ServiceNow GRC Consultant

DivIHN Integration
United States
24 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

JavaScript (Programming Language) Configuration Management Databases Cyber Security Information Systems System Configuration PCI Data Security Standards SOAPAPI Information Technology CIS Benchmarks Servicenow

Job description

  • We seek a senior consultant to lead a full ServiceNow GRC build for a state agency.
  • The agency owns the GRC (IRM) module suite.
  • It has not turned the modules on or set them up.
  • This person starts at zero and takes the platform live.
  • The right hire has led this kind of build before, start to finish.
  1. What Success Looks Like By the close of the engagement, the consultant will have delivered the items below.
  • A live GRC platform in production.
  • Configured Risk Management, Policy and Compliance, and Audit Management modules.
  • A working risk register, control library, and policy repository.
  • Tested workflows, dashboards, and reports.
  • GRC tied into the agency’s current ServiceNow apps.
  • Complete technical and functional documentation.
  • Trained administrators and business users.
  1. Core Responsibilities The consultant owns the work below across each phase. Plan and design
  • Lead the build from planning through production.
  • Gather business and technical needs from agency stakeholders.
  • Turn those needs into a clear solution design.

Configure and build

  • Configure Risk Management, Policy and Compliance, and Audit Management.
  • Configure Vendor Risk Management and Business Continuity Management where the agency needs them.
  • Build workflows, forms, approvals, notifications, dashboards, and reports.
  • Build risk registers, control libraries, compliance frameworks, and policy repositories.
  • Write custom logic with JavaScript, Flow Designer, Business Rules, Script Includes, UI Policies, and In-tegrationHub when the work calls for it.

Integrate

  • Connect GRC to current ServiceNow apps: ITSM, CMDB, Security Operations, and Vulnerability Re-sponse.
  • Connect to third-party tools through REST and SOAP APIs.

Test, deploy, and support

  • Run testing and guide user acceptance testing (UAT).
  • Deploy to production.
  • Support the agency after go-live.

Document and train

  • Write technical and functional documents.
  • Run knowledge transfer sessions.
  • Train administrators and business users.
  • Lead knowledge transfer sessions and effectively train administrators, business users, and support staff to ensure the agency can independently administer and maintain the ServiceNow GRC platform after implementation.

Collaborate

  • Work with business, security, compliance, audit, and infrastructure teams through each phase.

Requirements

  • Bachelor’s degree in computer science, Information Systems, or a related field (or equivalent experi-ence).
  • 7+ years of ServiceNow experience.
  • 3+ years implementing ServiceNow GRC / IRM.
  • A proven ground-up GRC build, start to finish.
  • Hands-on configuration of Risk Management.
  • Hands-on configuration of Policy and Compliance.
  • Hands-on configuration of Audit Management.
  • Strong JavaScript development.
  • Hands-on work with Flow Designer, Business Rules, Script Includes, ACLs, and UI Policies.
  • Integration through REST and SOAP APIs.
  • Strong requirements gathering and documentation.
  • Understanding of Integration Hub, Integration with ITSM, CMDB, Security Operations, and Vulnera-bility Response.
  • Working knowledge of NIST, CIS Controls, ISO 27001, HIPAA, CJIS, PCI-DSS, or SOX.
  • Proven knowledge transfer and training.
  • Strong communication and facilitation skills with ex-perience delivering end-user training, mentoring administrators, and conducting effective knowledge transfer during enterprise platform implementations.
  1. Preferred Qualifications * CIS-RC certification (Certified Implementation Specialist, Risk and Compliance). * CSA certification (Certified System Administrator). * GRC build experience in government or public sector. * Configuration of Vendor Risk Management. * Configuration of Business Continuity Management. * IntegrationHub experience.

About the company

DivIHN, the ‘‘IT Asset Performance Services’’ organization, provides Professional Consulting, Custom Projects, and Professional Resource Augmentation services to clients in the Mid-West and beyond. The strategic characteristics of the organization are Standardization, Specialization, and Collaboration.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · World Congress 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:46 min

Navigating a career in cloud transformation consulting

Piet Van Dongen · LIVE

2:27 min

Establishing a simulated technical environment for the workflow demo

Tobias Dunn-Krahn · LIVE

1:06 min

Developer experience and project variety at scale

Alexandra Petri · World Congress 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all