Role Title: ServiceNow GRC / IRM – Lead Solution Advisor
Experience: 5–7 years relevant ServiceNow (GRC/IRM)
Primary Modules Needed: IRM (Integrated Risk Management), SIR (Security Incident Response), VR (Vulnerability Response), TPRM (Third Party Risk Management), BCM (Business Continuity Management)
Certifications (Must): ServiceNow CSA (Certified System Administrator)
Lead configuration + development on ServiceNow with strong understanding of platform security, operations, and exception handling.
Define solution architecture for ServiceNow implementations (data/object model, workflows, access controls).
Convert requirements into epics/user stories, build mock-ups, and drive delivery hands-on.
Own end-to-end use case delivery: workflow configuration, customizations, testing support, and deployments to higher environments.
Conduct code reviews and enforce ServiceNow best practices.
Build/maintain integrations using APIs/web services/connectors.
Enable/support internal teams with training and complex configuration guidance.
Support pre-sales / solution discussions within the domain when needed.
5–7 years ServiceNow experience with strong IRM/GRC delivery exposure.
Hands-on with: Workspace, UI Builder, Flow Designer / complex workflows.
Strong scripting/config: Business Rules, Client Scripts, UI Policies, UI Scripts, UI Actions, UI Pages, Script Includes, ACLs.
Integrations: REST/SOAP/APIs and connectors (preferred).
Platform management: deployments, upgrades, troubleshooting.
Delivered 2–3+ end-to-end projects (req → build → go-live).
Strong documentation + communication; able to work with distributed teams.
SecOps / IRM implementations: Risk, Audit, Policy, Vendor Risk, SIR, VR, TPRM.
Exposure to ITAM / SAM / HAM / CMDB.
Certifications: CAD, CIS – Risk & Compliance, CIS – SIR, CIS – TPRM, CIS – VR.
Knowledge of GRC roadmap + tools like RSA Archer / MetricStream.
The work sits within Cyber Strategy & Transformation: governance, risk assessments, compliance, third-party risk, security posture programs, cyber transformation, risk analytics & reporting.


