×
Register Here to Apply for Jobs or Post Jobs. X

ServiceNow IRM Practice Lead

Job in Arlington, Arlington County, Virginia, 22201, USA
Listing for: iTech AG
Full Time position
Listed on 2026-09-13
Job specializations:
  • IT/Tech
    Cybersecurity, IT Consultant, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 150000 - 210000 USD Yearly USD 150000.00 210000.00 YEAR
Job Description & How to Apply Below

OVERVIEW

iTech AG is seeking an IRM Practice Lead – Service Now Architect (Integrated Risk Management) to lead the solution architecture for a federal customer's cyber risk and Continuous Authorization and Monitoring (CAM) program. This is a senior, architect-level role responsible for owning the end-to-end IRM solution design on the Service Now platform and the integration architecture that connects it across multiple Service Now products – IRM/CAM, Policy and Compliance Management, Risk Management, Flow Designer and Workflow Studio, Integration Hub, Service Portal/UI Builder, Virtual Agent, and AI/Now Assist.

The ideal candidate is a true Service Now architect who has implemented IRM end-to-end, from control library and authorization boundary design through SSP management, POA&M and issue remediation, control testing, risk registers, dashboards, and data migration, and can direct developers to deliver it. They bring proven experience architecting cross-product Service Now solutions and enterprise integrations in FISMA/FedRAMP-governed environments. This role owns the IRM Technical Solutions, defines integration and security patterns, and collaborates with the iTech Solution SMEs, customers, and iTech Certified Master Architects.

ROLES

AND RESPONSIBILITIES
  • Own the end-to-end solution architecture for the Service Now IRM/CAM solution, including solution design, data model, control hierarchy, and the phased roadmap across modules
  • Architect and lead the implementation of Service Now IRM capabilities across the solution, including:
    • Continuous Authorization and Monitoring (CAM)
    • System Security Plans (SSPs) and Authorization Boundaries
    • Control Testing, Assessment, and Continuous Monitoring
    • Issue, Deficiency, and POA&M Management
    • Cyber Risk Register and Risk Assessments
    • Common and Inherited Controls
    • Policy and Compliance Management (authority documents, policies, and control attestations)
    • Audit Management and auditor evidence workflows
    • Third-Party / Vendor Risk Management
    • Business Continuity Management and contingency planning (CP control family)
    • Dashboards, Reporting, and Stakeholder Visibility
  • Author and maintain the Technical Solution — architecture diagrams, data model, control hierarchy, integration patterns, and security model — and drive architecture decisions and approvals each sprint
  • Configure IRM Continuous Authorization and Monitoring (CAM) for SSPs, POA&Ms, control testing, risk assessments, and control inheritance
  • Build automated issue and deficiency workflows, including assignment, notifications, tracking, review, and approval
  • Configure collaborative workflows to replace email-based processes across multiple security and technical teams
  • Design support for multiple authorization boundaries and SSPs, including GSS, ICs, and subsystem relationships
  • Configure common controls and inherited controls so control relationships cascade appropriately across parent systems and subsystems
  • Implement a cyber risk register and the workflows for creating, reviewing, and approving risk assessments
  • Build configurable dashboards and reports for issues, remediation status, SSP and control status, risks, and approvals that end users can adjust without recoding
  • Configure the annual SSP update and approval process, including auditor review and sign-off requirements
  • Ensure the control library supports the required NIST control and enhancement granularity — potentially down to examples such as AC-2(1)(b) — and design a documented workaround if native depth is insufficient
  • Plan and execute the IRM data migration effort, including:
    • Migration of approximately 10–14 SSPs, using OSCAL where feasible
    • An alternate JSON/import-map transformation approach where OSCAL is not viable
    • A practical manual, system-by-system configuration…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary