10 Oct
|
NewVison
|
India
ServiceNow Developer - GRC/IRM
Experience: 4-6 Years
Position
ServiceNow Developer - GRC/IRM
Experience
4-6 Years
Locations
Pune
Work Model
Hybrid / As per business requirements
Position Summary
We are seeking a ServiceNow Developer specializing in Governance, Risk and Compliance (GRC) and Integrated Risk Management (IRM) to design, configure, develop, and support scalable risk and compliance solutions on the ServiceNow platform. The role combines hands-on platform development with practical knowledge of risk, controls, compliance, audit, and issue remediation processes. The successful candidate will translate business requirements into maintainable workflows, assessments, dashboards, integrations, and technical components that improve enterprise risk visibility and compliance execution.
Work You'll Do
Design, configure, develop, test, and support ServiceNow GRC/IRM solutions across the project lifecycle.
Work with business, risk, compliance, audit, security, and technology stakeholders to convert functional requirements into technical designs and working solutions.
Build reusable, secure, and upgrade-aware platform components in line with ServiceNow development standards.
Participate in estimation, sprint planning, demonstrations, testing, release activities, defect resolution, documentation, and production support.
Contribute to continuous improvement through workflow automation, continuous monitoring, automated evidence collection, and responsible use of Artificial Intelligence (AI)-enabled capabilities.
Configure, extend, or support ServiceNow Otto for Integrated Risk Management (IRM), formerly Now Assist for IRM, including Generative Artificial Intelligence (GenAI) skills and agentic workflows, where available in the deployed release and licensed environment.
Key Responsibilities
Design, configure, and maintain ServiceNow GRC/IRM capabilities, including Risk Management, Policy and Compliance Management, Audit Management, Issue Management, Vendor Risk Management (VRM) or Third-Party Risk Management (TPRM), and Business Continuity Management (BCM), based on project scope.
Configure risk statements, risk assessments, scoring methodologies, control objectives, controls, indicators, attestations, authority documents, policies, issues, findings, and remediation workflows.
Develop ServiceNow components using JavaScript, Glide Application Programming Interfaces (APIs), Business Rules, Client Scripts, Script Includes, User Interface (UI) Policies, UI Actions, Flow Designer, Studio, and scoped applications.
Configure roles, groups, and Access Control Lists (ACLs) to support secure and appropriate access to risk and compliance information.
Create reports, dashboards, and Key Performance Indicators (KPIs) for risk posture, compliance status, control effectiveness, audit findings, open issues, overdue remediation, and third-party risk.
Integrate ServiceNow with enterprise platforms using Representational State Transfer (REST), Simple Object Access Protocol (SOAP), Integration Hub, MID Server, import sets, transform maps, and scripted interfaces where required.
Support automated evidence collection and data exchange with security, identity, vulnerability, asset, document, and enterprise systems.
Implement or support AI-assisted IRM use cases such as issue and risk-assessment summarization, control-objective rationalization and deduplication,
control recommendations, assessment-response assistance, and guided issue remediation, with appropriate human review and governance.
Perform unit testing, system integration testing, defect analysis, technical troubleshooting, code review, and release validation.
Create and maintain technical designs, configuration workbooks, test evidence, implementation plans, deployment instructions, and operational documentation.
Provide technical guidance to team members and communicate design decisions, dependencies, risks, and delivery status to relevant stakeholders.
Required Qualifications
4-6 years of overall ServiceNow platform experience, with substantial hands-on experience implementing or supporting GRC/IRM solutions.
Implementation experience in at least two core GRC/IRM areas, such as Risk Management, Policy and Compliance Management, Audit Management, Issue Management, or Vendor/Third-Party Risk Management.
Solid ServiceNow development capability using JavaScript, Glide APIs, Business Rules, Script Includes, Client Scripts, UI Policies, UI Actions, Flow Designer, and scoped application development.
Familiarity with ServiceNow Artificial Intelligence (AI) capabilities relevant to IRM, including ServiceNow Otto for IRM / Now Assist for IRM, Generative AI, AI agents, agentic workflows, Predictive Intelligence, AI Search, and responsible AI implementation principles.
Working knowledge of the GRC/IRM data model and relationships among entities, risks, controls, control objectives, policies, authority documents, indicators, issues, findings, and remediation tasks.
Experience developing integrations using REST, SOAP, Integration Hub, MID Server, import sets, transform maps, JavaScript Object Notation (JSON), and Extensible Markup Language (XML).
Experience with reporting, dashboards, data imports, update sets or application repository-based deployments, and ServiceNow release practices.
Understanding of Software Development Life Cycle (SDLC), Agile delivery, User Acceptance Testing (UAT), release management, and post-production support.
Strong analytical, troubleshooting, communication, documentation, and stakeholder collaboration skills.
Bachelor's degree in Computer Science, Information Technology, Engineering, or a related discipline, or equivalent practical experience.
Functional Knowledge
Governance, Risk and Compliance (GRC) and Integrated Risk Management (IRM) concepts, including risk identification, assessment, treatment, monitoring, and reporting.
Policy lifecycle, control mapping, control testing, attestations, compliance monitoring, audit lifecycle, findings, exceptions, issues, and remediation.
Familiarity with one or more relevant frameworks or regulations, such as International Organization for Standardization (ISO) 27001, National Institute of Standards and Technology (NIST), Sarbanes-Oxley Act (SOX), Payment Card Industry Data Security Standard (PCI DSS), General Data Protection Regulation (GDPR),
Health Insurance Portability and Accountability Act (HIPAA), or Federal Risk and Authorization Management Program (FedRAMP).
Preferred Qualifications
ServiceNow Certified System Administrator (CSA).
ServiceNow Certified Implementation Specialist - Risk and Compliance (CIS-RC) or the current equivalent ServiceNow certification applicable to the deployed product release.
ServiceNow Certified Application Developer (CAD).
Exposure to implementing or supporting ServiceNow Otto for IRM / Now Assist for IRM, AI agents, Generative AI skills, intelligent summarization, recommendations, or AI-enabled risk and compliance workflows is preferred.
Experience with Third-Party Risk Management, Business Continuity Management, continuous monitoring, indicator management, or automated evidence collection.
Experience with UI Builder, configurable workspaces, Automated Test Framework (ATF), Performance Analytics, or ServiceNow platform upgrades.
Exposure to Configuration Management Database (CMDB), Common Service Data Model (CSDM), Security Operations (SecOps), Vulnerability Response, or related enterprise integrations is advantageous but not mandatory.
Key Technical Skills, Experience and Knowledge
Capability Area
Expected Proficiency
ServiceNow GRC/IRM
Risk, Policy and Compliance, Audit, Issues, Vendor/Third-Party Risk, Business Continuity
Platform Development
JavaScript, Glide APIs, Business Rules, Script Includes, Client Scripts, UI Policies, UI Actions, Flow Designer, Studio
Security and Data
ACLs, roles, groups, scoped applications, data imports, transform maps, data quality
Integrations
REST, SOAP, Integration Hub, MID Server, JSON, XML, scripted interfaces
Reporting
Reports, dashboards, KPIs, Performance Analytics exposure
Delivery
Agile, SDLC, estimation, testing, UAT, release management, defect resolution, documentation
ServiceNow AI Capabilities
ServiceNow Otto for IRM / Now Assist for IRM, Generative AI, AI agents, agentic workflows, Predictive Intelligence, AI Search, intelligent summarization and recommendations, with human oversight
Essential Competencies
Hands-on, quality-focused developer with sound technical judgment and attention to maintainability.
Ability to work independently while collaborating effectively with functional consultants, architects, testers, administrators, and business stakeholders.
Clear written and verbal communication, including the ability to explain technical matters to non-technical audiences.
Structured problem solving, ownership of assigned deliverables, and proactive risk and dependency management.
Commitment to secure development, peer review, documentation, knowledge sharing, and continuous learning.
Role Logistics
Location: Pune
Work Model: Hybrid or as defined by business requirements
Shift Timings: As per project and business requirements. Any rotational or night-shift expectation should be explicitly communicated during the hiring process.
Candidate Screening Guidance
Candidates should demonstrate depth rather than only broad module exposure. During screening, validate at least one end-to-end GRC/IRM implementation, the candidate's individual development contribution, understanding of the IRM data model, scripting proficiency, integration ownership, and ability to explain a risk-to-remediation workflow using a real project example.
📌 ServiceNow Developer - GRC/IRM (India)
🏢 NewVison
📍 India