ServiceNow Integrated Risk Management (IRM) Specialist

Saltech Systems
  • Ames, IA
    3 days ago

    Job Description

    Role Summary

    Implement and enhance ServiceNow IRM capabilities for enterprise risk, compliance, controls, policy, audit, third-party risk, and regulatory management.

    Key Responsibilities

    • Configure Policy and Compliance, Risk Management, Audit Management, and, where in scope, Third-Party (Vendor) Risk, Business Continuity, and Privacy Management.
    • Set up entity types, entity scoping, authority documents, citations, control objectives, and controls (including UCF content where licensed).
    • Configure risk frameworks, Advanced Risk Assessments, scoring, indicators (manual, Performance Analytics, scripted), attestations, and continuous monitoring.
    • Build issue and remediation workflows, exceptions, and GRC workspaces.
    • Translate governance, risk, and compliance requirements into ServiceNow solutions.
    • Build dashboards and reporting for risk, compliance, and audit stakeholders.
    • Integrate IRM with CMDB, ITSM, SecOps, and external GRC/data sources.
    • Work with security, audit, legal, and risk teams to improve governance processes; support testing, documentation, upgrades, and production operations.

    Required Qualifications & Skills

    • 4+ years of ServiceNow experience, including 2+ years of hands-on IRM/GRC implementation.
    • Understanding of enterprise risk, controls, compliance, and audit concepts.
    • Experience configuring entity scoping, indicators, assessments, and IRM workflows.
    • ServiceNow configuration, Flow Designer, scripting, and integration experience.
    • Strong analytical and stakeholder-management skills.

    Preferred Qualifications

    • CSA and CIS-Risk and Compliance; CIS-Vendor Risk Management a plus.
    • Knowledge of frameworks such as ISO 27001, NIST CSF/800-53, SOC 2, SOX, PCI DSS, or similar.
    • CISA, CRISC, or similar risk/audit credentials.

    Level & Experience
    We are hiring at multiple levels; final level/salary is based on interview performance.

    • L2 (3-5 yrs): Independently configures policy, compliance, risk, controls, assessments and issue workflows.
    • L3 (5-8 yrs): Leads IRM workstreams, designs entity scoping, framework mapping (NIST, ISO 27001, SOX) and continuous monitoring.
    • L4 (8+ yrs): Defines GRC architecture and roadmap across risk, audit, vendor risk and BCM, and advises risk, audit and client leadership.

    General Expectations

    • Work effectively in Agile/Scrum or hybrid delivery environments and collaborate with distributed, multi-time-zone teams.
    • Produce clear technical/functional documentation and follow established development, security, change, and release standards.
    • Communicate effectively with technical teams, business stakeholders, and client leadership.
    • Support production issues, releases, or scheduled activities outside standard business hours when required by the engagement.

    Numbers & Facts

    LocationAmes, IA

    Skills

    • ADO.NET Entity Frameworkunmatched
    • Agile Programming Methodologiesunmatched
    • Analysis Skillsunmatched
    • Auditingunmatched
    • Business Continuity Planning (BCP)unmatched
    • CISA - Certified Information Systems Auditorunmatched
    • Communication Skillsunmatched
    • ISO (International Organization for Standardization)unmatched
    • IT Service Management (ITSM)unmatched
    • Leadershipunmatched
    • Legalunmatched
    • PCI-DSSunmatched
    • Performance Analysisunmatched
    • Process Improvementunmatched
    • Production Supportunmatched
    • Regulationsunmatched
    • Regulatory Complianceunmatched
    • Reporting Dashboardsunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Sarbanes-Oxley Act (SOX)unmatched
    • Scripting (Scripting Languages)unmatched
    • Scrum Project Management and Software Developmentunmatched
    • Security Auditingunmatched
    • ServiceNowunmatched
    • Support Documentationunmatched
    • Team Playerunmatched
    • Technical Writingunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Vendor/Supplier Evaluationunmatched
    • Workflow Analysisunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder