Job Summary
We are seeking a Senior ServiceNow GRC Solution Architect to design and implement enterprise-wide Governance, Risk, and Compliance (GRC) solutions using ServiceNow IRM/GRC. The role will lead the architecture of cyber risk management capabilities, automate risk processes, and provide enterprise visibility through dashboards, reporting, and remediation tracking.
Roles and Responsibilities
- Design and implement enterprise Cyber Risk Register solutions using ServiceNow GRC/IRM.
- Architect workflows for risk identification, assessment, scoring, mitigation, escalation, and remediation.
- Translate business, cybersecurity, and GRC requirements into scalable ServiceNow solutions.
- Develop risk dashboards, reports, metrics, and executive-level risk visibility.
- Integrate ServiceNow GRC with security, IT, and enterprise platforms while ensuring data integrity and auditability.
- Lead solution architecture across requirements gathering, design, implementation, testing, deployment, and post-production support.
- Partner with business leaders, IT teams, risk committees, and senior stakeholders to define GRC strategy and gain consensus.
- Ensure GRC solutions align with cybersecurity controls, governance requirements, and regulatory standards.
- Support enterprise risk governance, compliance, audit readiness, and continuous process improvement.
Required Skills & Qualifications
- 8–15+ years of overall IT experience with 2–5+ years in GRC, risk management, or cybersecurity.
- Strong hands‑on experience architecting and implementing ServiceNow GRC/IRM solutions.
- Expertise in ServiceNow platform architecture, workflows, integrations, reporting, dashboards, and automation.
- Strong knowledge of NIST Cybersecurity Framework (CSF) and NIST SP 800-53.
- Experience designing solutions for large, complex enterprise environments.
- Strong understanding of cybersecurity risk, controls, compliance, and remediation processes.
- Excellent stakeholder management, communication, presentation, and consensus‑building skills.
- Ability to work across business, technology, cybersecurity, and risk teams.
Preferred Qualifications
- Experience in public sector, transportation, transit, or travel industries.
- Knowledge of enterprise risk architecture and information management.
- Understanding of secure SDLC and cybersecurity governance practices.
- ServiceNow GRC/IRM certifications are a plus.