
Staff Business Systems Analyst | Security Programs
- Milwaukee, WI
- Permanent
- Full-time
- Partner with security and compliance stakeholders to understand objectives, workflows, and pain points; translate these into detailed functional requirements and user stories.
- Conduct and facilitate requirements gathering for projects related to risk management, security tooling, audit automation, vendor security, and data protection.
- Perform gap analyses and identify opportunities for security process improvements using data and systems expertise.
- Conduct data analysis to validate requirements, support metrics, and monitor post-implementation effectiveness (e.g., SLA, security incident volume, audit closure rates).
- Lead cross-functional initiatives that span enterprise systems (e.g., GRC, Risk, Vendor Risk, Policy, IRM, SecOps), ensuring security and compliance requirements are embedded early in the lifecycle.
- Coordinate operational activities for multiple security-related projects simultaneously.
- Serve as a key liaison between Security, IT, and Engineering teams.
- Facilitate User Acceptance Testing for security tooling and workflow changes, guiding testers and resolving technical issues.
- Support change management activities, including the creation of training materials, process documentation, and operational support (e.g., office hours).
- Facilitate documentation, update, or deprecation of internal security policies and standards as required.
- Track security-related issues, defects, and findings across tools; gather evidence and ensure timely resolution or risk acceptance.
- Act as Scrum Master using Agile methodologies, leading sprint ceremonies and tracking delivery of security enhancements.
- Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving. This may include using AI-powered tools, automating workflows, analyzing AI-driven insights, or exploring AI’s potential impact on the function or industry.
- Security and Risk Platforms – Familiarity with GRC, IRM, SecOps, or vendor risk tools, ideally within the ServiceNow ecosystem.
- Business Process Modeling – Document and optimize security workflows using tools like Visio, Lucid, or Miro.
- Requirements Documentation – Write functional specifications, security user stories, and use cases tailored to InfoSec needs.
- Data Analysis & Reporting – Use SQL, Excel, Tableau, or Power BI to support risk reporting, compliance KPIs, and audit metrics.
- SDLC & Secure Development Awareness – Understand how to embed security into Agile/DevOps cycles and development pipelines.
- Process Improvement – Apply Lean or Six Sigma principles to enhance security workflows.
- Agile & Scrum – Strong facilitation of sprint planning, backlog grooming, and iterative delivery in a security context.
- Strong collaboration between technical and non-technical security stakeholders.
- Ability to simplify complex security and compliance concepts for business partners.
- High attention to detail in handling audit and risk data.
- Critical thinking and problem-solving under evolving security requirements.
- Ability to manage ambiguity and balance competing priorities across risk, compliance, and delivery.
- 8 or more years of experience in Business Systems Analysis, with at least 3 years supporting security, GRC, or risk/compliance domains.
- Demonstrated experience working with InfoSec teams, GRC platforms (ideally ServiceNow), or leading audits and remediation projects.
- Experience delivering technical solutions in cross-functional environments, preferably within a SaaS or cloud enterprise.
- Proven success as a project or Scrum lead on security or compliance-related initiatives.
- Bachelor's degree in information systems, Cybersecurity, Computer Science, or related field.
- Industry certifications such as CISA, CRISC, CISSP, CGEIT, or PMP are a plus.
- Familiarity with security standards and frameworks (e.g., ISO 27001, NIST, SOC 2, FedRAMP, PCI-DSS).