ServiceNow IRM Practice Lead

iTech AG

$125K — $150K *
Technical Services
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of hands-on ServiceNow experience, including 3+ years in a technical lead role.
  • 3+ years leading ServiceNow Integrated Risk Management (IRM) implementations end-to-end.
  • Deep experience in Continuous Authorization and Monitoring (CAM) and SSP management.
  • Experience designing integration architecture using IntegrationHub and REST/SOAP APIs.
  • Strong analytical and troubleshooting skills, with a background in mentoring developers.

Responsibilities

  • Own end-to-end solution architecture for ServiceNow IRM/CAM, including data model and control hierarchy.
  • Lead implementation of critical IRM capabilities like control testing, risk assessments, and policy management.
  • Author and maintain architecture diagrams and integration patterns, driving decisions each sprint.
  • Plan and execute data migration efforts, validating migrated data against source systems.
  • Define integration architecture across ServiceNow IRM and external systems, managing data flows effectively.

Benefits

  • Flexible work environment allowing for remote collaboration.
  • Opportunity to lead and architect major federal cyber risk initiatives.
  • Access to ongoing professional development and certification opportunities.
  • Engagement with a team of seasoned ServiceNow experts and certified Master Architects.
Full Job Description
Description

OVERVIEW

iTech AG is seeking an IRM Practice Lead - ServiceNow Architect (Integrated Risk Management) to lead the solution architecture for a federal customer's cyber risk and Continuous Authorization and Monitoring (CAM) program. This is a senior, architect-level role responsible for owning the end-to-end IRM solution design on the ServiceNow platform and the integration architecture that connects it across multiple ServiceNow products - IRM/CAM, Policy and Compliance Management, Risk Management, Flow Designer and Workflow Studio, IntegrationHub, Service Portal/UI Builder, Virtual Agent, and AI/Now Assist.

The ideal candidate is a true ServiceNow architect who has implemented IRM end-to-end, from control library and authorization boundary design through SSP management, POA&M and issue remediation, control testing, risk registers, dashboards, and data migration, and can direct developers to deliver it. They bring proven experience architecting cross-product ServiceNow solutions and enterprise integrations in FISMA/FedRAMP-governed environments. This role owns the IRM Technical Solutions, defines integration and security patterns, and collaborates with the iTech Solution SMEs, customers, and iTech Certified Master Architects.

ROLES AND RESPONSIBILITIES
  • Own the end-to-end solution architecture for the ServiceNow IRM/CAM solution, including solution design, data model, control hierarchy, and the phased roadmap across modules
  • Architect and lead the implementation of ServiceNow IRM capabilities across the solution, including:
    • Continuous Authorization and Monitoring (CAM)
    • System Security Plans (SSPs) and Authorization Boundaries
    • Control Testing, Assessment, and Continuous Monitoring
    • Issue, Deficiency, and POA&M Management
    • Cyber Risk Register and Risk Assessments
    • Common and Inherited Controls
    • Policy and Compliance Management (authority documents, policies, and control attestations)
    • Audit Management and auditor evidence workflows
    • Third-Party / Vendor Risk Management
    • Business Continuity Management and contingency planning (CP control family)
    • Dashboards, Reporting, and Stakeholder Visibility
  • Author and maintain the Technical Solution - architecture diagrams, data model, control hierarchy, integration patterns, and security model - and drive architecture decisions and approvals each sprint
  • Configure IRM Continuous Authorization and Monitoring (CAM) for SSPs, POA&Ms, control testing, risk assessments, and control inheritance
  • Build automated issue and deficiency workflows, including assignment, notifications, tracking, review, and approval
  • Configure collaborative workflows to replace email-based processes across multiple security and technical teams
  • Design support for multiple authorization boundaries and SSPs, including GSS, ICS, and subsystem relationships
  • Configure common controls and inherited controls so control relationships cascade appropriately across parent systems and subsystems
  • Implement a cyber risk register and the workflows for creating, reviewing, and approving risk assessments
  • Build configurable dashboards and reports for issues, remediation status, SSP and control status, risks, and approvals that end users can adjust without recoding
  • Configure the annual SSP update and approval process, including auditor review and sign-off requirements
  • Ensure the control library supports the required NIST control and enhancement granularity - potentially down to examples such as AC-2(1)(b) - and design a documented workaround if native depth is insufficient
  • Plan and execute the IRM data migration effort, including:
    • Migration of approximately 10-14 SSPs, using OSCAL where feasible
    • An alternate JSON/import-map transformation approach where OSCAL is not viable
    • A practical manual, system-by-system configuration fallback if automation is not possible
    • Validation of migrated control, POA&M, and boundary data against source systems
  • Define and govern the integration architecture between ServiceNow IRM and external systems, including authoritative control and compliance data sources, customer SSO, ITSM/ticketing, and enterprise reporting or data warehouse platforms
  • Identify how digital approvals and signatures will be handled on the current platform, including an interim workflow if native signature capability is unavailable
  • Establish development standards and hands-on build the most complex components - custom applications, workflows, business rules, UI policies, integrations, and Flow Designer automations
  • Partner with iTech AG Master Architects and the Solution SME on cross-product architecture and technical governance
  • Serve as a contributing member of the iTech AG ServiceNow Center of Excellence (CoE), sharing reusable patterns, standards, and lessons learned across programs
  • Act as the organization-wide leader for the IRM product area - advising other programs and pursuits, informing the IRM capability roadmap, and supporting proposal and solutioning efforts beyond this project
  • Lead the approximately four-week discovery with security stakeholders to validate processes, data sources, control hierarchy, and migration assumptions
  • Participate in Agile ceremonies including sprint planning, backlog refinement, demos, and retrospectives, and contribute to Technical Solution Document (TSD) updates each sprint
  • Lead code and design reviews, mentor developers, and enforce platform best practices and technical governance
  • Support platform upgrades, patching, and performance optimization activities, and resolve IRM defects, workflow issues, and production support requests
  • Ensure configurations and customizations align with federal security, compliance (e.g., NIST 800-53, FISMA, FedRAMP), accessibility, and data governance requirements
  • Contribute to technical documentation, knowledge transfer, operational readiness, and end-user adoption efforts
  • Other duties as assigned


MINIMUM QUALIFICATIONS
  • 5+ years of hands-on ServiceNow experience, including 3+ years in a technical lead role
  • 3+ years leading ServiceNow Integrated Risk Management (IRM) implementations end-to-end
  • Deep architecture and hands-on experience across:
    • Continuous Authorization and Monitoring (CAM) and SSP management
    • Control libraries, control testing, and continuous control monitoring
    • Issue, deficiency, and POA&M remediation workflows
    • Cyber risk register and risk assessment workflows
    • Dashboards, reporting, and stakeholder self-service
  • Working knowledge of NIST 800-53 control families and enhancements, FISMA, and the authorization boundary / ATO lifecycle
  • Experience designing integration architecture using IntegrationHub and REST/SOAP APIs, and leading GRC/IRM data migration
  • Strong experience defining ServiceNow data models, security models, and overall platform architecture
  • Proficiency with ServiceNow scripting including JavaScript, Glide APIs, Script Includes, and Flow Designer
  • Experience working in Agile delivery environments (ServiceNow Now Create methodology a plus)
  • Strong analytical, troubleshooting, and problem-solving skills, and experience leading, mentoring, and setting technical direction for developers

EDUCATION AND CERTIFICATIONS
  • Bachelor's degree or equivalent years experience
  • ServiceNow Certified System Administrator (CSA) or equivalent years experience
  • ServiceNow Certified Application Developer (CAD) or equivalent years experience
  • ServiceNow Certified Implementation Specialist (CIS) - Risk and Compliance (IRM), with additional CIS certifications across products (e.g., Data Foundations (CMDB/CSDM), ITSM, CSM, Discovery) a plus

PREFERRED QUALIFICATIONS
  • Experience supporting federal government programs subject to FISMA and/or FedRAMP authorization
  • Experience with OSCAL-based SSP export/import and control data transformation
  • Experience migrating from eMASS, Xacta, CSAM, or comparable GRC/ATO platforms into ServiceNow
  • Familiarity with continuous control monitoring, automated evidence collection, and control test automation
  • Experience implementing ServiceNow Policy and Compliance Management, Risk Management, Audit Management, or Vendor Risk Management
  • Experience implementing ServiceNow Business Continuity Management, Privacy Management, or Operational Resilience Management
  • Experience linking ServiceNow Security Operations (Vulnerability Response, Configuration Compliance) findings to IRM issues and POA&Ms
  • Familiarity with Now Assist for IRM, including AI-assisted control mapping and evidence summarization
  • Strong experience with Service Portal, UI Builder, and dashboard and reporting design for executive and auditor audiences
  • Familiarity with ServiceNow data model, CMDB relationships, and platform performance optimization
  • Experience with ServiceNow Now Create methodology and IntegrationHub-based integrations
  • Familiarity with ServiceNow Virtual Agent and AI / Now Assist capabilities
  • Strong communication, stakeholder engagement, and collaboration skills

SECURITY CLEARANCE
  • Ability to obtain and maintain a Public Trust
  • Pursuant to government contracts, US Citizenship is required

Similar Jobs

More Jobs at iTech AG

More Technical Services Jobs

Find similar ServiceNow IRM Practice Lead jobs: