Job Title: Senior ServiceNow GRC Solution Architect
Location: Washington, DC
Work Arrangement: Onsite
Position Type: Contract
Client: Amtrak
Key Responsibilities
ServiceNow GRC / IRM Architecture
- Architect, design, and implement an enterprise-wide Cyber Risk Register using ServiceNow GRC/IRM capabilities.
- Develop scalable solutions for centralized cyber risk identification, assessment, scoring, mitigation, monitoring, and remediation.
- Design and implement automated risk workflows, approval processes, escalation mechanisms, and remediation tracking.
- Develop customized reporting, dashboards, and risk visibility solutions for business and executive stakeholders.
- Ensure ServiceNow GRC solutions align with enterprise architecture and long-term technology strategies.
GRC Process Automation
- Translate business, cybersecurity, risk management, and compliance requirements into technical architecture and ServiceNow solutions.
- Automate risk identification, assessment, treatment, mitigation, escalation, and closure processes.
- Define standardized processes to improve enterprise risk visibility and consistency.
- Identify opportunities to optimize existing GRC processes through ServiceNow automation.
- Ensure workflows support appropriate governance, controls, approvals, and auditability.
Cybersecurity & Risk Management
- Apply practical knowledge of cybersecurity controls and enterprise risk management frameworks.
- Align GRC architecture and risk processes with NIST Cybersecurity Framework (NIST CSF) and NIST SP 800-53.
- Support enterprise cyber risk visibility and risk posture management.
- Ensure risk data, controls, remediation activities, and audit evidence are traceable and maintainable.
- Support regulatory compliance and enterprise audit-readiness initiatives.
Enterprise Integration & Data Architecture
- Integrate ServiceNow GRC/IRM capabilities with enterprise IT, cybersecurity, security operations, and other related platforms.
- Ensure data integrity, consistency, traceability, and auditability across integrated systems.
- Define integration patterns and data flows between ServiceNow and heterogeneous enterprise applications.
- Collaborate with technical teams to identify integration dependencies and resolve architectural challenges.
Solution Architecture & Project Leadership
- Lead technical activities throughout the full project lifecycle, including:
- Project scoping
- Requirements gathering
- Business analysis
- Solution architecture
- Technical design
- Implementation
- Integration
- Testing
- Deployment
- Post-production support
- Evaluate solution alternatives and provide architecture recommendations.
- Create technical designs, architecture documentation, and implementation strategies.
- Ensure solutions are scalable, secure, maintainable, and aligned with enterprise standards.
Stakeholder & Executive Engagement
- Partner with business leaders, IT leadership, cybersecurity teams, risk committees, and other stakeholders.
- Present architecture options and recommendations to senior leadership and governance committees.
- Facilitate discussions and drive consensus across diverse stakeholder groups.
- Translate complex technical and cybersecurity concepts into clear business-level recommendations.
- Provide executive leadership with actionable visibility into enterprise cyber risks, remediation progress, and overall risk posture.
Required Qualifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline, or equivalent professional experience.
- 8 15+ years of overall IT experience.
- 2 5+ years of focused Governance, Risk, and Compliance (GRC) experience.
- Strong experience architecting and implementing enterprise-scale ServiceNow solutions.
- Proven hands-on expertise with ServiceNow GRC / Integrated Risk Management (IRM).
- Experience designing and implementing Cyber Risk Registers or comparable enterprise risk management solutions.
- Strong understanding of cybersecurity controls, risk management, and governance processes.
- Practical knowledge of:
- NIST Cybersecurity Framework (NIST CSF)
- NIST SP 800-53
- Demonstrated experience working as a Solution Architect across large-scale, heterogeneous IT environments.
- Strong understanding of enterprise information management and risk architecture.
- Experience with ServiceNow workflows, automation, reporting, dashboards, and integrations.
- Strong understanding of data integrity, traceability, auditability, and enterprise integrations.
- Excellent verbal and written communication skills.
- Proven ability to influence senior stakeholders, present to committees, facilitate discussions, and build consensus.
- Strong analytical, problem-solving, and strategic-thinking skills.
Preferred Qualifications
- Experience delivering technology solutions within the public sector.
- Experience in the transportation, transit, railroad, or travel industry.
- Experience working with large transportation or infrastructure organizations.
- Strong knowledge of enterprise information management and risk architecture.
- Experience with Secure Software Development Life Cycle (SSDLC) practices.
- Experience integrating ServiceNow GRC with enterprise cybersecurity and IT platforms.
- Experience supporting regulatory compliance, governance, and audit-readiness initiatives.
- ServiceNow certifications related to GRC, IRM, or Solution Architecture are a plus.
Key Skills
ServiceNow GRC / IRM
ServiceNow Solution Architecture
Cyber Risk Register
Governance, Risk & Compliance (GRC)
Cybersecurity Risk Management
NIST CSF
NIST SP 800-53
Risk Assessment & Risk Scoring
Risk Mitigation & Remediation Tracking
ServiceNow Workflow & Automation
ServiceNow Reporting & Dashboards
Enterprise Architecture
Enterprise System Integration
Data Integrity & Auditability
Cybersecurity Controls
Compliance & Governance
Secure SDLC
Stakeholder & Executive Management
Public Sector / Transportation Experience