SonicJobs Logo
Left arrow iconBack to search

ServiceNow IRM Practice Lead

iTech AG
Posted 2 days ago, valid for a month
Location

Arlington, VA, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

OVERVIEW 

iTech AG is seeking an IRM Practice Lead – ServiceNow Architect (Integrated Risk Management) to lead the solution architecture for a federal customer's cyber risk and Continuous Authorization and Monitoring (CAM) program. This is a senior, architect-level role responsible for owning the end-to-end IRM solution design on the ServiceNow platform and the integration architecture that connects it across multiple ServiceNow products — IRM/CAM, Policy and Compliance Management, Risk Management, Flow Designer and Workflow Studio, IntegrationHub, Service Portal/UI Builder, Virtual Agent, and AI/Now Assist.

The ideal candidate is a true ServiceNow architect who has implemented IRM end-to-end, from control library and authorization boundary design through SSP management, POA&M and issue remediation, control testing, risk registers, dashboards, and data migration, and can direct developers to deliver it. They bring proven experience architecting cross-product ServiceNow solutions and enterprise integrations in FISMA/FedRAMP-governed environments. This role owns the IRM Technical Solutions, defines integration and security patterns, and collaborates with the iTech Solution SMEs, customers, and iTech Certified Master Architects.

ROLES AND RESPONSIBILITIES

  • Own the end-to-end solution architecture for the ServiceNow IRM/CAM solution, including solution design, data model, control hierarchy, and the phased roadmap across modules
  • Architect and lead the implementation of ServiceNow IRM capabilities across the solution, including:
    • Continuous Authorization and Monitoring (CAM)
    • System Security Plans (SSPs) and Authorization Boundaries
    • Control Testing, Assessment, and Continuous Monitoring
    • Issue, Deficiency, and POA&M Management
    • Cyber Risk Register and Risk Assessments
    • Common and Inherited Controls
    • Policy and Compliance Management (authority documents, policies, and control attestations)
    • Audit Management and auditor evidence workflows
    • Third-Party / Vendor Risk Management
    • Business Continuity Management and contingency planning (CP control family)
    • Dashboards, Reporting, and Stakeholder Visibility
  • Author and maintain the Technical Solution — architecture diagrams, data model, control hierarchy, integration patterns, and security model — and drive architecture decisions and approvals each sprint
  • Configure IRM Continuous Authorization and Monitoring (CAM) for SSPs, POA&Ms, control testing, risk assessments, and control inheritance
  • Build automated issue and deficiency workflows, including assignment, notifications, tracking, review, and approval
  • Configure collaborative workflows to replace email-based processes across multiple security and technical teams
  • Design support for multiple authorization boundaries and SSPs, including GSS, ICS, and subsystem relationships
  • Configure common controls and inherited controls so control relationships cascade appropriately across parent systems and subsystems
  • Implement a cyber risk register and the workflows for creating, reviewing, and approving risk assessments
  • Build configurable dashboards and reports for issues, remediation status, SSP and control status, risks, and approvals that end users can adjust without recoding
  • Configure the annual SSP update and approval process, including auditor review and sign-off requirements
  • Ensure the control library supports the required NIST control and enhancement granularity — potentially down to examples such as AC-2(1)(b) — and design a documented workaround if native depth is insufficient
  • Plan and execute the IRM data migration effort, including:
    • Migration of approximately 10–14 SSPs, using OSCAL where feasible
    • An alternate JSON/import-map transformation approach where OSCAL is not viable
    • A practical manual, system-by-system configuration fallback if automation is not possible
    • Validation of migrated control, POA&M, and boundary data against source systems
  • Define and govern the integration architecture between ServiceNow IRM and external systems, including authoritative control and compliance data sources, customer SSO, ITSM/ticketing, and enterprise reporting or data warehouse platforms
  • Identify how digital approvals and signatures will be handled on the current platform, including an interim workflow if native signature capability is unavailable
  • Establish development standards and hands-on build the most complex components — custom applications, workflows, business rules, UI policies, integrations, and Flow Designer automations
  • Partner with iTech AG Master Architects and the Solution SME on cross-product architecture and technical governance
  • Serve as a contributing member of the iTech AG ServiceNow Center of Excellence (CoE), sharing reusable patterns, standards, and lessons learned across programs
  • Act as the organization-wide leader for the IRM product area — advising other programs and pursuits, informing the IRM capability roadmap, and supporting proposal and solutioning efforts beyond this project
  • Lead the approximately four-week discovery with security stakeholders to validate processes, data sources, control hierarchy, and migration assumptions
  • Participate in Agile ceremonies including sprint planning, backlog refinement, demos, and retrospectives, and contribute to Technical Solution Document (TSD) updates each sprint
  • Lead code and design reviews, mentor developers, and enforce platform best practices and technical governance
  • Support platform upgrades, patching, and performance optimization activities, and resolve IRM defects, workflow issues, and production support requests
  • Ensure configurations and customizations align with federal security, compliance (e.g., NIST 800-53, FISMA, FedRAMP), accessibility, and data governance requirements
  • Contribute to technical documentation, knowledge transfer, operational readiness, and end-user adoption efforts
  • Other duties as assigned

 

MINIMUM QUALIFICATIONS

  • 5+ years of hands-on ServiceNow experience, including 3+ years in a technical lead role
  • 3+ years leading ServiceNow Integrated Risk Management (IRM) implementations end-to-end
  • Deep architecture and hands-on experience across:
    • Continuous Authorization and Monitoring (CAM) and SSP management
    • Control libraries, control testing, and continuous control monitoring
    • Issue, deficiency, and POA&M remediation workflows
    • Cyber risk register and risk assessment workflows
    • Dashboards, reporting, and stakeholder self-service
  • Working knowledge of NIST 800-53 control families and enhancements, FISMA, and the authorization boundary / ATO lifecycle
  • Experience designing integration architecture using IntegrationHub and REST/SOAP APIs, and leading GRC/IRM data migration
  • Strong experience defining ServiceNow data models, security models, and overall platform architecture
  • Proficiency with ServiceNow scripting including JavaScript, Glide APIs, Script Includes, and Flow Designer
  • Experience working in Agile delivery environments (ServiceNow Now Create methodology a plus)
  • Strong analytical, troubleshooting, and problem-solving skills, and experience leading, mentoring, and setting technical direction for developers

EDUCATION AND CERTIFICATIONS

  • Bachelor’s degree or equivalent years experience
  • ServiceNow Certified System Administrator (CSA) or equivalent years experience
  • ServiceNow Certified Application Developer (CAD) or equivalent years experience
  • ServiceNow Certified Implementation Specialist (CIS) – Risk and Compliance (IRM), with additional CIS certifications across products (e.g., Data Foundations (CMDB/CSDM), ITSM, CSM, Discovery) a plus

PREFERRED QUALIFICATIONS

  • Experience supporting federal government programs subject to FISMA and/or FedRAMP authorization
  • Experience with OSCAL-based SSP export/import and control data transformation
  • Experience migrating from eMASS, Xacta, CSAM, or comparable GRC/ATO platforms into ServiceNow
  • Familiarity with continuous control monitoring, automated evidence collection, and control test automation
  • Experience implementing ServiceNow Policy and Compliance Management, Risk Management, Audit Management, or Vendor Risk Management
  • Experience implementing ServiceNow Business Continuity Management, Privacy Management, or Operational Resilience Management
  • Experience linking ServiceNow Security Operations (Vulnerability Response, Configuration Compliance) findings to IRM issues and POA&Ms
  • Familiarity with Now Assist for IRM, including AI-assisted control mapping and evidence summarization
  • Strong experience with Service Portal, UI Builder, and dashboard and reporting design for executive and auditor audiences
  • Familiarity with ServiceNow data model, CMDB relationships, and platform performance optimization
  • Experience with ServiceNow Now Create methodology and IntegrationHub-based integrations
  • Familiarity with ServiceNow Virtual Agent and AI / Now Assist capabilities
  • Strong communication, stakeholder engagement, and collaboration skills

SECURITY CLEARANCE

  • Ability to obtain and maintain a Public Trust
  • Pursuant to government contracts, US Citizenship is required

iTech AG is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, genetic information, disability, protected veteran status, or any other characteristics protected by federal, state, or local laws.

 

iTech AG is committed to working with and providing reasonable accommodations to individuals with disabilities. Individuals with a disability who would like to request an accommodation for any part of the employment process should email their request to reasonableaccommodations@itechag.com. Please address the subject line as Accommodation Request and include your name, contact information, and a description of your accommodation request.




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.