Job Title: ServiceNow SecOps Architect Location: Phoenix, Az - 4 days hybrid Employment Type: Full Time Experience Required 12 Years
Must Have Technical/Functional Skills
12+ years of hands-on development experience in ServiceNow platform.
5+ years of experience specifically in Security Incident Response (SIR) and Vulnerability Response (VR) implementation.
Design, configure and customize ServiceNow SIR & VR module
Design and develop workflows, business rules, client scripts, and integrations supporting the SIR & VR lifecycle.
Integrate VR with external vulnerability scanners and CMDB (Configuration Management Database) to automate import and correlation of vulnerability data.
Configure MID Servers, data sources, and API connections for vulnerability data ingestion.
Design and develop automation for vulnerability assignment, remediation tracking, and exception management.
Create custom dashboards, reports, and Performance Analytics indicators for vulnerability KPIs and trends.
Lead end-to-end architecture for ServiceNow SecOps SIR & VR, including data model, scopes, and modular design aligned to platform guardrails and performance best practices.
Define SecOps governance standards and design patterns
Define prioritization models and Risk Score formulas to drive actionable SLAs and dashboards.
Design and develop robust CMDB relationships to tie vulnerabilities to assets, services, and business applications (CIs), enabling service-aware remediation and reporting.
Enable bi directional integration between SIR and ITSM.
Integrate enterprise vulnerability scanners (e.g., Tenable, Qualys, Rapid7) and threat Client feeds; tune parsing, de-duplication, and matching logic.
Optimize Vulnerability Item (VI) normalization, de-duplication, suppression, false positive handling, and asset-vuln correlation at scale.
Implement exception workflows (risk acceptance, compensating controls, deferrals) with risk justification and approvals.
Build executive and operational dashboards (exposure by service, asset tier, business unit, critical vulnerabilities, SLA breach, MTTR).