scanners, endpoint and network detection tools, threat intelligence providers, email-security platforms, cloud-security tools, application-security tools and collaboration systems.
- Design ingestion, transformation, normalization, correlation, enrichment, reconciliation, monitoring, error handling, encryption, auditability and support requirements.
- Align risks, controls, incidents and vulnerabilities with configuration items, applications, business services, owners, locations and organizational entities using CSDM and CMDB data, authoritative sources, identification rules, reconciliation, synchronization and data-quality controls.
- Support migration and validation of policies, controls, risks, issues, evidence, audit records, regulatory content, security incidents, vulnerable items and organizational data.
- Risk, compliance, incident response and vulnerability management
- Implement GRC/IRM workflows for control design and effectiveness, risk assessment, risk scoring, appetite and tolerance, attestations, testing, evidence collection, regulatory obligations, issues and remediation, indicators and continuous monitoring.
- Implement SecOps workflows for incident triage, investigation, containment, eradication, recovery, closure, evidence capture, communications, chain-of-custody and post-incident review.
- Configure risk-based vulnerability prioritization using severity, exploitability, threat intelligence, asset criticality, exposure, service impact and business context.
- Configure vulnerability groups, assignment rules, remediation tasks, service-level targets, exceptions, deferrals, false positives, scanner synchronization, backlog reporting and executive risk-reduction views.
- Support Third-Party Risk Management, Business Continuity Management and integration with wider enterprise security and risk operating models where in scope.
- Testing, governance and leadership
- Develop and review unit, system, integration, regression and user acceptance test materials; investigate defects and resolve configuration, security, integration, workflow, data and performance issues.
- Support release planning, code review, deployment, validation, rollback, Automated Test Framework usage, production hypercare, knowledge transfer and operational handover.
- Ensure compliance with development standards, security policies, data-protection requirements, change controls, least-privilege access, segregation of duties, requirements traceability, peer review, security review and architecture governance.
- Provide technical leadership to consultants, developers, analysts, administrators and integration specialists; review deliverables and contribute reusable methods, templates, accelerators and integration patterns.
- Support pre-sales activities including discovery, solution shaping, demonstrations, estimates, proposals, statements of work and customer presentations.
Mandatory Qualifications and Experience
- Current ServiceNow certification relevant to either GRC/IRM or Security Operations, such as Certified Implementation Specialist - Risk and Compliance, Certified Implementation Specialist - Security Incident Response, Certified Implementation Specialist - Vulnerability Response or current equivalent credentials.
- Proven experience implementing ServiceNow GRC/IRM and/or Security Operations in complex enterprise environments, including multiple end-to-end implementations.
- Strong knowledge of ServiceNow risk, compliance and security architecture, data structures, workflows, security, reporting, integrations, CMDB alignment and enterprise operating models.
- ServiceNow Certified Technical Architect (CTA) – highly preferred
- Excellent soft skills – executive communication (written/verbal), adaptability, problem solving, teamwork, relationship building, dependability, and organization
- At least 3 x Certified Implementation Specialist certificates
- Extensive hands-on experience architecting and delivering ServiceNow solutions
- Proven success leading technically complex implementations
- Ability to lead technical discussions confidently with customers and stakeholders
- Prior consulting experience
- Experience leading teams and supervising others
- Proven experience engineering and supporting ServiceNow in complex enterprise environments.
- Proven ability to provide detailed product and technical design input to ServiceNow Solution and Technical Architects.
- Experience translating risk, compliance, audit, regulatory, cybersecurity, incident response, vulnerability management and operational requirements into implementable ServiceNow designs.
- Experience working directly with senior executives, CISOs, security leaders, risk and compliance leaders, internal audit, legal, security, control-owner teams, SOC, incident response, vulnerability management, threat intelligence, IT operations, infrastructure and application teams.
- Strong ServiceNow configuration and development skills, including JavaScript, Glide APIs, REST APIs, IntegrationHub, import sets, transform maps, authentication and technical documentation.
- Experience integrating ServiceNow with security, identity, vulnerability, CMDB, asset, reporting, SIEM, SOAR, scanner, endpoint, threat intelligence and enterprise data platforms.
- Excellent written and verbal English, including the ability to lead workshops, manage conflicting priorities and present complex recommendations to executive and technical audiences.
- Ability to work independently, manage competing priorities and deliver high-quality outputs within agreed timescales.
Expected Experience
- Typically eight or more years of cybersecurity, risk technology, security technology or enterprise application experience.
- Five or more years of hands-on ServiceNow experience, with three or more years in ServiceNow GRC/IRM, SecOps or adjacent risk and security implementation work.
- Delivery experience across at least two substantial end-to-end ServiceNow implementations in GRC/IRM, Security Incident Response, Vulnerability Response or comparable risk and security domains.
- Experience in large, regulated, multinational, government, financial services, healthcare, energy, utilities, telecommunications, critical-infrastructure, defence or comparable environments is preferred.
Technical and Domain Knowledge
- The candidate should demonstrate practical knowledge across ServiceNow GRC/IRM and Security Operations, including Policy and Compliance Management, enterprise and operational risk, risk assessment, scoring, appetite and tolerance, Audit Management, control design and effectiveness, attestations, testing and evidence, issues and remediation, indicators and continuous monitoring, regulatory obligations, Security Incident Response, Vulnerability Response, major security incidents, threat intelligence, response playbooks, evidence and audit requirements, risk-based vulnerability remediation, SIEM and SOAR, vulnerability scanners, EDR and NDR, cloud and application-security tooling, Flow Designer, IntegrationHub, JavaScript and Glide APIs, REST/SOAP integrations, data migration, reporting, dashboards and workspaces, CSDM and CMDB, role-based access controls, Automated Test Framework, release management and upgrade-safe implementation.
- Framework familiarity is preferred across ISO 27001, ISO 31000, NIST, NIST CSF, NIST 800-61, COBIT, COSO, CIS Controls, MITRE ATT&CK, CVSS, OWASP, SOC 2, PCI DSS, SOX, GDPR, DORA, HIPAA or comparable standards and regulations.
Preferred Qualifications
- ServiceNow Certified System Administrator, Certified Application Developer or additional relevant implementation credentials.
- One or more additional ServiceNow certifications across Risk and Compliance, Security Incident Response, Vulnerability Response, Performance Analytics, IntegrationHub or Automated Test Framework.
- Professional risk, audit, security or compliance qualification such as CISSP, CISM, GIAC, Security+, CEH or equivalent experience.
- Experience integrating GRC/IRM with SecOps, ITSM, ITOM, CMDB, Strategic Portfolio Management, HR Service Delivery, Customer Service Management, SOC tooling and enterprise data platforms.
- Experience supporting ServiceNow pre-sales, solution shaping, demonstrations, estimates, proposals and statements of work.
Professional Competencies and Key Deliverables
Competencies
- Structured analysis and problem-solving with the ability to connect business risk, regulatory obligations, security operations and technical implementation choices.
- Credibility with executives, CISOs, security professionals, risk and compliance leaders, internal audit, legal teams and technical specialists.
- Strong facilitation, presentation, negotiation and stakeholder management skills.
- Confidence to challenge unclear, inappropriate, insecure or over-customized requirements while communicating risks and constraints objectively.
- Professionalism, integrity, confidentiality, discretion and effectiveness during priority incidents or high-visibility governance discussions.
- Ability to work effectively across distributed teams with a commitment to mentoring, reusable delivery methods and continuous improvement.
Measures of Success
- Secure, maintainable and scalable solutions that conform to approved architecture, ServiceNow standards and enterprise security requirements.
- Accurate translation of business, regulatory, cybersecurity and operational requirements into working functionality delivered to agreed milestones.
- Effective management of technical risks, dependencies, defects and sensitive data, supported by complete documentation and successful operational handover.
- Strong customer confidence, stakeholder collaboration and adoption of the implemented GRC/IRM and SecOps capabilities.
- Visible improvement in risk transparency, control effectiveness, incident handling, vulnerability prioritization, remediation outcomes and executive reporting quality.
Working Arrangements
The role will be primarily remote, although on-site work may be required depending on customer and project needs. The candidate must be willing to participate in workshops, governance meetings, security exercises, critical delivery activities, priority incident activities and critical deployments across global time zones.
Here at Atos, diversity and inclusion are embedded in our DNA. Read more about our commitment to a fair work environment for all.
Atos is a recognized leader in its industry across Environment, Social and Governance (ESG) criteria. Find out more on our CSR commitment.
Choose your future. Choose Atos.