ServiceNow Developer GRCIRM
Job Summary
ServiceNow Developer - GRC/IRM
Experience: 4-6 Years
Position | ServiceNow Developer - GRC/IRM | Experience | 4-6 Years |
Locations | Pune | Work Model | Hybrid / As per business requirements |
Position Summary
We are seeking a ServiceNow Developer specializing in Governance Risk and Compliance (GRC) and Integrated Risk Management (IRM) to design configure develop and support scalable risk and compliance solutions on the ServiceNow platform. The role combines hands-on platform development with practical knowledge of risk controls compliance audit and issue remediation processes. The successful candidate will translate business requirements into maintainable workflows assessments dashboards integrations and technical components that improve enterprise risk visibility and compliance execution.
Work Youll Do
Design configure develop test and support ServiceNow GRC/IRM solutions across the project lifecycle.
Work with business risk compliance audit security and technology stakeholders to convert functional requirements into technical designs and working solutions.
Build reusable secure and upgrade-aware platform components in line with ServiceNow development standards.
Participate in estimation sprint planning demonstrations testing release activities defect resolution documentation and production support.
Contribute to continuous improvement through workflow automation continuous monitoring automated evidence collection and responsible use of Artificial Intelligence (AI)-enabled capabilities.
Configure extend or support ServiceNow Otto for Integrated Risk Management (IRM) formerly Now Assist for IRM including Generative Artificial Intelligence (GenAI) skills and agentic workflows where available in the deployed release and licensed environment.
Key Responsibilities
Design configure and maintain ServiceNow GRC/IRM capabilities including Risk Management Policy and Compliance Management Audit Management Issue Management Vendor Risk Management (VRM) or Third-Party Risk Management (TPRM) and Business Continuity Management (BCM) based on project scope.
Configure risk statements risk assessments scoring methodologies control objectives controls indicators attestations authority documents policies issues findings and remediation workflows.
Develop ServiceNow components using JavaScript Glide Application Programming Interfaces (APIs) Business Rules Client Scripts Script Includes User Interface (UI) Policies UI Actions Flow Designer Studio and scoped applications.
Configure roles groups and Access Control Lists (ACLs) to support secure and appropriate access to risk and compliance information.
Create reports dashboards and Key Performance Indicators (KPIs) for risk posture compliance status control effectiveness audit findings open issues overdue remediation and third-party risk.
Integrate ServiceNow with enterprise platforms using Representational State Transfer (REST) Simple Object Access Protocol (SOAP) Integration Hub MID Server import sets transform maps and scripted interfaces where required.
Support automated evidence collection and data exchange with security identity vulnerability asset document and enterprise systems.
Implement or support AI-assisted IRM use cases such as issue and risk-assessment summarization control-objective rationalization and deduplication control recommendations assessment-response assistance and guided issue remediation with appropriate human review and governance.
Perform unit testing system integration testing defect analysis technical troubleshooting code review and release validation.
Create and maintain technical designs configuration workbooks test evidence implementation plans deployment instructions and operational documentation.
Provide technical guidance to team members and communicate design decisions dependencies risks and delivery status to relevant stakeholders.
Required Qualifications
4-6 years of overall ServiceNow platform experience with substantial hands-on experience implementing or supporting GRC/IRM solutions.
Implementation experience in at least two core GRC/IRM areas such as Risk Management Policy and Compliance Management Audit Management Issue Management or Vendor/Third-Party Risk Management.
Strong ServiceNow development capability using JavaScript Glide APIs Business Rules Script Includes Client Scripts UI Policies UI Actions Flow Designer and scoped application development.
Familiarity with ServiceNow Artificial Intelligence (AI) capabilities relevant to IRM including ServiceNow Otto for IRM / Now Assist for IRM Generative AI AI agents agentic workflows Predictive Intelligence AI Search and responsible AI implementation principles.
Working knowledge of the GRC/IRM data model and relationships among entities risks controls control objectives policies authority documents indicators issues findings and remediation tasks.
Experience developing integrations using REST SOAP Integration Hub MID Server import sets transform maps JavaScript Object Notation (JSON) and Extensible Markup Language (XML).
Experience with reporting dashboards data imports update sets or application repository-based deployments and ServiceNow release practices.
Understanding of Software Development Life Cycle (SDLC) Agile delivery User Acceptance Testing (UAT) release management and post-production support.
Strong analytical troubleshooting communication documentation and stakeholder collaboration skills.
Bachelors degree in Computer Science Information Technology Engineering or a related discipline or equivalent practical experience.
Functional Knowledge
Governance Risk and Compliance (GRC) and Integrated Risk Management (IRM) concepts including risk identification assessment treatment monitoring and reporting.
Policy lifecycle control mapping control testing attestations compliance monitoring audit lifecycle findings exceptions issues and remediation.
Familiarity with one or more relevant frameworks or regulations such as International Organization for Standardization (ISO) 27001 National Institute of Standards and Technology (NIST) Sarbanes-Oxley Act (SOX) Payment Card Industry Data Security Standard (PCI DSS) General Data Protection Regulation (GDPR) Health Insurance Portability and Accountability Act (HIPAA) or Federal Risk and Authorization Management Program (FedRAMP).
Preferred Qualifications
ServiceNow Certified System Administrator (CSA).
ServiceNow Certified Implementation Specialist - Risk and Compliance (CIS-RC) or the current equivalent ServiceNow certification applicable to the deployed product release.
ServiceNow Certified Application Developer (CAD).
Exposure to implementing or supporting ServiceNow Otto for IRM / Now Assist for IRM AI agents Generative AI skills intelligent summarization recommendations or AI-enabled risk and compliance workflows is preferred.
Experience with Third-Party Risk Management Business Continuity Management continuous monitoring indicator management or automated evidence collection.
Experience with UI Builder configurable workspaces Automated Test Framework (ATF) Performance Analytics or ServiceNow platform upgrades.
Exposure to Configuration Management Database (CMDB) Common Service Data Model (CSDM) Security Operations (SecOps) Vulnerability Response or related enterprise integrations is advantageous but not mandatory.
Key Technical Skills Experience and Knowledge
Capability Area | Expected Proficiency |
ServiceNow GRC/IRM | Risk Policy and Compliance Audit Issues Vendor/Third-Party Risk Business Continuity |
Platform Development | JavaScript Glide APIs Business Rules Script Includes Client Scripts UI Policies UI Actions Flow Designer Studio |
Security and Data | ACLs roles groups scoped applications data imports transform maps data quality |
Integrations | REST SOAP Integration Hub MID Server JSON XML scripted interfaces |
Reporting | Reports dashboards KPIs Performance Analytics exposure |
Delivery | Agile SDLC estimation testing UAT release management defect resolution documentation |
ServiceNow AI Capabilities | ServiceNow Otto for IRM / Now Assist for IRM Generative AI AI agents agentic workflows Predictive Intelligence AI Search intelligent summarization and recommendations with human oversight |
Essential Competencies
Hands-on quality-focused developer with sound technical judgment and attention to maintainability.
Ability to work independently while collaborating effectively with functional consultants architects testers administrators and business stakeholders.
Clear written and verbal communication including the ability to explain technical matters to non-technical audiences.
Structured problem solving ownership of assigned deliverables and proactive risk and dependency management.
Commitment to secure development peer review documentation knowledge sharing and continuous learning.
Role Logistics
Location: Pune
Work Model: Hybrid or as defined by business requirements
Shift Timings: As per project and business requirements. Any rotational or night-shift expectation should be explicitly communicated during the hiring process.
Candidate Screening Guidance
Candidates should demonstrate depth rather than only broad module exposure. During screening validate at least one end-to-end GRC/IRM implementation the candidates individual development contribution understanding of the IRM data model scripting proficiency integration ownership and ability to explain a risk-to-remediation workflow using a real project example.
Required Experience:
IC