Posted on: 01/07/2026
9+ years of Experience in :
- ServiceNow Certified System Administrator (CSA) (Mandatory), ServiceNow CIS Risk & Compliance or IRM (Mandatory); CIS VRM/Audit; ServiceNow CAD is a plus.
- Additional certifications in ITIL, or other relevant frameworks are a plus such Industry certifications such as ISO 27001 LA/LI, CISA, CRISC, CIA, or FAIR are an advantage.
Technical Skills :
The following are highlighted entrepreneurial competencies and core expectations for the job/role :
- Policy & Compliance : Authority docs, citations, profiles, control objectives, indicators, attestations, and automated evidence collection.
- Risk Management : Risk registers, scripted scoring models, KRIs, assessments, statements, treatment plans, and risk response workflows.
- Audit Management : Engagements, scoping, workpapers, test plans, issues, and evidence automation.
- Vendor Risk Management : Vendor tiering, assessments, inherent/residual scoring, findings and remediation, and data integrations.
- Develop and customize GRC applications, Engineer catalog items / record producers that trigger GRC workflows and approvals, Extend and configure GRC tables.
- Experience mapping model regulatory frameworks (ISO 27001, SOC 2, SOX, GDPR, NIST, COBIT etc.) into control libraries, assignments and map them to policies and assets.
- Establish robust RBAC using roles, ACLs, data policies, encryption, and table/field-level security; secure GRC tables, records, and attachments with proper segregation.
- Align GRC data model with CSDM and CMDB to relate risks, controls, policies, issues, and services.
- Optimize platform performance : indexing, query best practices, and guardrails for large data volumes.
- Partner with InfoSec, Internal Audit, Compliance, and Risk Owners to operationalize GRC workflows and continuous improvements.
- Practical knowledge of Policy & Compliance, Risk Management, Audit Management, and Vendor Risk Management modules.
- Ability to design risk scoring models, KRIs, CMIs, treatment plans, and issue remediation workflows.
- IRM Enterprise capabilities (Advanced Risk, Risk Quantification/FAIR, enterprise CSDM alignment).
- Exposure to Security Operations (Vulnerability Response, Incident Response) and SIEM/DevOps integrations (Splunk, Sentinel).
- Background in Internal Audit, ITGC/SOX, InfoSec, or Data Privacy.
- Domain separation, encryption strategies, and multi-tenant designs.
- Strong troubleshooting skill set to support daily operations of GRC module and custom applications built on the ServiceNow platform.
- Experience integrating ServiceNow with external systems and platforms (e.g., API integrations, IntegrationHub, and MID Server for secure data flow).
- Ingest risk, vulnerability, and compliance data from external sources (e.g., Qualys, Tenable, Rapid7, cloud CSPs).
- Develop reports, dashboards, and KPIs for risk and compliance visibility.
- Expertise in ServiceNow development : JavaScript, GlideScript, ServiceNow scripting (client, server, business rules, etc.).
- Ability to support, build and configure within the Event Management and Discovery platforms on the Service Now platform.
- Strong experience with ServiceNow GRC/ITIL modules, including Governance, Risk, Compliance, Change, Asset, and Request Management.
- Familiarity with cloud technologies, especially in healthcare environments (e.g., AWS, Azure).
Did you find something suspicious?
Posted by
Posted in
Platform Engineering / SAP/Oracle
Functional Area
Other Software Development
Job Code
1650315