ServiceNow SecOps Specialist
FyerxJob Description
This is a remote position.
ServiceNow SecOps Specialist
Job Details
- Employment Type: Contract
- Work Mode: Remote
- Location: Offshore
- Total Experience Required: 4 to 8 years
- Relevant Experience Required: 3+ years of dedicated implementation and configuration experience across ServiceNow Security Operations (SecOps) modules
- Mandatory Certification: ServiceNow Certified Implementation Specialist – Security Incident Response (CIS-SIR) or Vulnerability Response (CIS-VR)
Job Summary
We are seeking an experienced ServiceNow SecOps Specialist to bridge the gap between enterprise security tools and automated workflow orchestration. The ideal candidate will design, configure, and optimize Security Incident Response (SIR) and Vulnerability Response (VR) modules, building robust ingestion pipelines that ingest security threat telemetry into actionable, prioritized, and automated remediation workflows.
Key Responsibilities
- Configure and manage core ServiceNow SecOps modules, focusing on Security Incident Response (SIR), Vulnerability Response (VR), and Threat Intelligence integration.
- Design automated ingestion pipelines via Integration Hub, connecting ServiceNow with external SIEMs (e.g., Splunk, Sentinel), EDRs (e.g., CrowdStrike), and vulnerability scanners (e.g., Tenable, Qualys).
- Build complex security orchestration and playbooks within Flow Designer to automate initial validation containment tasks, asset lookups, and owner assignments.
- Implement Vulnerability Assignment Rules and Calculator Groups, prioritizing vulnerabilities dynamically using corporate asset criticality ratings and CVSS threat matrices.
- Establish strict data confidentiality controls, managing Access Control Lists (ACLs), read-permissions, and data isolation barriers to keep sensitive breach investigations restricted to authorized teams.
- Govern Configuration Item (CI) reconciliation matches, collaborating with CMDB data stewards to ensure incoming security event data maps correctly to existing infrastructure assets.
- Support end-to-end user acceptance testing (UAT), creating target test failure patterns, verifying playbook action workflows, and delivering analyst enablement training workshops.
Requirements
- 4 to 8 years of core enterprise IT or cybersecurity experience, with 3+ dedicated years actively designing, building, and maintaining configurations within the ServiceNow SecOps application suite.
- Strong technical mastery of JavaScript scripting, Flow Designer parameters, ServiceNow Glide API frameworks, JSON parsing structures, and REST/SOAP endpoint mappings.
- Deep structural understanding of cybersecurity incident response phases (NIST/SANS), the MITRE ATT&CK framework, common infrastructure vulnerability vectors, and CMDB hierarchy frameworks.
- Mandatory certification: ServiceNow CIS-SIR or CIS-VR.
Preferred Qualifications
- CompTIA Security+, CEH (Certified Ethical Hacker), or GCIH (GIAC Certified Incident Handler) designation.
- Prior experience implementing ServiceNow Major Security Incident Management (MSIM) frameworks or handling multi-tenant domain separation configurations.