ServiceNow Architect SME – GRC/Cyber
Listed on 2026-08-31
-
IT/Tech
Cybersecurity, IT Consultant, Systems Engineer
Location:
Chantilly, VA (Government/Contractor SCIF) 100% on-site
Clearance:Active Top Secret Clearance/TS SCI Preferred
We are seeking a GRC Solution Architect to lead the design of a continuous-authorization posture for DIA’s Service Now Continuous Authorization and Monitoring (CAM) / Risk Management Framework (RMF) implementation, replacing the Agency’s existing Xacta-based authorization process. This is among the most complex Service Now GRC implementations in the Intelligence Community, and this role owns the target solution architecture, integration design and migration boundary that make the effort achievable within the funding identified.
You will define the target CAM/RMF operating model, perform out-of-the-box fit-gap analysis against the current Xacta process, and design the CMDB, Vulnerability Response, ITSM and monitoring integration set that the delivery team builds against through Crawl and Walk.
What We’re Looking For- Deep hands-on experience architecting Service Now GRC (CAM/RMF) or comparable Risk Management Framework implementations.
- Working knowledge of NIST SP 800-37 and 800-137, ICD 503 and DoD RMF.
- Experience leading fit-gap analysis and target-state architecture for complex, regulated authorization workflows.
- Ability to design integration architecture spanning CMDB, Vulnerability Response and ITSM.
- Proven ability to produce Government-approved architecture, requirements traceability and migration-boundary documentation.
- Comfortable operating as design authority in a classified, structured, or air-gapped environment.
- Own the target CAM/RMF solution architecture and integration design for the initial authorization enclave.
- Lead out-of-the-box fit-gap analysis against DIA’s current Xacta-based authorization process.
- Define the initial enclave and authorization boundary in partnership with DIA CIO4 stakeholders.
- Design the CMDB, Vulnerability Response, ITSM and monitoring integration set.
- Establish the migration boundary, security, testing and cutover strategy for the Government-approved set of active ATO packages and open POA&Ms.
- Partner with the RMF/CAM Functional SME and development team through Crawl and Walk to ensure delivered configuration matches the approved architecture.
- Support Government acceptance milestones, including IOC go-live and the Xacta retirement-readiness recommendation.
To be successful in this role, you’ll need:
Success in this role is measured by your ability to architect a defensible, Government-approved continuous-authorization solution and to keep the delivery team building against it through IOC and Walk. You proactively identify integration and migration risk and translate compliance requirements into workable Service Now design.
Must meet degree and years of experience criteria below:
High School Diploma/ GED
16
Associates Degree
14
Bachelors Degree
12
Masters Degree
10
PhD
8
Required Certifications- DoD 8570 IAT II (e.g., Security+)
- Service Now Certified System Administrator (CSA)
- Service Now Certified Implementation Specialist – GRC
- CISSP or CAP (Certified Authorization Professional)
- Service Now Certified Technical Architect (CTA)
- ITIL 4 Foundation
Salary Range: $185-275k. The final offered salary will be based on several factors, including but not limited to the candidate’s depth of experience, skill set, qualifications, and internal pay equity. Hiring at the top end of the range would not be typical, to allow for future meaningful salary growth in this position
New River Systems is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, nation origin, disability, protected veteran status or any other factor protected by law.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).