Tech Stack
Cyber SecurityJavaScriptServiceNowSOAPSplunk
About the role
- Design, configure, and enhance the Vulnerability Response (VR) module in ServiceNow
- Build workflows and automation for vulnerability triage, prioritization, assignment, and remediation tracking
- Create custom dashboards, reports, and metrics for vulnerability KPIs and SLA monitoring
- Implement and maintain correlation rules between vulnerability items and CMDB CIs
- Collaborate with cybersecurity, infrastructure, and application teams to align remediation workflows with enterprise risk management objectives
- Customize and support SecOps modules: SIR, VR, Threat Intelligence
- Integrate with external tools such as SIEMs, email security gateways, and vulnerability scanners
- Design orchestration workflows for automated threat response
- Develop scripts, business rules, and notifications
- Configure dashboards for visibility into threat and vulnerability data
- Maintain and secure MID Servers for on-prem communication
- Collaborate with security analysts to refine detection and response workflows
Requirements
- Bachelor's degree
- at least 5 years of ServiceNow development experience, specifically in Vulnerability Response
- deep experience with SecOps/VR Suite
- Integrations: REST APIs, IntegrationHub, data import sets
- Strong grasp of Vulnerability process and role-based access controls in VR
- Certifications (Nice to Have): CSA, CIS–VR, CIS–GRC, CIS–SECOPS
- Strong analytical mindset, attention to detail, and excellent stakeholder communication
- Experience with Splunk, QRadar, Qualys, Tenable
- Integration Knowledge: REST APIs, MID Server, Orchestration, PowerShell scripting
- Certifications (Preferred): CSA, CIS–SecOps, Security+, GCIH
- Strong communication, problem-solving abilities, and teamwork with security teams
- Understanding of cybersecurity principles, vulnerability lifecycle management, and risk assessment
- Hands-on experience with integrating ServiceNow with scanning tools
- Proficiency in scripting (JavaScript), Glide API, REST/SOAP APIs, and MID Servers