DescriptionOVERVIEWiTech AG is seeking an IRM Practice Lead - ServiceNow Architect (Integrated Risk Management) to lead the solution architecture for a federal customer's cyber risk and Continuous Authorization and Monitoring (CAM) program. This is a senior, architect-level role responsible for owning the end-to-end IRM solution design on the ServiceNow platform and the integration architecture that connects it across multiple ServiceNow products - IRM/CAM, Policy and Compliance Management, Risk Management, Flow Designer and Workflow Studio, IntegrationHub, Service Portal/UI Builder, Virtual Agent, and AI/Now Assist.
The ideal candidate is a true ServiceNow architect who has implemented IRM end-to-end, from control library and authorization boundary design through SSP management, POA&M and issue remediation, control testing, risk registers, dashboards, and data migration, and can direct developers to deliver it. They bring proven experience architecting cross-product ServiceNow solutions and enterprise integrations in FISMA/FedRAMP-governed environments. This role owns the IRM Technical Solutions, defines integration and security patterns, and collaborates with the iTech Solution SMEs, customers, and iTech Certified Master Architects.
ROLES AND RESPONSIBILITIES- Own the end-to-end solution architecture for the ServiceNow IRM/CAM solution, including solution design, data model, control hierarchy, and the phased roadmap across modules
- Architect and lead the implementation of ServiceNow IRM capabilities across the solution, including:
- Continuous Authorization and Monitoring (CAM)
- System Security Plans (SSPs) and Authorization Boundaries
- Control Testing, Assessment, and Continuous Monitoring
- Issue, Deficiency, and POA&M Management
- Cyber Risk Register and Risk Assessments
- Common and Inherited Controls
- Policy and Compliance Management (authority documents, policies, and control attestations)
- Audit Management and auditor evidence workflows
- Third-Party / Vendor Risk Management
- Business Continuity Management and contingency planning (CP control family)
- Dashboards, Reporting, and Stakeholder Visibility
- Author and maintain the Technical Solution - architecture diagrams, data model, control hierarchy, integration patterns, and security model - and drive architecture decisions and approvals each sprint
- Configure IRM Continuous Authorization and Monitoring (CAM) for SSPs, POA&Ms, control testing, risk assessments, and control inheritance
- Build automated issue and deficiency workflows, including assignment, notifications, tracking, review, and approval
- Configure collaborative workflows to replace email-based processes across multiple security and technical teams
- Design support for multiple authorization boundaries and SSPs, including GSS, ICS, and subsystem relationships
- Configure common controls and inherited controls so control relationships cascade appropriately across parent systems and subsystems
- Implement a cyber risk register and the workflows for creating, reviewing, and approving risk assessments
- Build configurable dashboards and reports for issues, remediation status, SSP and control status, risks, and approvals that end users can adjust without recoding
- Configure the annual SSP update and approval process, including auditor review and sign-off requirements
- Ensure the control library supports the required NIST control and enhancement granularity - potentially down to examples such as AC-2(1)(b) - and design a documented workaround if native depth is insufficient
- Plan and execute the IRM data migration effort, including:
- Migration of approximately 10-14 SSPs, using OSCAL where feasible
- An alternate JSON/import-map transformation approach where OSCAL is not viable
- A practical manual, system-by-system configuration fallback if automation is not possible
- Validation of migrated control, POA&M, and boundary data against source systems
- Define and govern the integration architecture between ServiceNow IRM and external systems, including authoritative control and compliance data sources, customer SSO, ITSM/ticketing, and enterprise reporting or data warehouse platforms
- Identify how digital approvals and signatures will be handled on the current platform, including an interim workflow if native signature capability is unavailable
- Establish development standards and hands-on build the most complex components - custom applications, workflows, business rules, UI policies, integrations, and Flow Designer automations
- Partner with iTech AG Master Architects and the Solution SME on cross-product architecture and technical governance
- Serve as a contributing member of the iTech AG ServiceNow Center of Excellence (CoE), sharing reusable patterns, standards, and lessons learned across programs
- Act as the organization-wide leader for the IRM product area - advising other programs and pursuits, informing the IRM capability roadmap, and supporting proposal and solutioning efforts beyond this project
- Lead the approximately four-week discovery with security stakeholders to validate processes, data sources, control hierarchy, and migration assumptions
- Participate in Agile ceremonies including sprint planning, backlog refinement, demos, and retrospectives, and contribute to Technical Solution Document (TSD) updates each sprint
- Lead code and design reviews, mentor developers, and enforce platform best practices and technical governance
- Support platform upgrades, patching, and performance optimization activities, and resolve IRM defects, workflow issues, and production support requests
- Ensure configurations and customizations align with federal security, compliance (e.g., NIST 800-53, FISMA, FedRAMP), accessibility, and data governance requirements
- Contribute to technical documentation, knowledge transfer, operational readiness, and end-user adoption efforts
- Other duties as assigned
MINIMUM QUALIFICATIONS- 5+ years of hands-on ServiceNow experience, including 3+ years in a technical lead role
- 3+ years leading ServiceNow Integrated Risk Management (IRM) implementations end-to-end
- Deep architecture and hands-on experience across:
- Continuous Authorization and Monitoring (CAM) and SSP management
- Control libraries, control testing, and continuous control monitoring
- Issue, deficiency, and POA&M remediation workflows
- Cyber risk register and risk assessment workflows
- Dashboards, reporting, and stakeholder self-service
- Working knowledge of NIST 800-53 control families and enhancements, FISMA, and the authorization boundary / ATO lifecycle
- Experience designing integration architecture using IntegrationHub and REST/SOAP APIs, and leading GRC/IRM data migration
- Strong experience defining ServiceNow data models, security models, and overall platform architecture
- Proficiency with ServiceNow scripting including JavaScript, Glide APIs, Script Includes, and Flow Designer
- Experience working in Agile delivery environments (ServiceNow Now Create methodology a plus)
- Strong analytical, troubleshooting, and problem-solving skills, and experience leading, mentoring, and setting technical direction for developers
EDUCATION AND CERTIFICATIONS- Bachelor's degree or equivalent years experience
- ServiceNow Certified System Administrator (CSA) or equivalent years experience
- ServiceNow Certified Application Developer (CAD) or equivalent years experience
- ServiceNow Certified Implementation Specialist (CIS) - Risk and Compliance (IRM), with additional CIS certifications across products (e.g., Data Foundations (CMDB/CSDM), ITSM, CSM, Discovery) a plus
PREFERRED QUALIFICATIONS- Experience supporting federal government programs subject to FISMA and/or FedRAMP authorization
- Experience with OSCAL-based SSP export/import and control data transformation
- Experience migrating from eMASS, Xacta, CSAM, or comparable GRC/ATO platforms into ServiceNow
- Familiarity with continuous control monitoring, automated evidence collection, and control test automation
- Experience implementing ServiceNow Policy and Compliance Management, Risk Management, Audit Management, or Vendor Risk Management
- Experience implementing ServiceNow Business Continuity Management, Privacy Management, or Operational Resilience Management
- Experience linking ServiceNow Security Operations (Vulnerability Response, Configuration Compliance) findings to IRM issues and POA&Ms
- Familiarity with Now Assist for IRM, including AI-assisted control mapping and evidence summarization
- Strong experience with Service Portal, UI Builder, and dashboard and reporting design for executive and auditor audiences
- Familiarity with ServiceNow data model, CMDB relationships, and platform performance optimization
- Experience with ServiceNow Now Create methodology and IntegrationHub-based integrations
- Familiarity with ServiceNow Virtual Agent and AI / Now Assist capabilities
- Strong communication, stakeholder engagement, and collaboration skills
SECURITY CLEARANCE- Ability to obtain and maintain a Public Trust
- Pursuant to government contracts, US Citizenship is required