ServiceNow GRC / IRM Implementation Consultant

TAWANTECH

Riyadh

On-site

SAR 320,000 - 520,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

TAWANTECH in Riyadh is seeking an experienced ServiceNow GRC/IRM consultant to lead or support implementations, translating governance processes into practical configurations and ensuring traceable, testable solutions.

The role requires at least 5 years in GRC or ServiceNow consulting, hands-on experience in policy/risk/audit domains, and fluent Arabic language skills for workshops.

Qualifications

  • Minimum 5 years in GRC, assurance, or ServiceNow consulting with at least 3 years hands-on implementation.
  • Hands-on in Compliance Management, BCM, or Internal Audit; multiple domains are preferred.
  • Proven ServiceNow GRC/IRM implementation experience in policy, risk, audit, or BCM.
  • Fluent Arabic language skills, written and spoken, are mandatory for workshops.

Responsibilities

  • Lead or support the functional implementation of ServiceNow GRC/IRM capabilities.
  • Conduct discovery workshops with policy, compliance, risk, BCM, internal audit, and technology stakeholders.
  • Define future-state workflows, approvals, and reporting needs.
  • Configure ServiceNow GRC/IRM capabilities per approved requirements and standards.
  • Prepare functional design docs, user stories, and traceability records.
  • Support data mapping, migration validation, and UAT readiness.
  • Provide demonstrations, training, and knowledge transfer to end users.

Skills

GRC process design
ServiceNow configuration
Workshop facilitation
Stakeholder management
Requirements tracing
Testing & acceptance

Education

Bachelor’s degree in Information Systems / CS / Engineering / Business Administration / Risk Management / Accounting / Finance

Tools

ServiceNow

Job description

Role purpose

Lead or support the functional implementation of ServiceNow Governance, Risk, and Compliance / Integrated Risk Management capabilities. The role translates approved governance and assurance processes into practical ServiceNow requirements and configurations, supports customer workshops, and helps deliver traceable, testable, and adoption-ready solutions.

  • Conduct discovery and process workshops with policy, compliance, risk, BCM, internal audit, control-owner, and technology stakeholders.
  • Assess current-state processes and define future-state workflows, roles, approvals, notifications, escalations, evidence needs, and reporting requirements.
  • Configure or guide configuration of applicable ServiceNow GRC/IRM capabilities in line with approved requirements, platform standards, and agreed scope.
  • Define entity, authority document, policy, control, risk, issue, indicator, continuity, audit, finding, remediation, and evidence relationships where applicable.
  • Prepare or review functional design documents, user stories, acceptance criteria, configuration workbooks, process flows, and traceability records.
  • Support data mapping and migration validation for policies, regulatory content, risks, controls, audits, findings, plans, and related historical records.
  • Support integration requirement definition and functional validation while coordinating technical design and development with the responsible integration team.
  • Prepare test scenarios; support system integration testing, UAT preparation, defect triage, remediation validation, and business sign-off.
  • Develop the end user training material and conduct end user training sessions before or after going live.
  • Provide demonstrations, knowledge transfer, administrator guidance, and functional handover documentation.
  • Advise stakeholders on practical use of out-of-box GRC/IRM capabilities and identify requests requiring customization, additional licensing, or change control.
  • Identify scope gaps, dependencies, risks, assumptions, and change requests early; avoid unsupported commitments or undocumented configuration.
Mandatory experience and knowledge
  • At least 5 years of relevant GRC, assurance, resilience, or ServiceNow consulting experience, including at least 3 years of hands-on ServiceNow implementation exposure.
  • Hands-on practitioner or implementation experience in at least one of the following domains: Compliance Management, Business Continuity Management, or Internal Audit. Experience in more than one is strongly preferred.
  • Demonstrated ServiceNow GRC/IRM implementation experience involving at least one relevant product area such as Policy and Compliance, Risk, Audit, or BCM.
  • Working knowledge of controls, evidence, issues/findings, remediation, approvals, attestations, assessments, reporting, and audit trails.
  • Ability to facilitate business workshops and convert business needs into implementable and testable functional requirements.
  • Experience supporting UAT, defect resolution, data validation, and deployment readiness.
  • Fluent Arabic language proficiency, spoken and written, is mandatory for this role given direct workshop facilitation with Arabic-speaking policy, compliance, risk, BCM, and audit stakeholders.
Preferred experience
  • Experience with enterprise or regulated organizations, especially banking or financial services.
  • Exposure to regulatory and control frameworks such as SAMA, ISO 27001, ISO 22301, ISO 31000, COSO, COBIT, NIST, or equivalent.
  • Experience with third-party risk, operational resilience, regulatory change, control testing, indicators, or issue management.
  • Ability to review ServiceNow configuration and flows and communicate effectively with developers and architects.
Academic and professional certifications
  • Required: Relevant bachelor’s degree such as Information Systems, Computer Science, Engineering, Business Administration, Risk Management, Accounting, Finance, or a related discipline.
  • Required: ServiceNow Certified System Administrator (CSA).
  • Required or to be obtained within the agreed onboarding period: ServiceNow Certified Implementation Specialist - Risk and Compliance (CIS-RC).
  • Required: At least one relevant professional certification appropriate to the candidate’s domain depth, such as CISA, CIA, CRISC, CGEIT, ISO 27001 Lead Implementer/Lead Auditor, ISO 22301 Lead Implementer/Lead Auditor, CBCI/CBCP, PMI-RMP, or equivalent.
  • Strongly preferred: Postgraduate qualification in risk, audit, compliance, resilience, information systems, or business administration.
Core competencies
  • GRC process design and analytical thinking
  • ServiceNow functional configuration
  • Workshop facilitation and stakeholder management
  • Requirements traceability and documentation
  • Quality, testing, and evidence discipline
  • Scope, dependency, and risk management

.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Business Analyst - ServiceNow GRC & SPM
Business Analyst - ServiceNow GRC & SPM

TAWANTECH • Riyadh

On-site
SAR 250,000 - 420,000
Business & Data Analyst - ServiceNow GRC & SPM
Business & Data Analyst - ServiceNow GRC & SPM

TAWANTECH • Riyadh

On-site
SAR 180,000 - 280,000
Business & Data Analyst - ServiceNow GRC & SPM
Business & Data Analyst - ServiceNow GRC & SPM

TAWANTECH • Saudi Arabia

On-site
SAR 180,000 - 240,000
ServiceNow SPM Implementation Consultant
ServiceNow SPM Implementation Consultant

TAWANTECH • Riyadh

On-site
SAR 180,000 - 300,000
GRC Consultant
GRC Consultant

Catalyic Security • Saudi Arabia

On-site
SAR 50,000 - 75,000
GRC Specialist
GRC Specialist

Managed.sa • Jeddah

On-site
SAR 70,000 - 100,000
GRC Manager
GRC Manager

MINDFREE Consulting | Insurance Talent Hub • Riyadh

On-site
GRC Specialist (KSA National)
GRC Specialist (KSA National)

Specialized Technical Services – STS • Riyadh

On-site
SAR 100,000 - 150,000
Digital Enablement GRC Specialist
Digital Enablement GRC Specialist

cyberani solutions • Riyadh

On-site
SAR 180,000 - 300,000
GRC Consultant
GRC Consultant

EhsanLab • Saudi Arabia

Hybrid
Competitive compensation aligned with market standards
Opportunity to work on high-impact regulatory projects in KSA and GCC
Exposure to leading financial institutions and fintech clients
+2