Principal Engineering Program Manager
Below is a clear, industry‑standard job description you can use for hiring, role clarity, or internal alignment.
Job Title
ServiceNow GRC Business Analyst
Role Summary
The ServiceNow GRC Business Analyst acts as a bridge between business stakeholders, risk/compliance teams, and technical ServiceNow platform teams. The role focuses on gathering requirements, designing GRC solutions, optimizing processes, and ensuring successful implementation and adoption of ServiceNow GRC (IRM) modules.
Key Responsibilities
Business & Requirements Analysis
- Engage with Risk, Compliance, Audit, IT Security, Legal, and Business teams to understand GRC needs
- Conduct requirements gathering workshops, stakeholder interviews, and process walkthroughs
- Translate business requirements into functional specifications, user stories, and acceptance criteria
- Define KPIs, reports, and dashboards aligned to GRC objectives
ServiceNow GRC / IRM Functional Ownership
- Configure and support ServiceNow GRC modules, including:
- Policy and Compliance Management (PCM)
- Risk Management
- Issue Management
- Audit Management
- Vendor Risk Management (VRM)
- Map regulatory requirements (SOX, ISO, SOC, GDPR, HIPAA, etc.) to ServiceNow controls
- Support risk assessments, control testing, and remediation workflows
Process Improvement & Governance
- Analyze existing GRC processes and recommend process improvements and automation
- Ensure alignment with enterprise risk management (ERM) and governance frameworks
- Maintain documentation for processes, controls, workflows, and data models
- Support GRC governance standards and best practices
Collaboration & Delivery
- Work closely with ServiceNow developers and architects to ensure correct solution design
- Participate in UAT planning, execution, and defect resolution
- Support change management, training, and user adoption initiatives
- Provide post‑implementation support and continuous improvement recommendations
Required Skills & Qualifications
Functional & Domain Skills
- Strong understanding of GRC concepts: risk, controls, compliance, audits, and issues
- Hands‑on experience with ServiceNow GRC / IRM modules
- Knowledge of regulatory and compliance frameworks (SOX, ISO 27001, NIST, COBIT, GDPR, etc.)
- Experience in business process mapping and requirements documentation
ServiceNow & Technical Skills
- Experience writing user stories, BRDs, FRDs, and test cases
- Understanding of ServiceNow capabilities: workflows, roles, ACLs, reporting
- Ability to collaborate with developers on configuration (no‑code/low‑code understanding preferred)
- Familiarity with integrations and data imports is a plus
Soft Skills
- Strong stakeholder management and communication skills
- Analytical mindset with attention to detail
- Ability to work in Agile / Scrum environments
- Comfortable working with senior leadership and auditors
Education & Experience
- Bachelor’s degree in Information Systems, Business, Risk Management, or related field
- 5–10+ years experience as a Business Analyst, with 2–4+ years in ServiceNow GRC
- Experience in regulated industries (Banking, Insurance, Healthcare, Manufacturing, IT Services) preferred
Certifications (Preferred)
- ServiceNow Certified Implementation Specialist – GRC / IRM
- ServiceNow Certified System Administrator (CSA)
- CRISC, CISA, CISSP, or similar GRC certifications
- Agile / Scrum certification
Success Metrics
- Successful delivery of GRC implementations and enhancements
- Stakeholder satisfaction and adoption of GRC processes
- Reduction in manual effort through automation
- Improved audit outcomes and risk visibility