- Company Name
- Axiom Path
- Job Title
- Lead IT Policy & Compliance Analyst (ServiceNow GRC) #3551647
- Job Description
-
Job Title: Lead IT Policy & Compliance Analyst (ServiceNow GRC)
Role Summary: Lead the execution and automation of enterprise policy and compliance operations using ServiceNow GRC/IRM modules. Manage policy lifecycle, ticket queues, evidence collection, and reporting while collaborating with Security, Risk, Legal, Audit, and IT stakeholders.
Expactations:
- 3+ years of hands‑on ServiceNow GRC/IRM experience, preferably with ServiceNow ITSM.
- Demonstrated knowledge of NIST SP 800‑53, NIST CSF, ISO/IEC 27001, and SaaS regulatory frameworks (HIPAA, SOX, NY DFS, SOC 1/2).
- Bachelor's degree in Information Technology, Computer Science, or equivalent practical experience.
- Strong written and verbal communication; ability to engage technical and non‑technical audiences.
- Detail‑oriented, organized, able to manage competing priorities.
Key Responsibilities:
- Administer and optimize ServiceNow Policy and Compliance modules; maintain accurate configuration and day‑to‑day operations.
- Oversee ITSM ticket queues for policy, catalog, and compliance requests; ensure timely triage, tracking, and resolution.
- Operationalize and automate policy lifecycle activities: reviews, attestations, continuous monitoring, and control testing.
- Drive workflow improvements to reduce manual evidence collection and enhance control validation efficiency.
- Support “test once, satisfy many” approach for regulatory, audit, and assurance requirements.
- Coordinate enterprise‑wide evidence collection for audits, regulatory inquiries, and internal reviews.
- Develop dashboards, metrics, and reporting to provide compliance insights to leadership.
- Implement continuous monitoring processes to proactively detect and remediate policy or control violations.
- Create and maintain SOPs, job aids, and documentation supporting governance processes.
- Independently manage competing priorities while maintaining high accuracy and quality standards.
Required Skills:
- ServiceNow GRC/IRM administration.
- ServiceNow ITSM knowledge.
- Governance, risk, and compliance (GRC) principles in regulated environments.
- Understanding of SDLC and basic project management.
- Familiarity with Unified Control Framework (UCF) and Shared Assessments SIG.
- Ability to work effectively in a distributed team environment.
- Strong analytical and problem‑solving capabilities.
Required Education & Certifications:
- Bachelor’s degree in IT, Computer Science, or related field (or equivalent experience).
- Certifications: Security+, CISA, CISSP, CISM, CGRC, PMP, or NIST‑related credentials (preferred).
- Knowledge of regulatory frameworks such as HIPAA, SOX, NY DFS, SOC 1/2 (advantage).