وصف العمل
الغرض من الدور قيادة أو دعم التطبيق الوظيفي لـ ServiceNow Governance, Risk, and Compliance / Integrated Risk Management capabilities.
يترجم الدور العمليات المعتمدة للحوكمة والضمان إلى متطلبات وتكوينات عملية لـ ServiceNow، وي Supports customer workshops, and helps deliver traceable, testable, and adoption-ready solutions.
المعرفة والخبرة اللازمة · ما لا يقل عن 5 سنوات من الخبرة ذات الصلة في GRC, الضمان، المرونة، أو استشارات ServiceNow، بما فيها ثلاثة أعوام على الأقل من التعرض الفعلي لتنفيذ ServiceNow.
· خبرة عملية في أحد مجالات: إدارة الامتثال، إدارة استمرارية الأعمال، أو التدقيق الداخلي على الأقل.
يعتبر وجود خبرة في أكثر من مجال واحد أمراً مفضلاً بشدة.
· وجود خبرة مثبتة في تنفيذ ServiceNow GRC/IRM تشمل على الأقل منطقة منتج ذات صلة مثل السياسة والامتثال، المخاطر، التدقيق، أو BCM.
· معرفة عملية بالضوابط، الأدلة، القضايا/النتائج، التصحيح، الموافقات، الشهادات، التقييمات، التقارير، ومسارات التدقيق.
· القدرة على تسهيل ورش العمل التجارية وتحويل الاحتياجات إلى متطلبات وظيفية قابلة للتنفيذ والاختبار.
· خبرة في دعم اختبارات قبول المستخدم، حل العيوب، التحقق من البيانات، واستعداد النشر.
· إتقان اللغة العربية قراءة وكتابة تحدثاً شرط رئيسي لهذا الدور نظرًا لتنظيم ورش العمل مع أصحاب المصلحة الذين يتحدثون العربية في السياسات، الامتثال، المخاطر، BCM، والتدقيق.
الخبرة المفضلة · خبرة مع مؤسسات كبرى أو منظمة منظمة، خاصة في القطاع المصرفي أو الخدمات المالية.
· التعرض لأطر تنظيمية وضوابط مثل SAMA، ISO 27001، ISO 22301، ISO 31000، COSO، COBIT، NIST، أو ما يعادله.
· الخبرة مع مخاطر الطرف الثالث، المرونة التشغيلية، التغييرات التنظيمية، اختبارات الضوابط، المؤشرات، أو إدارة القضايا.
· القدرة على مراجعة تكوين ServiceNow والتدفقات والتواصل بفعالية مع المطورين والمعماريين.
الشهادات الأكاديمية والمهنية · المطلوب: درجة البكالوريوس ذات صلة مثل نظم المعلومات، علوم الحاسوب، الهندسة، إدارة الأعمال، إدارة المخاطر، المحاسبة، المالية، أو تخصص ذي صلة.
· المطلوب: ServiceNow Certified System Administrator (CSA).
· المطلوب أو المطلوب الحصول عليه خلال فترة الانضمام المتفق عليها: ServiceNow Certified Implementation Specialist – Risk and Compliance (CIS-RC).
· المطلوب: شهادة مهنية واحدة على الأقل ذات صلة بمجال المرشح مثل CISA أو CIA أو CRISC أو CGEIT أو ISO 27001 Lead Implementer/Lead Auditor، ISO 22301 Lead Implementer/Lead Auditor، CBCI/CBCP، PMI-RMP، أو ما يعادلها.
· مفضل بشدة: مؤهل دراسي عالٍ في المخاطر، التدقيق، الامتثال، المرونة، أنظمة المعلومات، أو إدارة الأعمال.
الكفاءات الأساسية تصميم عمليات GRC والتفكير التحليلي تكوين وظيفي لـ ServiceNow ورش العمل وإدارة أصحاب المصلحة تتبُّع المتطلبات والوثائق الجودة، الاختبار، ونظام الأدلة ضبط النطاق والاعتماد والمخاطر .
· إجراء جلسات الاكتشاف وورش العمل العملية مع أصحاب المصلحة من السياسة والامتثال والمخاطر و BCM والتدقيق الداخلي ومالك الرقابة والتكنولوجيا.
· تقييم العمليات الحالية وتحديد سير العمل المستقبلي، الأدوار، الموافقات، الإشعارات، التصعيدات، احتياجات الأدلة، ومتطلبات التقارير.
· إعداد أو توجيه إعداد تكوينات ServiceNow GRC/IRM ذات الصلة وفقًا للمتطلبات المعتمدة، معايير المنصة، والنطاق المتفق عليه.
· تحديد الكيان، الوثيقة التفويض، السياسة، الضابط، المخاطر، القضية، المؤشر، الاستمرارية، التدقيق، النتائج، والتعويضات حيثما كان ذلك ممكناً.
· إعداد أو مراجعة وثائق التصميم الوظيفي، قصص المستخدم، معايير القبول، دفاتر تكوين، مخططات العمليات، وسجلات التتبع.
· دعم توصيف البيانات وما تتبعه من تحقق للسياسات والمحتوى التنظيمي والمخاطر والضوابط والتدقيق والخطط والسجلات التاريخية ذات الصلة.
· دعم تعريف متطلبات التكامل والتحقق الوظيفي أثناء تنسيق التصميم والتطوير التقني مع فريق التكامل المسؤول.
· إعداد سيناريوهات الاختبار؛ دعم اختبار تكامل النظام، التحضير لاختبار قبول المستخدم، فرز العيوب، التحقق من التصحيح، وموافقة العمل.
· تطوير مواد التدريب للمستخدم النهائي وتقديم جلسات تدريب قبل أو بعد الإطلاق.
· توفير عروض توضيحية، نقل المعرفة، إرشاد المشرفين، ووثائق تسليم وظيفي.
· إرشاد أصحاب المصلحة حول الاستخدام العملي لحزم GRC/IRM خارج الصندوق وتحديد الطلبات التي تتطلب تخصيصاً أو ترخيصاً إضافياً أو تغييراً تحكمياً.
· تحديد ثغرات النطاق، الاعتمادات، المخاطر، الافتراضات، وطلبات التغيير مبكراً؛ وتجنب الالتزامات غير المدعومة أو التكوين غير الموثق.
مرشح مفضل
سنوات الخبرة
لا حاجة للخبرة
الدرجة العلمية
درجة البكالوريوس / دبلوم عالي
Job description
Role purpose Lead or support the functional implementation of ServiceNow Governance, Risk, and Compliance / Integrated Risk Management capabilities.
The role translates approved governance and assurance processes into practical ServiceNow requirements and configurations, supports customer workshops, and helps deliver traceable, testable, and adoption-ready solutions.
Mandatory experience and knowledge · At least 5 years of relevant GRC, assurance, resilience, or ServiceNow consulting experience, including at least 3 years of hands-on ServiceNow implementation exposure.
· Hands-on practitioner or implementation experience in at least one of the following domains: Compliance Management, Business Continuity Management, or Internal Audit.
Experience in more than one is strongly preferred.
· Demonstrated ServiceNow GRC/IRM implementation experience involving at least one relevant product area such as Policy and Compliance, Risk, Audit, or BCM.
· Working knowledge of controls, evidence, issues/findings, remediation, approvals, attestations, assessments, reporting, and audit trails.
· Ability to facilitate business workshops and convert business needs into implementable and testable functional requirements.
· Experience supporting UAT, defect resolution, data validation, and deployment readiness.
· Fluent Arabic language proficiency, spoken and written, is mandatory for this role given direct workshop facilitation with Arabic-speaking policy, compliance, risk, BCM, and audit stakeholders.
Preferred experience · Experience with enterprise or regulated organizations, especially banking or financial services.
· Exposure to regulatory and control frameworks such as SAMA, ISO 27001, ISO 22301, ISO 31000, COSO, COBIT, NIST, or equivalent.
· Experience with third-party risk, operational resilience, regulatory change, control testing, indicators, or issue management.
· Ability to review ServiceNow configuration and flows and communicate effectively with developers and architects.
Academic and professional certifications · Required: Relevant bachelor’s degree such as Information Systems, Computer Science, Engineering, Business Administration, Risk Management, Accounting, Finance, or a related discipline.
· Required: ServiceNow Certified System Administrator (CSA).
· Required or to be obtained within the agreed onboarding period: ServiceNow Certified Implementation Specialist – Risk and Compliance (CIS-RC).
· Required: At least one relevant professional certification appropriate to the candidate’s domain depth, such as CISA, CIA, CRISC, CGEIT, ISO 27001 Lead Implementer/Lead Auditor, ISO 22301 Lead Implementer/Lead Auditor, CBCI/CBCP, PMI-RMP, or equivalent.
· Strongly preferred: Postgraduate qualification in risk, audit, compliance, resilience, information systems, or business administration.
Core competencies GRC process design and analytical thinking ServiceNow functional configuration Workshop facilitation and stakeholder management Requirements traceability and documentation Quality, testing, and evidence discipline Scope, dependency, and risk management .
· Conduct discovery and process workshops with policy, compliance, risk, BCM, internal audit, control-owner, and technology stakeholders.
· Assess current-state processes and define future-state workflows, roles, approvals, notifications, escalations, evidence needs, and reporting requirements.
· Configure or guide configuration of applicable ServiceNow GRC/IRM capabilities in line with approved requirements, platform standards, and agreed scope.
· Define entity, authority document, policy, control, risk, issue, indicator, continuity, audit, finding, remediation, and evidence relationships where applicable.
· Prepare or review functional design documents, user stories, acceptance criteria, configuration workbooks, process flows, and traceability records.
· Support data mapping and migration validation for policies, regulatory content, risks, controls, audits, findings, plans, and related historical records.
· Support integration requirement definition and functional validation while coordinating technical design and development with the responsible integration team.
· Prepare test scenarios; support system integration testing, UAT preparation, defect triage, remediation validation, and business sign-off.
· Develop the end user training material and conduct end user training sessions before or after going live.
· Provide demonstrations, knowledge transfer, administrator guidance, and functional handover documentation.
· Advise stakeholders on practical use of out-of-box GRC/IRM capabilities and identify requests requiring customization, additional licensing, or change control.
· Identify scope gaps, dependencies, risks, assumptions, and change requests early; avoid unsupported commitments or undocumented configuration.
Preferred candidate
Years of experience
No experience required
Degree
Bachelor's degree / higher diploma