Position Name : Senior ServiceNow GRC Solution Architect
Location : Washington, DC
Duration: Long term
Job description :
Randstad is seeking a Senior ServiceNow GRC Solution Architect to lead the design and implementation of an enterprise-wide Cyber Risk Register in ServiceNow for a major transportation client in Washington, D.C.
Serving as a key strategic advisor across business and IT units, you will translate complex cyber risk requirements into scalable, automated ServiceNow solutions—including workflows, reporting, dashboards, and remediation tracking. In this high-visibility role, you will interface with cross-functional leadership, drive consensus, and align GRC architecture with NIST frameworks to enhance enterprise risk visibility, strengthen governance, and ensure audit readiness throughout the project lifecycle.
Education & Experience:
Bachelor’s degree (or equivalent experience) with 8–15+ years in IT, including 2–5+ years focused specifically within a Governance, Risk, and Compliance (GRC) function.
ServiceNow Expertise: Proven track record of successfully architecting and deploying large-scale ServiceNow solutions, particularly within GRC/Integrated Risk Management (IRM).
Cybersecurity Frameworks:
Strong practical knowledge of cybersecurity controls and risk frameworks, specifically NIST CSF and NIST 800-53.
Large-Scale Architecture:
Demonstrated experience acting as a Solution Architect across multiple heterogeneous, large-scale IT programs.
Stakeholder Management:
Exceptional verbal and written communication skills with a proven ability to present to committees, influence senior stakeholders, and build consensus.
Experience delivering IT solutions within the public sector, transit, or travel/transportation industry.
Deep grounding in enterprise information management, risk architecture, and secure software development lifecycles.
Architect & Implement GRC Capability: Design and deploy a centralized, enterprise Cyber Risk Register in ServiceNow, including automated workflows, risk scoring, custom reporting, dashboards, and remediation tracking.
Strategic Vision & Consensus Building: Partner with cross-functional business areas, IT leaders, and risk committees to define the future-state GRC architecture, present solutions, gain concurrence, and ensure sustainable service delivery.
Process Automation & Optimization: Enable consistent risk identification, assessment, mitigation, and escalation processes by translating business and risk management requirements into technical architecture.
Platform Integration & Data Integrity: Integrate ServiceNow GRC modules with related enterprise IT and security platforms, ensuring data integrity, traceability, and auditability.
Full Lifecycle Leadership: Lead technical efforts across all phases of the project lifecycle—from initial scoping and requirements gathering through architecture design, implementation, and post-deployment alignment.
Executive Visibility & Governance: Provide executive leadership with actionable visibility into enterprise cyber risks, remediation progress, and overall risk posture to support regulatory compliance and audit readiness.