IRM Business Process Consultant
ServiceNow
- Location
- Sao Paulo, SAO PAULO, Brazil
- Employment
- Full Time
- Work model
- Remote
- Level
- Mid
- H-1B history
- 185 approvals (FY2023)
- Posted
- 1h ago
Skills
About this role
Company Description
It all started when engineer Fred Luddy wrote code that automated a tedious task for his coworker, Phyllis. She cried tears of joy. That moment inspired Fred to build a company that could do that for everyone—freeing people from busywork so they could focus on meaningful work. Today, ServiceNow is the AI control tower for business reinvention. Our ServiceNow AI platform brings together any AI, any data, and any workflow— helping 85% of the Fortune 500® work smarter, faster, and better. We're building an AI-native culture where technology and talent are unstoppable together. And we're just getting started. Join us to put AI to work for people.
Job Description
Job Description The Business Process Consultant – IRM is a trusted advisor who partners with customers to analyze, design, and optimize risk, compliance, resilience, and audit processes through the ServiceNow IRM platform. This role bridges business risk objectives and technology solutions, helping organizations mature their GRC operating model while delivering measurable business outcomes. The BPC – IRM leads discovery activities, facilitates workshops, gathers requirements, and provides process expertise across Risk Management, Policy & Compliance, BCM/TPRM, Audit, and Privacy engagements. Working closely with customers, architects, technical consultants, and project teams, the BPC ensures solutions align with risk appetite, regulatory requirements, and organizational priorities. What You Get To Do In This Role Lead customer discovery workshops to understand risk, compliance, resilience, and audit challenges and objectives. Analyze current-state GRC processes and define future-state risk operating models. Gather, document, and prioritize business requirements across Risk, Policy & Compliance, TPRM, BCM, Audit, and Privacy. Translate customer needs into solution requirements and user stories for IRM modules. Provide process advisory based on industry leading practices (NIST, ISO 27001, COBIT, ISF SOGP, etc.) and ServiceNow IRM capabilities. Facilitate alignment between executive risk owners, compliance/audit teams, and technical delivery teams. Support solution design activities by ensuring risk and compliance requirements are clearly defined and understood. Drive change management and adoption conversations across GRC engagements. Identify opportunities for risk process standardization, automation, and control efficiency. Present recommendations and findings to risk, compliance, and executive stakeholders.
Key Responsibilities
Conduct risk and compliance maturity assessments (e.g., aligned to NIST CSF, ISO 27001, etc.). Document process flows, operating models, business requirements, and functional specifications for Risk, Policy & Compliance, TPRM, BCM, Audit, and Privacy. Facilitate stakeholder interviews and working sessions with risk owners, compliance officers, and auditors. Lead requirements validation and process design workshops for GRC use cases. Define business outcomes, success metrics, and value realization plans for IRM programs. Collaborate with Technical Consultants and Architects to ensure solution alignment. Support testing, training, and user adoption activities for risk and compliance users. Identify project risks, dependencies, and business impacts across IRM implementations. Provide guidance on governance, organizational readiness, and risk operating model design. Contribute to IRM practice assets, methodologies, and knowledge sharing.
Qualifications
Required 4+ years of experience in GRC consulting, risk/compliance transformation, audit, or related fields. Experience leading workshops and managing customer-facing discussions with risk and compliance stakeholders. Strong business process analysis and requirements gathering skills applied to