19 Aug
|
LogFix SCM Solutions
|
Pune
19 Aug
LogFix SCM Solutions
Pune
ServiceNow Vulnerability Response (VR) Engineer
Experience: 5-6 Years
Relevant ServiceNow Experience: 4+ Years in ServiceNow Security Operations / SecOps
Contract: 3 Months, Extendable
Location: Remote — Candidates from Chennai, Bangalore, or Pune preferred
Communication: Excellent verbal and written communication skills required
Position Summary
We are looking for an experienced ServiceNow Vulnerability Response (VR) Engineer to implement, configure, integrate, and support ServiceNow Vulnerability Response solutions in an enterprise environment.
The candidate will be responsible for managing the end-to-end vulnerability lifecycle, developing remediation workflows, integrating ServiceNow with enterprise security tools, and improving risk-based vulnerability prioritization.
The role requires strong knowledge of *ServiceNow SecOps and Vulnerability Response, along with a good functional understanding of **ITOM, CMDB, Discovery, Service Mapping, configuration management, and asset lifecycle management*.
The ideal candidate should be capable of connecting vulnerability findings with accurate infrastructure and business-service context to enable effective, risk-based remediation.
Key Responsibilities
ServiceNow Vulnerability Response
- Configure and maintain ServiceNow Vulnerability Response applications and modules.
Configure vulnerability groups, assignment rules, remediation targets, and workflows.
Develop and maintain remediation workflows using Flow Designer and ServiceNow workflow capabilities.
Configure and optimize vulnerability risk scoring and prioritization models.
Manage vulnerability findings, remediation tasks, exceptions, and remediation status.
Support vulnerability identification, analysis, prioritization, assignment, and closure.
Ensure vulnerability remediation processes align with organizational security policies and SLAs.
Vulnerability Management & Security Operations
Manage the complete vulnerability lifecycle from detection through remediation and closure.
Analyze vulnerability findings and prioritize remediation based on risk, severity, asset criticality, and business impact.
Work closely with security, infrastructure, application, and operations teams to drive remediation.
Track remediation progress and identify aging or SLA-breaching vulnerabilities.
Support root-cause analysis for vulnerability-related operational issues.
Assist in improving vulnerability management processes and operational efficiency.
Prepare vulnerability metrics, KPI dashboards, SLA reports,
and compliance reports.
ITOM, CMDB & Asset Context
Leverage CMDB information to improve vulnerability prioritization and remediation decisions.
Understand relationships between Configuration Items (CIs), applications, infrastructure components, and business services.
Work with CMDB and Discovery teams to ensure accurate asset information.
Validate CI relationships and service dependencies used for vulnerability analysis.
Ensure vulnerability findings are correctly correlated with discovered assets and CIs.
Support business-service-aware vulnerability remediation.
Collaborate with ITOM teams to improve asset visibility and data quality.
ServiceNow ITOM Knowledge The candidate should have a strong functional understanding of:
CMDB
Discovery
Service Mapping
Configuration Management
Asset Management / Asset Lifecycle
Event Management — preferred
CI relationships and dependency mapping
Business services and service dependencies The candidate should understand how security findings and vulnerabilities relate to infrastructure assets, applications, Configuration Items, and business services.
Security Tool Integrations
Hands-on experience integrating ServiceNow Vulnerability Response with security and vulnerability management platforms is required.
Preferred integration experience includes:
- Qualys
- Tenable
- Rapid7
- Microsoft Defender
- CrowdStrike
The candidate should understand vulnerability data ingestion, mapping/correlation, CI identification, synchronization, remediation task creation, and status updates between ServiceNow and external security tools. Collaboration The engineer will work closely with:
- Security Operations / Cybersecurity Teams
- Vulnerability Management Teams
- CMDB Teams
- ServiceNow Platform Teams
- Discovery / ITOM Teams
- Infrastructure Operations
- Network Teams
- Application Support Teams
- Compliance and Risk Teams
Operational Responsibilities
- Provide production support for ServiceNow Vulnerability Response.
- Troubleshoot incidents related to vulnerability integrations, workflows, data synchronization, and remediation processes.
- Perform root-cause analysis and implement corrective actions.
- Monitor vulnerability processing and remediation SLAs.
- Identify opportunities for automation and process optimization.
- Support operational reporting and security governance activities.
- Participate in enhancement and continuous-improvement initiatives.
Mandatory Technical Skills
- ServiceNow SecOps
- ServiceNow Vulnerability Response
- ServiceNow Security Operations / SecOps
- Vulnerability lifecycle management
- Vulnerability remediation
- Vulnerability groups
- Assignment rules
- Risk scoring
- Remediation workflows
- Flow Designer
- ServiceNow configuration and administration
Vulnerability Management
- Vulnerability assessment and prioritization
- CVSS
- Risk assessment
- Vulnerability remediation processes
- Security operations processes
- SLA-based remediation
Integration Experience Hands-on experience with one or more of the following:
- Qualys
- Tenable
- Rapid7
- Microsoft Defender
- CrowdStrike
Preferred Skills
- ServiceNow Security Incident Response (SIR)
- Threat Intelligence
- GRC
- ITOM
- CMDB
- Discovery
- Service Mapping
- Event Management
- ITIL processes
Certifications
Mandatory:
ServiceNow Certified System Administrator (CSA)
Preferred:
- ServiceNow Certified Implementation Specialist - Vulnerability Response (CIS-VR)
- CompTIA Security+
- ITIL Foundation
Candidate Profile 5-6 years of overall IT experience.
Minimum 3+ years of hands-on ServiceNow SecOps experience.
- Strong hands-on experience with ServiceNow Vulnerability Response.
Good understanding of enterprise vulnerability management processes.
Strong understanding of CMDB, Discovery, Service Mapping, and asset relationships.
Experience working with vulnerability/security tool integrations.
Strong analytical and troubleshooting skills.
Ability to work independently in a remote workplace.
Excellent verbal and written communication skills.
Strong stakeholder management and collaboration skills.
Key Requirements at a Glance
Must Have:
ServiceNow Vulnerability Response
ServiceNow SecOps
Vulnerability Management
Flow Designer / Workflow Configuration
CVSS & Risk Assessment
Qualys / Tenable / Rapid7 integration experience
CMDB knowledge
ITOM understanding
CSA certification
Excellent communication skills
Good to Have:
ServiceNow SIR
Threat Intelligence
GRC
Discovery
Service Mapping
Event Management
CIS-Vulnerability Response
Security+
ITIL Foundation
📌 ServiceNow Vulnerability Response (VR) Engineer (Pune)
🏢 LogFix SCM Solutions
📍 Pune