Cybersecurity Risk Management Analyst
As a Cybersecurity Risk Analyst on our Cyber GRC Engineering team, you will apply engineering, automation, and data analytics principles to strengthen governance, risk, and compliance across Chubb’s cybersecurity environment. You will serve as a hands-on platform specialist for ServiceNow IRM, helping optimize and enhance the GRC ecosystem so it continues to meet Chubb’s evolving cybersecurity analytics, compliance, and risk management needs. In this role, you will connect data, controls, and risk signals to drive deeper risk analysis, proactively identify potential issues before risk is realized, and support executive reporting on application security exposure and broader cybersecurity risk. You will also play a key role in managing the platform, including how data is reviewed, how workflows are executed, and how AI capabilities are leveraged within the platform to improve automation, insight generation, and operational efficiency.
In this role, you will:
- Design and implement automated control testing workflows in partnership with the Cyber Risk & Assurance Manager, including detailed automation playbooks for compliance and control testing
- Own and enhance ServiceNow IRM workflows, including issue and exception management, automated ticketing, and compliance tracking
- Implement and maintain automated risk scoring and InfoSec criticality rating calculations based on methodology defined by the Cyber Risk Assessment team, while ensuring the logic remains aligned as the methodology evolves
- Build and maintain custom workflows, connectors, and integrations within ServiceNow IRM to support expanding GRC Engineering use cases
- Analyze control, risk, and exception data to identify trends, validate potential gaps, and surface issues that require remediation before they become realized risk
- Support executive reporting by translating technical findings into clear, actionable insight on application security risk and broader cybersecurity exposure
- Help optimize the GRC platform through automation, AI-enabled capabilities, and workflow improvements that strengthen Chubb’s cybersecurity analytics and risk management posture
- Partner cross-functionally to ensure the platform ecosystem continues to support Chubb’s broader technical environment and evolving security requirements
- A minimum of 5 years of experience in GRC technology, IT automation, or security platform engineering
- Hands-on ServiceNow development experience, with strong preference for the IRM module; experience with other GRC modules and/or platforms is also acceptable
- Demonstrated Python scripting experience in a production or automation environment
- Experience supporting cyber risk, compliance, or audit functions
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent practical experience
- ServiceNow certification, such as CIS-IRM or equivalent, is a plus
- Experience with API and integration development for platform connectors is a plus
- Familiarity with insurance or financial services risk and compliance environments is a plus