SRM Digital LLC is seeking an experienced ServiceNow IRM Business Analyst with strong expertise in Integrated Risk Management (IRM) and Governance, Risk & Compliance (GRC). The ideal candidate will bridge business requirements with technical solutions, drive IRM implementations, and ensure alignment with ServiceNow platform best practices.
Responsibilities:
- Partner with business stakeholders to gather, analyze, and document functional and technical requirements
- Translate business requirements into detailed functional specifications and technical user stories for the development team
- Serve as the primary liaison between business users, architects, developers, and platform teams
- Map end-to-end business processes to ServiceNow IRM configurations and capabilities
- Support the design, analysis, and implementation of ServiceNow IRM solutions
- Validate system configurations and ensure delivered solutions align with business requirements
- Conduct demos and walkthroughs of IRM implementations for business stakeholders
- Collaborate with ServiceNow Architects to ensure solutions adhere to platform best practices and design standards
- Review configurations and development outputs to ensure quality and requirement alignment
- Facilitate the development of IRM reports and dashboards to support governance and risk visibility
Requirements:
- 8+ years of experience as a ServiceNow Business Analyst, with at least 3+ years focused on ServiceNow IRM implementations
- Strong expertise in Integrated Risk Management (IRM) / Governance, Risk & Compliance (GRC)
- Proven hands-on experience implementing and configuring ServiceNow IRM solutions
- Deep understanding of end-to-end business processes and ability to map them to ServiceNow IRM capabilities
- Experience working in Agile environments and translating requirements into user stories
- Strong stakeholder management and cross-functional collaboration skills
- Experience across the following ServiceNow IRM modules: Policy & Compliance Management, Risk Management, Audit Management, Third-Party Risk Management
- Strong understanding of risk statements, risk scoring models, and assessment methodologies
- Strong understanding of control frameworks, control testing, and issue management
- Strong understanding of policy lifecycle management and attestation processes
- Strong understanding of regulatory mapping and evidence collection
- Strong understanding of IRM reporting, dashboards, and analytics