ServiceNow Business Analyst – IRM/GRC at ServiceNow Platform · Bengaluru (Bangalore), Mumbai, Hyderabad, Delhi · 7 - 10 years · ₹18L - ₹20L / yr · Posted 30 Jun 2026

Job Summary
We are seeking an experienced ServiceNow Business Analyst with strong expertise in Integrated Risk Management (IRM) and Governance, Risk, and Compliance (GRC). The ideal candidate will bridge business needs and technical solutions, driving the implementation and optimization of ServiceNow IRM/GRC modules while ensuring alignment with organizational risk and compliance objectives.
Key Responsibilities
- Collaborate with stakeholders to gather, analyze, and document business requirements for IRM/GRC processes
- Translate business requirements into functional specifications and user stories for ServiceNow implementations
- Lead workshops, requirements sessions, and stakeholder meetings
- Configure and support ServiceNow IRM/GRC modules, including:
- Policy and Compliance Management,
- Risk Management,
- Audit Management,
- Vendor Risk Management
- Work closely with developers and architects to ensure accurate implementation of requirements
- Perform gap analysis and recommend process improvements aligned with industry best practices
- Support User Acceptance Testing (UAT), including test case creation and defect management
- Maintain documentation, including BRDs, FRDs, process flows, and user guides
- Ensure data integrity, reporting accuracy, and dashboard creation within ServiceNow
- Provide ongoing support and enhancements post-implementation
Required Skills & Qualifications
- 6+ years of experience as a ServiceNow Business Analyst, with at least 4+ years in ServiceNow IRM/GRC
- Strong understanding of risk management and compliance frameworks (e.g., ISO 27001, NIST, SOX)
- Hands-on experience with ServiceNow IRM/GRC modules
- Proficiency in requirement gathering, stakeholder management, and business process mapping
- Experience working in Agile/Scrum environments
- Strong analytical, problem-solving, and communication skills
- Ability to work with cross-functional teams and manage multiple priorities
Preferred Qualifications
- ServiceNow Certified System Administrator (CSA)
- ServiceNow Certified Implementation Specialist – Risk and Compliance (CIS-RC)
- Experience with integrations, reporting, and dashboards in ServiceNow
- Knowledge of ITSM processes and their alignment with GRC
- Prior consulting or client-facing experience
Key Competencies
- Stakeholder Management
- Business Analysis & Requirement Elicitation
- Risk & Compliance Domain Knowledge
- Process Improvement
- Communication & Presentation Skills
Nice to Have
- Experience with SecOps or Third-Party Risk Management
- Exposure to automation and workflow optimization within ServiceNow
- Understanding of regulatory environments across industries (BFSI, Healthcare, etc.)

Similar jobs (9)
Key Responsibilities –
- Requirement Gathering & Analysis: Collaborate with business units to understand their needs and challenges, and document these into functional specifications, user stories, and process workflows.
- Process Design: Design, document, and improve business processes and workflows within the ServiceNow platform to identify opportunities for automation and increased efficiency.
- Solution Implementation: Work with the development team to ensure that requirements are understood and implemented correctly, assisting with configuration and testing, including User Acceptance Testing (UAT).
- Stakeholder Communication: Act as a liaison between IT and business departments, ensuring clear communication, managing expectations, and providing support to end-users.
- Documentation & Reporting: Maintain system documentation, process maps, and standard operating procedures (SOPs), and create reports for management on project progress and system performance.
- Optimization: Identify opportunities to optimize the use of ServiceNow across various modules (e.g., ITSM, ITOM, GRC, HRSD, CSM, ITAM) and assist with managing and creating dashboards and performance metrics.
Required Qualifications
- A degree in a relevant field like Computer Science or Information Technology.
- Proven experience in implementing and configuring ServiceNow solutions.
- 5+ years hands-on ServiceNow development experience, with demonstrable delivery on client-facing implementation projects
- 2+ years working directly in ServiceNow GRC/IRM, specifically Policy and Compliance Management and/or Risk Management. Candidates whose GRC exposure is limited to a single mod
- Demonstrated experience with Flow Designer, business rules, client scripts, UI Actions, UI Policies, and script includes
- Experience configuring notifications and inbound email actions, including email-actionable approvals
- Experience with ACL configuration and understanding of role-based access design
- Experience with SLA definitions and task-based SLA behavior
- Experience with Service Catalog record producers and Employee Center / Service Portal configuration
- Proficiency with update set management and promotion across development, test, and production instances
- ServiceNow Certified System Administrator (CSA) required CIS Advanced Risk preferred
Roles & Responsibilities
- Develop and customize ServiceNow solutions with strong focus on IRM and Third-Party Risk Management (TPRM).
- Configure and customize TPRM workflows covering third-party onboarding, due diligence, risk assessments and review processes.
- Configure questionnaires, assessment templates, scoring methodologies, risks, controls and control objectives.
- Develop and configure Business Rules, Client Scripts, UI Policies, ACLs, Forms and Catalog components.
- Automate approval and vendor onboarding workflows using Flow Designer.
- Work on ServiceNow scripting using JavaScript and Glide APIs.
- Develop integrations with external systems using REST APIs, Scripted REST APIs and REST Messages.
- Create and customize tables, fields, forms, reports and dashboards based on business requirements.
- Work on ServiceNow Policy & Compliance / Risk & Compliance capabilities wherever required.
- Troubleshoot workflows, approvals, notifications, integrations and other ServiceNow issues.
- Follow ServiceNow development best practices, change management and deployment processes.
Ideal Candidate
1.Strong ServiceNow Developer / ServiceNow IRM / TPRM profiles
2.Mandatory (Experience 1) - Must have minimum 3+ years of overall IT experience with strong hands-on experience in ServiceNow Development, including configuration, customization and implementation.
3Mandatory (Experience 2) - Must have strong hands-on experience in ServiceNow Integrated Risk Management (IRM), with specific experience in Third-Party Risk Management (TPRM)
4.Mandatory (Experience 3) - Must have hands-on experience working on end-to-end TPRM processes, including Third-Party/Vendor Onboarding, Due Diligence, Risk Assessment, Review and Approval workflows
5.Mandatory (Experience 4) - Must have experience configuring and customizing TPRM questionnaires, assessment templates, scoring methodologies, Risk, Risk Statements, Controls and Control Objectives
6.Mandatory (Experience 5) - Must have strong ServiceNow development experience with Business Rules, Client Scripts, UI Policies, ACLs, Forms, Tables and Fields
7Mandatory (Experience 6) - Must have hands-on experience with Flow Designer for workflow automation, including vendor onboarding, approvals and TPRM-related business processes
8.Mandatory (Experience 7) - Must have strong programming/scripting experience in JavaScript and ServiceNow Glide APIs, with hands-on development of client-side and server-side scripts
9.Mandatory (Experience 8) - Must have experience developing integrations with external systems using REST APIs, Scripted REST APIs and REST Messages
10.Mandatory (Experience 9) - Must have strong experience troubleshooting ServiceNow workflows, approvals, notifications and integrations
11.Mandatory (Domain Exclusion) - Candidate must have hands-on development experience in TPRM/IRM; profiles with only ServiceNow ITSM, ServiceNow Administration or generic ServiceNow support experience will not be considered. - Required
12.Mandatory (Age) - Candidate's Age should be below 28 years.
13.Mandatory (CTC) - The CTC breakup offered will be 75% fixed + 25% variable, as per company policy
14.Preferred (Experience 1) - Candidates with experience in ServiceNow Policy & Compliance and/or Audit Management modules will be preferred.
15.Preferred (Experience 2) - Candidates with ServiceNow CSA / CIS certifications, particularly certifications related to IRM, Risk, Compliance or relevant ServiceNow modules, will be preferred.
16.Preferred (Experience 3) - Experience with ServiceNow Workspace, instance upgrades, quarterly cloning, deployment/change management and platform optimization will be preferred
17.Preferred (Certification) - ServiceNow CSA or CIS certifications, especially CIS-IRM or CIS-TPRM.
This role is focused on Cyber Security Risk, Governance, Risk & Compliance (GRC), IT Controls, and Security Audits, with strong emphasis on Backup, Disaster Recovery (DR), and Business Continuity (BCP).
Key responsibilities:
- Perform security control assessments against organizational policies, security standards, and regulatory requirements.
- Identify control gaps, risks, audit findings, and compliance issues, and monitor remediation until closure.
- Assess Backup, Disaster Recovery, and Business Continuity processes and controls.
- Validate backup availability, restoration/recovery procedures, DR readiness, and evidence of periodic DR/BCP testing.
- Conduct control testing and risk assessments and support internal/external security audits.
- Review security policies, procedures, standards, and governance frameworks for compliance.
- Maintain audit evidence, track findings, and coordinate with stakeholders for remediation.
- Support overall security governance, regulatory compliance, and IT risk management activities.
Required Skills
- Cyber Security Risk & Compliance / GRC
- IT Risk & Controls
- Security Control Assessment & Testing
- Security Audits
- Backup & Disaster Recovery
- BCP / DR
- Risk Assessment
- Compliance & Governance
- Security Policies & Standards
- Audit Finding & Remediation Management
ServiceNow USEM Technical Consultant -(Offshore) Contract Role
· Location- Remote
· Contract- 6 months
Job Description
Position Description:
The ServiceNow USEM (SecOps) Technical Consultant (Security Operations) is responsible to lead the design, development, and implementation of security operations (SecOps) solutions on the ServiceNow platform. This role is responsible for integrating security workflows, enhancing automation, and optimizing security response processes to ensure robust cybersecurity operations.
Primary Responsibilities:
Design, configure, and implement ServiceNow GRC/IRM modules, focusing on Policy, Compliance, and Risk Management frameworks. Develop custom solutions utilizing Flow Designer, Business Rules, Client Scripts, UI Actions, UI Policies, and Script Includes.
Configure Service Portal/Employee Center components, Service Catalog record producers, notifications, inbound email actions, and email-actionable approvals.
Manage Access Control Lists (ACLs) and role-based access designs alongside SLA definitions and task-based SLA behaviors.
Handle update set management and oversee code promotion across development, test, and production instances.
Requirements
Qualifications:
· 5+ years hands-on ServiceNow development experience, with demonstrable delivery on client-facing implementation projects
· 2+ years working directly in ServiceNow GRC/IRM, specifically Policy and Compliance Management and/or Risk Management. Candidates whose GRC exposure is limited to a single mod
· Demonstrated experience with Flow Designer, business rules, client scripts, UI Actions, UI Policies, and script includes
· Experience configuring notifications and inbound email actions, including email-actionable approvals
· Experience with ACL configuration and understanding of role-based access design
· Experience with SLA definitions and task-based SLA behavior
· Experience with Service Catalog record producers and Employee Center / Service Portal configuration
· Proficiency with update set management and promotion across development, test, and production instances
· ServiceNow Certified System Administrator (CSA) required CIS Advanced Risk preferred
· Work Experience: 5+ years
· Industry: Technology
- 5+ years of ServiceNow development or implementation experience, including at least 3 years focused on ServiceNow TPRM.
- Bachelor's degree from an accredited college or university, or equivalent relevant professional experience.
- Strong hands-on knowledge of ServiceNow TPRM and relevant platform capabilities, including Flow Designer, UI Builder, business rules, notifications, UI pages, UI macros, formatters, database views, reporting, dashboards, and role-based security.
We are seeking an experienced Governance, Risk & Compliance (GRC) Lead to spearhead the
design, implementation, and maintenance of our ISO 27001 Information Security Management
System (ISMS). This is a hands-on leadership role responsible for establishing a robust security
governance framework, achieving ISO 27001 certification, and embedding a culture of
continuous security improvement across the organization.
Key Responsibilities
● ISMS Implementation & Certification: Lead end-to-end ISO 27001 implementation
from gap analysis through to successful Stage 1 and Stage 2 certification audits;
manage external auditor relationships
● Risk Management: Develop and operationalize the information security risk
management framework; conduct risk assessments, treatment planning, and risk
acceptance processes.
● Policy & Governance : Author, approve, and maintain the Statement of Applicability
(SoA), information security policies, standards, and procedures aligned with ISO 27001
Annex A controls.
● Control Implementation: Translate ISO 27001 Annex A controls into operational
security measures; coordinate with IT, Accounts, HR, Backoffice, and business units to
implement and validate controls.
● Compliance Monitoring: Establish continuous monitoring, internal audit programs, and
KPIs/KRIs to measure ISMS effectiveness; manage non-conformities and corrective
actions.
● Third-Party Risk: Oversee vendor security assessments and ensure supply chain
security controls meet organizational and ISO 27001 standards.
● Stakeholder Management: Report ISMS performance, risks, and compliance status to
senior leadership and the board; act as primary liaison for external auditors and
regulators.
Required Qualifications
● 5+ years of experience in information security governance, risk, and compliance
● Proven track record of leading at least one full ISO 27001:2022 certification cycle (gap
analysis → certification)
● Deep expertise in ISO 27001:2022 standard, Annex A controls, and ISMS
documentation requirements
● Strong understanding of risk assessment methodologies (e.g., ISO 27005, NIST RMF,
OCTAVE, FAIR)
● Familiarity with internal audit practices and managing external certification bodies
● Excellent stakeholder management and ability to influence across technical and non-
technical teams
● Strong documentation and communication skills — able to translate complex standards
into actionable guidance
Preferred Qualifications
● Experience implementing ISMS in fintech, healthcare, or regulated industries
● Experience with SOC 2, GDPR, NIST CSF, PCI-DSS, or other compliance frameworks
● Background in cloud security (AWS, Azure, GCP) and DevSecOps environments
● Knowledge of automation for compliance evidence collection and control testing
● Certifications: CISM, CRISC, CISA, ISO 27001 Lead Auditor, or ISO 27001 Lead
Implementer
Why Join Us
● Opportunity to build the security governance function from the ground up
● High-visibility role with direct impact on customer trust and market differentiation
● Collaborative environment that values security as a business enabler, not a blocker
Company Profile:
We are a one-stop financial services shop, widely known for quality of its advice, personalized
service and cutting-edge technology. We started our journey in 2008. Currently we are serving
more than 50,000 investors with a team of 100 members. Our core product offering is mutual
fund, FD, Govt. Bonds, Debenture, etc.
ServiceNow TPRM Sr.Solution Engineer (Offshore)
· Location- Remote
· Contract- 6 months
· Budget- 1.50 lpm
Job Description
Position Description:
Templar Shield is seeking a highly skilled ServiceNow TPRM Sr. Solution Engineer to provide advisory and technical leadership for the design, optimization, implementation, and sustainment of ServiceNow Third-Party Risk Management solutions. This role translates business needs into practical platform capabilities, prioritizes out-of-box functionality, and delivers solutions aligned with Templar Shield and ServiceNow best practices.
Requirements
Primary Objectives:
· Provide advisory support and implementation best practices for ServiceNow Third-Party Risk Management.
· Assess and optimize existing ServiceNow TPRM implementations, including processes, workflows, configurations, and operating practices.
· Review and refine third-party risk tiering, Inherent Risk Questionnaires (IRQ), Vendor Risk Assessments (VRA), and scoring methodologies to improve consistency and alignment with business needs.
· Define and recommend solution options for formally tracking risk mitigation activities in ServiceNow, considering applicable licensing constraints and other business, technical, and operational factors.
· Support the creation, review, and refinement of ServiceNow user stories, acceptance criteria, process designs, test plans, and implementation documentation using Agile/Scrum methods.
· Provide advisory and subject matter expert support for client-led development, testing, validation, defect management, user acceptance testing, rollout planning, and rollout execution.
· Prepare and support project-related documentation, solution demonstrations, and stakeholder presentations.
· Provide post-rollout hypercare, troubleshooting, and knowledge transfer for the TPRM solution in accordance with the applicable project plan or other written agreement.
· Provide knowledge transfer and advisory support to client personnel for ongoing operation, administration, and sustainment of the TPRM program following project completion.
· Design, configure, implement, and support TPRM workflows, assessments, notifications, reporting, dashboards, portals, integrations, approval paths, exceptions, and ongoing monitoring.
· Develop and maintain integrations between ServiceNow TPRM and third-party tools using APIs and web services, including JSON, SOAP, and XML.
· Create and maintain solution design specifications, configuration records, deployment notes, troubleshooting guidance, and technical knowledge articles.
· Provide technical guidance and TPRM best practices to client teams; train and mentor junior consultants and administrators.
· Collaborate effectively with distributed teams and manage assigned work in alignment with client expectations and delivery standards.
Qualifications:
Core Experience:
· 5+ years of ServiceNow development or implementation experience, including at least 3 years focused on ServiceNow TPRM.
· Bachelor's degree from an accredited college or university, or equivalent relevant professional experience.
· Demonstrated ability to lead technical workstreams, facilitate client discussions, solve complex problems, and exercise independent judgment in a customer-focused consulting environment.
· Excellent written and verbal communication, analytical, documentation, troubleshooting, and teamwork skills.
Technical Skills:
· Strong hands-on knowledge of ServiceNow TPRM and relevant platform capabilities, including Flow Designer, UI Builder, business rules, notifications, UI pages, UI macros, formatters, database views, reporting, dashboards, and role-based security.
· Proficiency in ServiceNow scripting and development, including JavaScript, Glide API, web services, and application configuration; experience with HTML and CSS. Familiarity with React, AngularJS, or Java is beneficial.
· Ability to design TPRM data models, workflow automation, integrations, security roles, reports, and client-specific configurations while maintaining platform upgradeability.
· Knowledge of third-party risk assessment, compliance, control testing, issue management, remediation, internal audit, and continuous monitoring methodologies.
· Knowledge of common security and compliance frameworks, such as NIST SP 800-53, NIST SP 800-171, NIST CSF, ISO 27000 series, PCI DSS, CIS, and NERC CIP. Knowledge of ServiceNow Performance Analytics, ITSM, or ITOM is a plus.
Certifications:
· ServiceNow Certified System Administrator required. ServiceNow Certified Implementation Specialist in TPRM preferred.
🚨 Hiring: ServiceNow Developer | ITSM + HRSD
We are looking for an experienced ServiceNow Developer to join our team!
🔹 Experience: 6+ Years
🔹 Skills: ServiceNow, ITSM, HRSD
🔹 Location: Bangalore
🔹 Work Mode: Hybrid – 3 Days WFO
🔹 Interview Process:
• Round 1 – Virtual
• Round 2 – Face-to-Face (FTF)
🔹 Interview: Tomorrow
📩 Interested candidates, please share your updated resume.
#Hiring #ServiceNow #ServiceNowDeveloper #ITSM #HRSD #BangaloreJobs #HybridJobs #TechJobs #ImmediateHiring #ITJobs #JobOpening







