Desired Competencies (Technical / Behavioral Competency)
Must-Have
- Configure and implement ServiceNow GRC / IRM applications : Policy & Compliance, Risk, Audit Management, Vendor Risk.
- Define and map Authority Documents, Citations, and Controls; establish continuous monitoring indicators.
- Automate risk assessment questionnaires, policy exception workflows, and evidence collection using Flow Designer.
- Develop custom risk and compliance dashboards, reports, and performance indicators.
- Integrate GRC / IRM with vulnerability, security incident, and third‑party risk data sources via IntegrationHub or APIs.
- Ensure data integrity and segregation of duties within GRC tables.
- Collaborate with Security, Audit, and Business teams to translate requirements into platform configurations.
- Produce and maintain solution design documents, test scripts, and user guides.
Good-to-Have
Knowledge of regulatory frameworks such as ISO 27001, NIST CSF, GDPR, SOX.Experience with ServiceNow Operational Resilience or Continuous Authorization & Monitoring modules.Exposure to SecOps Vulnerability Response or Security Incident Response.Familiarity with Archer, MetricStream, or similar GRC tools.Basic scripting in JavaScript, Python, or PowerShell.Relevant certifications such as ITIL v4, CISA, CRISC, or CISSP.