Policy, compliance, and controls
Authority documents, policies, control objectives, controls, attestations, indicators, evidence, testing, issues, exceptions, and the ownership model behind them.
Start a search
IRM / GRC staffing
Find ServiceNow Integrated Risk Management people who understand the operating decisions behind the control framework: architects, developers, risk and compliance specialists, product owners, and delivery leads screened by practitioners.
01 — The specialty
IRM, still widely known as ServiceNow GRC, connects policies, risks, controls, evidence, issues, third parties, and resilience work. We look for people who can turn that structure into an operating model the business can actually use.
Authority documents, policies, control objectives, controls, attestations, indicators, evidence, testing, issues, exceptions, and the ownership model behind them.
Risk statements, taxonomies, assessments, scoring, appetite, treatment, indicators, loss events, issues, and reporting that supports accountable decisions.
Audit planning, engagements, workpapers, evidence, findings, remediation, validation, and coordination across internal audit, compliance, risk, and control owners.
Vendor tiering, due diligence, assessments, issues, monitoring, business impact analysis, continuity plans, exercises, recovery, and operational resilience.
02 — Practitioner screening
Real IRM ownership shows up when evidence is incomplete, scoring is disputed, control failures cross teams, and remediation competes with operating priorities. We look for the decisions that made risk data credible and follow-through visible.
We ask how authority sources, policies, control objectives, controls, owners, evidence, testing, and issues were connected without creating duplicate work.
We follow the issue through risk evaluation, ownership, treatment, exception, remediation, validation, escalation, and closure to understand who made each decision.
We look for the taxonomy, scoring logic, data authority, indicators, quality controls, and reporting choices that turned platform records into a defensible view of risk.
03 — Roles we place
We recruit across permanent, contract, and contract-to-hire needs. The search starts with the risk domains, control model, regulatory obligations, data sources, stakeholders, and decisions the person must own.
Risk and control model, solution design, integrations, data authority, governance, security, and technical direction.
Assessments, workflows, workspaces, integrations, automation, reporting, and maintainable platform extensions.
Frameworks, policies, risks, controls, assessments, indicators, issues, treatment, governance, and operating-model design.
Audit planning, engagements, testing, evidence, findings, remediation, assurance coordination, and control effectiveness.
Vendor risk, due diligence, monitoring, continuity, business impact, exercises, recovery, issues, and accountable ownership.
Roadmap, governance, intake, stakeholder alignment, adoption, service health, and measurable risk-program outcomes.
04 — Start the conversation
On the first call, we’ll give you an honest view of search difficulty, candidate availability, and likely timing. If the brief is still broad, we’ll help separate platform responsibilities from risk-and-compliance ownership.
Looking for your next IRM or GRC role? Introduce yourself confidentially.