16 Aug
|
AvanteNow
|
Bengaluru
16 Aug
AvanteNow
Bengaluru
Job Title: ServiceNow GRC / IRM / VR / SIR Architect (On-site)
Experience: 8+ Years
Location: KSA
Work Mode: [Saudi - On-site]
Employment Type: Full-Time
About the Role
We are seeking a highly experienced ServiceNow GRC / IRM / VR / SIR Architect to lead the architecture, design, implementation, and optimization of enterprise-wide Governance, Risk, Compliance, Vulnerability Management, and Security Incident Response solutions on the ServiceNow platform.
The ideal candidate will bring strong expertise across ServiceNow Integrated Risk Management (IRM/GRC), Vendor Risk Management (VRM), Vulnerability Response (VR), and Security Incident Response (SIR) , combined with excellent ServiceNow platform architecture, integration, and stakeholder-management skills.
This role will work closely with Risk, Compliance, Internal Audit, Cybersecurity, Information Security, IT, Procurement, and business leadership to deliver scalable and automated solutions aligned with enterprise and regulatory requirements.
? Key Responsibilities
ServiceNow Architecture
- Lead end-to-end solution and technical architecture for ServiceNow GRC/IRM, VRM, VR, and SIR.
- Define architecture standards, technical roadmap, data models, integration patterns, security, and governance.
- Conduct architecture and requirements workshops with business and technical stakeholders.
- Translate complex business, cybersecurity, risk, compliance, and regulatory requirements into scalable ServiceNow solutions.
- Review existing implementations and recommend optimization, automation, modernization, and standardization opportunities.
- Provide technical leadership to ServiceNow developers, administrators, integration teams, and implementation partners.
GRC / Integrated Risk Management
- Design and implement Risk Management, Policy & Compliance, Audit Management, Regulatory Change, Control Management, Assessments, Issues, and Remediation solutions.
- Design risk frameworks, risk statements, controls, indicators, assessments, attestations, issues,
and remediation processes.
- Develop automated workflows for risk identification, assessment, treatment, monitoring, and reporting.
- Support regulatory and industry frameworks such as SOX, NIST, ISO 27001, PCI DSS, SOC 2, GDPR , and other applicable standards.
- Improve enterprise risk visibility through dashboards, reporting, metrics, and automation.
Vendor / Third-Party Risk Management
- Architect Vendor Risk Management (VRM) and third-party risk solutions.
- Design vendor onboarding, due diligence, inherent risk assessments, questionnaires, control assessments, remediation, and ongoing monitoring.
- Integrate vendor risk processes with procurement, vendor management, cybersecurity, and enterprise risk functions.
Vulnerability Response
- Architect and optimize ServiceNow Vulnerability Response (VR) solutions.
- Design vulnerability ingestion, normalization, prioritization, assignment, remediation, exception, and closure processes.
- Integrate vulnerability management platforms with ServiceNow.
- Develop risk-based vulnerability prioritization using asset criticality, business impact, severity, exploitability, and threat intelligence .
- Integrate Vulnerability Response with CMDB, ITSM, SIR, and Security Operations .
Security Incident Response
- Design and implement ServiceNow Security Incident Response (SIR) solutions.
- Develop security incident workflows covering identification, enrichment, prioritization, investigation, containment, remediation, and closure.
- Integrate ServiceNow with SIEM, SOAR, EDR, threat intelligence, vulnerability management, and other cybersecurity platforms .
- Establish automation and orchestration to improve security incident response and operational efficiency.
? Integration & Technical Skills
- Strong experience with REST/SOAP APIs, IntegrationHub, MID Server, Import Sets, Transform Maps, web services, and scripted integrations .
- Experience integrating ServiceNow with enterprise and security platforms including SIEM, EDR, vulnerability scanners, CMDB, ITSM, IAM, procurement, and GRC systems .
- Strong knowledge of ServiceNow platform capabilities including:
- Flow Designer
- Business Rules
- Script Includes
- Client Scripts
- UI Policies
- ACLs
- Roles & Groups
- Notifications
- Reporting & Dashboards
- Strong JavaScript / ServiceNow scripting skills.
- Understanding of ServiceNow security, performance, upgrades, application lifecycle management, and platform governance.
? Required Experience
- 8+ years of overall ServiceNow experience with significant architecture experience.
- 5+ years of experience in ServiceNow GRC/IRM and/or SecOps .
- Strong hands-on experience with IRM/GRC, VRM, Vulnerability Response, and Security Incident Response .
- Proven experience leading complex, enterprise-scale ServiceNow implementations.
- Solid understanding of enterprise risk, compliance, audit, cybersecurity, vulnerability management, and security incident processes .
- Experience working with global stakeholders and distributed delivery teams.
- Excellent communication, presentation, problem-solving, and stakeholder-management skills.
? Preferred Certifications
- ServiceNow Certified System Administrator ( CSA )
- ServiceNow Certified Application Developer ( CAD )
- ServiceNow IRM/GRC Implementation Specialist
- ServiceNow Security Operations / Vulnerability Response certifications
- ServiceNow Certified Technical Architect (CTA) – highly desirable
- CISA, CISM, CISSP, CRISC or equivalent cybersecurity/risk certification – preferred
📌 ServiceNow GRC / IRM / VR / SIR Architect (On-site) (Bengaluru)
🏢 AvanteNow
📍 Bengaluru