ServiceNow GRC / IRM Implementation Consultant
Role purpose
Lead or support the functional implementation of ServiceNow Governance, Risk, and Compliance / Integrated Risk Management capabilities. The role translates approved governance and assurance processes into practical ServiceNow requirements and configurations, supports customer workshops, and helps deliver traceable, testable, and adoption-ready solutions.
Requirements
· Conduct discovery and process workshops with policy, compliance, risk, BCM, internal audit, control-owner, and technology stakeholders.
· Assess current-state processes and define future-state workflows, roles, approvals, notifications, escalations, evidence needs, and reporting requirements.
· Configure or guide configuration of applicable ServiceNow GRC/IRM capabilities in line with approved requirements, platform standards, and agreed scope.
· Define entity, authority document, policy, control, risk, issue, indicator, continuity, audit, finding, remediation, and evidence relationships where applicable.
· Prepare or review functional design documents, user stories, acceptance criteria, configuration workbooks, process flows, and traceability records.
· Support data mapping and migration validation for policies, regulatory content, risks, controls, audits, findings, plans, and related historical records.
· Support integration requirement definition and functional validation while coordinating technical design and development with the responsible integration team.
· Prepare test scenarios; support system integration testing, UAT preparation, defect triage, remediation validation, and business sign-off.
· Develop the end user training material and conduct end user training sessions before or after going live.
· Provide demonstrations, knowledge transfer, administrator guidance, and functional handover documentation.
· Advise stakeholders on practical use of out-of-box GRC/IRM capabilities and identify requests requiring customization, additional licensing, or change control.
· Identify scope gaps, dependencies, risks, assumptions, and change requests early; avoid unsupported commitments or undocumented configuration.
Benefits
Mandatory experience and knowledge
· At least 5 years of relevant GRC, assurance, resilience, or ServiceNow consulting experience, including at least 3 years of hands-on ServiceNow implementation exposure.
· Hands-on practitioner or implementation experience in at least one of the following domains: Compliance Management, Business Continuity Management, or Internal Audit. Experience in more than one is strongly preferred.
· Demonstrated ServiceNow GRC/IRM implementation experience involving at least one relevant product area such as Policy and Compliance, Risk, Audit, or BCM.
· Working knowledge of controls, evidence, issues/findings, remediation, approvals, attestations, assessments, reporting, and audit trails.
· Ability to facilitate business workshops and convert business needs into implementable and testable functional requirements.
· Experience supporting UAT, defect resolution, data validation, and deployment readiness.
· Fluent Arabic language proficiency, spoken and written, is mandatory for this role given direct workshop facilitation with Arabic-speaking policy, compliance, risk, BCM, and audit stakeholders.
Preferred experience
· Experience with enterprise or regulated organizations, especially banking or financial services.
· Exposure to regulatory and control frameworks such as SAMA, ISO 27001, ISO 22301, ISO 31000, COSO, COBIT, NIST, or equivalent.
· Experience with third-party risk, operational resilience, regulatory change, control testing, indicators, or issue management.
· Ability to review ServiceNow configuration and flows and communicate effectively with developers and architects.
Academic and professional certifications
· Required: Relevant bachelor’s degree such as Information Systems, Computer Science, Engineering, Business Administration, Risk Management, Accounting, Finance, or a related discipline.
· Required: ServiceNow Certified System Administrator (CSA).
· Required or to be obtained within the agreed onboarding period: ServiceNow Certified Implementation Specialist – Risk and Compliance (CIS-RC).
· Required: At least one relevant professional certification appropriate to the candidate’s domain depth, such as CISA, CIA, CRISC, CGEIT, ISO 27001 Lead Implementer/Lead Auditor, ISO 22301 Lead Implementer/Lead Auditor, CBCI/CBCP, PMI-RMP, or equivalent.
· Strongly preferred: Postgraduate qualification in risk, audit, compliance, resilience, information systems, or business administration.
Core competencies
GRC process design and analytical thinking
ServiceNow functional configuration
Workshop facilitation and stakeholder management
Requirements traceability and documentation
Quality, testing, and evidence discipline
Scope, dependency, and risk management
.
Skills
As published by workable · 23 questions · 21 written answers
Basics
First name, Last name, Email, Phone, Address, Resume, Cover letter
Short answers (2)
- what is your current salary ?
- what is your expected salary in SAR?
Written answers (21)
- whats your notes period ?
- What is your current location?
- What is your nationality?
- What is your current company and job title?
- How many years of total experience do you have?
- How many years of total experience do you have?
- How many years of hands-on experience do you have with ServiceNow?
- How many years of hands-on experience do you have with ServiceNow GRC / IRM implementations?
- Are you fluent in Arabic (Speaking and Writing)?
- Do you have experience working with Banking or Financial Services organizations? If yes, please mention the projects.
- Are you willing to work onsite in Riyadh, Saudi Arabia?
- What is your notice period?
- How many end-to-end ServiceNow GRC / IRM implementations have you completed? Please mention the modules implemented?
- Which ServiceNow GRC / IRM modules have you worked on? (Policy & Compliance, Risk Management, Audit Management, BCM, Third-Party Risk Management, Regulatory Change Management, etc.)
- Please describe your role and responsibilities in one complete ServiceNow GRC / IRM implementation project.
- Do you hold the ServiceNow Certified System Administrator (CSA) certification? If yes, please specify.
- Do you hold the ServiceNow Certified Implementation Specialist – Risk and Compliance (CIS-RC) certification? If not, are you willing to obtain it during the onboarding period?
- What is your experience in configuring Policies, Controls, Risks, Findings, Evidence, and Remediation workflows within ServiceNow?
- Have you been involved in UAT preparation, defect resolution, and go-live activities? Please explain your responsibilities
- Which regulatory or governance frameworks have you worked with? (SAMA, ISO 27001, ISO 22301, ISO 31000, COBIT, COSO, NIST, etc.)
- Have you worked on ServiceNow GRC / IRM integrations with other systems? If yes, please explain your role in defining or validating the integration requirements.