IRM 业务流程顾问
IRM Business Process Consultant
#### 公司简介
一切始于工程师Fred Luddy为他的同事Phyllis编写了一段代码,自动化了一个繁琐的任务。她感动得流下了眼泪。这一时刻激发了Fred创建一家公司,让每个人都能摆脱琐事,专注于有意义的工作。如今,ServiceNow是企业转型的AI控制中心。我们的ServiceNow AI平台整合任何AI、任何数据和任何工作流程,帮助85%的财富500强®企业更聪明、更快、更好地工作。我们正在打造一种AI原生文化,让技术和人才携手不可阻挡。而我们才刚刚开始。
加入我们,让AI为人们工作。
#### 职位描述
**职位描述**
**业务流程顾问 – IRM** 是一位值得信赖的顾问,与客户合作,通过ServiceNow IRM平台分析、设计和优化风险、合规、韧性和审计流程。该角色连接业务风险目标和技术解决方案,帮助组织提升其GRC运营模式,同时实现可衡量的业务成果。
BPC – IRM负责主导发现活动,组织研讨会,收集需求,并在风险管理、政策与合规、BCM/TPRM、审计和隐私项目中提供流程专业知识。与客户、架构师、技术顾问和项目团队紧密合作,BPC确保解决方案符合风险偏好、监管要求和组织优先事项。
**您将在此职位中从事以下工作**
- 主导客户发现研讨会,了解风险、合规、韧性和审计的挑战与目标。
- 分析当前的GRC流程并定义未来状态的风险运营模型。
- 收集、记录并优先处理风险、政策与合规、TPRM、BCM、审计和隐私方面的业务需求。
- 将客户需求转化为IRM模块的解决方案需求和用户故事。
- 基于行业领先实践(如NIST、ISO 27001、COBIT、ISF SOGP等)和服务Now IRM功能提供流程咨询。
- 协调高管风险负责人、合规/审计团队和技术交付团队之间的对齐。
- 通过确保风险和合规需求明确且被理解,支持解决方案设计活动。
- 推动GRC项目中的变革管理和采用讨论。
- 识别风险流程标准化、自动化和控制效率的机会。
- 提交报告
查看英文原文
#### Company Description
It all started when engineer Fred Luddy wrote code that automated a tedious task for his coworker, Phyllis. She cried tears of joy. That moment inspired Fred to build a company that could do that for everyone—freeing people from busywork so they could focus on meaningful work. Today, ServiceNow is the AI control tower for business reinvention. Our ServiceNow AI platform brings together any AI, any data, and any workflow— helping 85% of the Fortune 500® work smarter, faster, and better. We're building an AI-native culture where technology and talent are unstoppable together. And we're just getting started.
Join us to put AI to work for people.
#### Job Description
**Job Description**
The **Business Process Consultant – IRM** is a trusted advisor who partners with customers to analyze, design, and optimize risk, compliance, resilience, and audit processes through the ServiceNow IRM platform. This role bridges business risk objectives and technology solutions, helping organizations mature their GRC operating model while delivering measurable business outcomes.
The BPC – IRM leads discovery activities, facilitates workshops, gathers requirements, and provides process expertise across Risk Management, Policy & Compliance, BCM/TPRM, Audit, and Privacy engagements. Working closely with customers, architects, technical consultants, and project teams, the BPC ensures solutions align with risk appetite, regulatory requirements, and organizational priorities.
**What You Get To Do In This Role**
- Lead customer discovery workshops to understand risk, compliance, resilience, and audit challenges and objectives.
- Analyze current-state GRC processes and define future-state risk operating models.
- Gather, document, and prioritize business requirements across Risk, Policy & Compliance, TPRM, BCM, Audit, and Privacy.
- Translate customer needs into solution requirements and user stories for IRM modules.
- Provide process advisory based on industry leading practices (NIST, ISO 27001, COBIT, ISF SOGP, etc.) and ServiceNow IRM capabilities.
- Facilitate alignment between executive risk owners, compliance/audit teams, and technical delivery teams.
- Support solution design activities by ensuring risk and compliance requirements are clearly defined and understood.
- Drive change management and adoption conversations across GRC engagements.
- Identify opportunities for risk process standardization, automation, and control efficiency.
- Present recommendations and findings to risk, compliance, and executive stakeholders.
**Key Responsibilities**
- Conduct risk and compliance maturity assessments (e.g., aligned to NIST CSF, ISO 27001, etc.).
- Document process flows, operating models, business requirements, and functional specifications for Risk, Policy & Compliance, TPRM, BCM, Audit, and Privacy.
- Facilitate stakeholder interviews and working sessions with risk owners, compliance officers, and auditors.
- Lead requirements validation and process design workshops for GRC use cases.
- Define business outcomes, success metrics, and value realization plans for IRM programs.
- Collaborate with Technical Consultants and Architects to ensure solution alignment.
- Support testing, training, and user adoption activities for risk and compliance users.
- Identify project risks, dependencies, and business impacts across IRM implementations.
- Provide guidance on governance, organizational readiness, and risk operating model design.
- Contribute to IRM practice assets, methodologies, and knowledge sharing.
#### Qualifications
**To be successful in this role you have:**
**Qualifications Required**
- 4+ years of experience in GRC consulting, risk/compliance transformation, audit, or related fields.
- Experience leading workshops and managing customer-facing discussions with risk and compliance stakeholders.
- Strong business process analysis and requirements gathering skills applied to risk, compliance, or audit domains.
- Experience documenting business requirements, process maps, and functional designs.
- Strong facilitation and stakeholder management skills.
- Excellent written and verbal communication abilities.
- Professional English proficiency.
**Preferred**
- Experience with ServiceNow IRM or other GRC/risk SaaS platforms.
- Knowledge of risk and compliance frameworks (NIST CSF, ISO 27001/27002, ISF SOGP, COBIT, DORA).
- Experience with operating model redesign and BCM/resilience programs.
- Working knowledge of Agile delivery methodologies.
- Spanish proficiency for LATAM-facing roles.
**Success Profile**
- Independently leads customer workshops and discovery engagements across IRM domains.
- Acts as the primary risk/compliance process advisor for medium-to-large projects.
- Identifies opportunities to improve customer risk posture and business outcomes.
- Translates complex risk and compliance challenges into actionable requirements.
- Builds trusted relationships with risk, compliance, and audit stakeholders.
- Drives alignment between risk objectives and solution delivery teams.
#### Additional Information
**Work Personas**
We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. [Learn more here](https://careers.servicenow.com/life-at-servicenow#workpersonas). To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.
**Equal Opportunity Employer**
ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, age, disability, gender identity, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.
**Accommodations**
We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact [globaltalentss@servicenow.com](mailto:globaltalentss@servicenow.com) for assistance.
**Export Control Regulations**
For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.
From Fortune. ©2026 Fortune Media IP Limited. All rights reserved. Used under license.