Apply Edge Start your job search

Technology GRC Manager - ServiceNow GRC/IRM

edari · Dubai, United Arab Emirates

Apply & track with Apply Edge

We are looking for a Technology GRC Manager to lead the operationalisation and continuous improvement of Technology Governance, Risk and Compliance processes for our client, an esteemed group in Dubai. This role requires hands-on ownership of GRC processes, ServiceNow GRC/IRM, technology risk and control management, workflow automation, data quality, remediation tracking, and audit-ready governance.This role will begin on a 12-month contract, is highly renewable and will report to the Director – Cybersecurity, Risk & Assurance within the Information Technology department.

Key Responsibilities

Operationalise and mature the Technology GRC framework in line with organisational strategy, risk appetite, regulatory expectations, and recognised standards.Drive adoption of standardised Technology governance, risk, control, compliance, and remediation practices across Technology teams.Act as the Technology GRC business product owner and operational lead for ServiceNow GRC/IRM, including workflows, data structures, roles, dashboards, controls, reporting, and user adoption.Maintain and prioritise the ServiceNow GRC/IRM enhancement backlog and coordinate requirements, testing, implementation, adoption, and continuous improvement.Drive the transition from fragmented manual trackers to controlled ServiceNow GRC workflows and a reliable single source of truth.Monitor platform adoption, workflow performance, data quality, and compliance with required GRC processes.Support Technology risk identification, assessment, treatment, review, acceptance, and escalation, ensuring risks are accurately maintained and monitored.Maintain traceability between risks, controls, findings, obligations, issues, actions, and remediation plans.Support the mapping and maintenance of Technology control frameworks against relevant standards, including ISO 27001, ISO 20000, COBIT, and other applicable requirements.Coordinate control monitoring, evidence collection, control reviews, and remediation activities for key Technology controls.Maintain central visibility of Technology risks, audit findings, compliance obligations, issues, management actions, and remediation plans.Drive remediation actions through to closure by managing stakeholders, dependencies, blockers, escalation, and closure evidence.Identify overdue, stalled, or repeatedly followed-up items and ensure accountable owners maintain realistic remediation plans.Identify manual or inefficient GRC activities and implement workflow automation, process simplification, and continuous improvement initiatives.Establish and monitor GRC data standards covering accuracy, completeness, timeliness, consistency, ownership, and traceability.Develop operational dashboards and KPIs covering Technology risk, control effectiveness, action closure, overdue items, data quality, process adoption, workflow performance, and automation progress.Coordinate operational activities supporting audits, certifications, compliance reviews, governance forums, and regulatory initiatives while maintaining structured evidence and action repositories.Develop and maintain Technology GRC procedures, playbooks, workflows, templates, governance records, and accountability mechanisms.Provide practical guidance and training to Technology stakeholders to improve GRC process and platform adoption.Work closely with Technology risk, compliance, audit, security, and other relevant stakeholders to establish clear ownership and avoid duplication across GRC activities.Knowledge, skills & experience:7–10 years of experience in Technology governance, risk, compliance, audit, GRC operations, process improvement, or transformation.Strong hands-on experience implementing, operating, or materially improving a GRC platform, with ServiceNow GRC / Integrated Risk Management / IRM experience strongly preferred.Experience translating governance and risk requirements into practical workflows, procedures, system requirements, data controls, and operational processes.Strong experience managing Technology risks, controls, findings, remediation plans, action tracking, and audit closure activities across multiple stakeholders.Experience delivering process automation, data-quality improvement, workflow optimisation, or operating-model maturity initiatives within a large or complex organisation.Strong understanding of Technology governance, risk assessment and treatment, control frameworks, compliance, audit, issue management, and remediation processes.Practical knowledge of ServiceNow GRC / Integrated Risk Management / IRM, including workflow design, data structures, reporting, testing, backlog management, and user adoption.Practical knowledge of ISO 27001, ISO 20000, COBIT, and other relevant Technology governance and control frameworks.Strong process design, procedure development, workflow optimisation, automation, and continuous improvement skills.Experience with GRC data governance, data-quality controls, operational dashboards, and KPI development.Strong documentation skills with an evidence-based and audit-ready approach.Strong execution and delivery focus, with the ability to drive actions through to closure.Structured, organised, self-motivated, and comfortable working within a developing function.Strong stakeholder management skills, with the ability to influence, challenge constructively, and collaborate across Technology and business functions.Ability to communicate technical and GRC matters clearly to business stakeholders.Analytical and solution-oriented, with the ability to identify root causes and implement practical improvements.Comfortable balancing hands-on delivery with manager-level ownership and accountability.Relevant certifications such as ServiceNow GRC / IRM, CRISC, CGEIT, CISA, ISO 27001 Lead Auditor / Implementer, ITIL, COBIT, Lean Six Sigma, or PMP are preferred.A Bachelor’s degree in Information Technology, Information Systems, Risk Management, Business Management, or a related discipline is preferred.Availability: Preference will be given to candidates available immediately or a maximum 30 days after accepting the offer.We are looking for a candidate who will be able to work in United Arab Emirates. Please apply with your resume and remember to provide us with your contact details.We will review your job application within 7 working days. Should your profile fit the requirements of the role, a consultant from Edari will be in touch with you to get a deeper understanding of your profile, to discuss the role in more detail and potential next steps.