ServiceNow IRM & GRC Staffing & Recruiting | Kaladesi
Start a search
Kaladesi / ServiceNow specialties

IRM / GRC staffing

ServiceNow
IRM staffing.

Find ServiceNow Integrated Risk Management people who understand the operating decisions behind the control framework: architects, developers, risk and compliance specialists, product owners, and delivery leads screened by practitioners.

Full-timeContractContract-to-hire

01 — The specialty

A control library is not a risk program.

IRM, still widely known as ServiceNow GRC, connects policies, risks, controls, evidence, issues, third parties, and resilience work. We look for people who can turn that structure into an operating model the business can actually use.

AREA/01

Policy, compliance, and controls

Authority documents, policies, control objectives, controls, attestations, indicators, evidence, testing, issues, exceptions, and the ownership model behind them.

AREA/02

Enterprise and operational risk

Risk statements, taxonomies, assessments, scoring, appetite, treatment, indicators, loss events, issues, and reporting that supports accountable decisions.

AREA/03

Audit and assurance

Audit planning, engagements, workpapers, evidence, findings, remediation, validation, and coordination across internal audit, compliance, risk, and control owners.

AREA/04

Third-party risk and resilience

Vendor tiering, due diligence, assessments, issues, monitoring, business impact analysis, continuity plans, exercises, recovery, and operational resilience.

02 — Practitioner screening

Risk ownership appears between assessment and action.

Real IRM ownership shows up when evidence is incomplete, scoring is disputed, control failures cross teams, and remediation competes with operating priorities. We look for the decisions that made risk data credible and follow-through visible.

QUESTION/01

How did a requirement become a control?

We ask how authority sources, policies, control objectives, controls, owners, evidence, testing, and issues were connected without creating duplicate work.

QUESTION/02

What happened when a control failed?

We follow the issue through risk evaluation, ownership, treatment, exception, remediation, validation, escalation, and closure to understand who made each decision.

QUESTION/03

Which risk data could leadership trust?

We look for the taxonomy, scoring logic, data authority, indicators, quality controls, and reporting choices that turned platform records into a defensible view of risk.

03 — Roles we place

The right IRM seat, clearly defined.

We recruit across permanent, contract, and contract-to-hire needs. The search starts with the risk domains, control model, regulatory obligations, data sources, stakeholders, and decisions the person must own.

IRM/01

IRM Architect

Risk and control model, solution design, integrations, data authority, governance, security, and technical direction.

IRM/02

IRM Developer

Assessments, workflows, workspaces, integrations, automation, reporting, and maintainable platform extensions.

IRM/03

Risk / Compliance Consultant

Frameworks, policies, risks, controls, assessments, indicators, issues, treatment, governance, and operating-model design.

IRM/04

Audit / Controls Specialist

Audit planning, engagements, testing, evidence, findings, remediation, assurance coordination, and control effectiveness.

IRM/05

Third-Party Risk / Resilience Specialist

Vendor risk, due diligence, monitoring, continuity, business impact, exercises, recovery, issues, and accountable ownership.

IRM/06

IRM Product Owner

Roadmap, governance, intake, stakeholder alignment, adoption, service health, and measurable risk-program outcomes.

04 — Start the conversation

Tell us what the risk program must make visible.

On the first call, we’ll give you an honest view of search difficulty, candidate availability, and likely timing. If the brief is still broad, we’ll help separate platform responsibilities from risk-and-compliance ownership.

Looking for your next IRM or GRC role? Introduce yourself confidentially.