Key Responsibilities :
Configure and implement ServiceNow IRM / GRC modules, including :
- Risk Management
- Policy & Compliance Management
- Vendor / Third-Party Risk
- Audit Management
- Lead project-level implementation cycles : gather client requirements, architect solutions, configure workflows, integrate systems, and deploy IRM modules with best practices.
- Conduct stakeholder workshops (Risk, Compliance, Security, Audit teams) to translate business needs into actionable GRC solutions.
- Build technical documentation including architecture diagrams, integration blueprints, configuration standards, and governance frameworks.
- Manage solutions lifecycle : support upgrades, administer configurations, troubleshoot issues, and maintain optimal system health.
- Develop integrations with external systems (e.g., GRC platforms, risk tools, APIs, iPaaS) using REST, SOAP, MID Server, and other integration mechanisms.
- Apply industry-standard risk frameworks (e.g., COSO, COBIT, FAIR) in IRM implementations, ensuring compliance with SOX, GDPR, ISO, NIST regulations.
Required Skills & Qualifications
3-7+ years of experience in ServiceNow implementation, with specific focus on IRM / GRC modules.Hands-on configuration and development experience with ServiceNow IRM / GRC modules (Policy & Compliance, Risk, Audit, Vendor Risk).Proficiency in JavaScript, Scripting (e.g., Business Rules, Script Includes), Flow Designer, and ServiceNow development tools (Studio, UI Builder) .Expertise in solution architecture, requirement analysis, implementation of risk compliance processes, and configurable components.Strong understanding of risk frameworks and IRM methodology.Experience in stakeholder management, technical documentation, and cross-functional team (preferred) :ServiceNow Certified Application Developer (CAD)Certified Implementation Specialist IRM / GRCServiceNow System AdministratorOptional Enhancements :
Exposure to Vendor Risk Management or Third-Party Risk modules (TPRM)Background in BFSI (Banking, Financial Services, Insurance), healthcare, or enterprise environmentsIntegration experience with mid-tier tools (e.g., MuleSoft) or legacy GRC platforms.(ref : hirist.tech)