04 Sep
|
4AT CONSULTING
|
Hyderabad
04 Sep
4AT CONSULTING
Hyderabad
Role: ServiceNow Security Operations (SecOps) and Vulnerability Response Management (VRM) Developer
Contractor role Location: Bangalore / Hybrid / Remote
Experience: 5 – 8 Years
No of positions : 2
Contract - 3 to 6 months (Full time)
Shift is mandatory (2:30 PM – 11:30 PM IST).
Pay - upto 1200 to 1500 hourly
Summary of Role
ServiceNow Security Operations (SecOps) and Vulnerability Response Management (VRM) Developer to design, configure, develop, integrate, and support ServiceNow Security Operations capabilities across Security Incident Response (SIR), Vulnerability Response / VRM, Threat Intelligence, workflow automation, and security platform integrations. This role will focus on building scalable ServiceNow SecOps solutions that help security teams ingest alerts, enrich incidents, prioritize vulnerabilities, automate workflows, coordinate remediation, and improve operational visibility. The ideal candidate is a hands-on ServiceNow developer with deep experience in SecOps and VRM, strong platform development skills, and proven integration experience with SOAR tools, EDR platforms, vulnerability scanners, threat intelligence sources, SIEM/security analytics platforms, and cybersecurity tools.
A key requirement for this role is experience integrating ServiceNow with CrowdStrike, Wiz, and ProofPoint including CrowdStrike Falcon-related use cases such as endpoint context, incident enrichment, threat intelligence, vulnerability/exposure data, and response actions
Key Responsibilities
- Design, configure, develop, and maintain ServiceNow Security Operations capabilities with a primary focus on Security Incident Response (SIR) and Vulnerability Response Management (VRM).
- Configure and enhance ServiceNow SIR workflows for security incident intake, triage, investigation, containment, remediation, closure, post-incident review, and reporting.
- Configure and enhance ServiceNow VRM / Vulnerability Response workflows for vulnerability ingestion, vulnerable item creation, risk scoring, assignment, remediation tracking, exception handling, false positive handling, and closure.
- Develop and maintain integrations between ServiceNow SecOps/VRM and external cybersecurity platforms, including CrowdStrike, SOAR platforms, SIEM tools, EDR platforms, vulnerability scanners, threat intelligence platforms, cloud security tools, and email security tools.
- Implement and support CrowdStrike integrations for use cases such as endpoint enrichment, detection/alert intake, host context, threat intelligence indicators, host isolation or response actions where approved, vulnerability/exposure ingestion, and CMDB/asset enrichment.
- Build integration patterns using REST/SOAP APIs, IntegrationHub, Flow Designer / Workflow Studio, Import Sets, Transform Maps, Scripted REST APIs, webhooks, MID Server where applicable, OAuth 2.0, service accounts, API keys, and secure credential management.
- Configure ServiceNow SecOps automation using Flow Designer, Playbooks, Runbooks, Process Automation Designer, business rules,
assignment rules, escalation rules, notifications, SLAs, and approval workflows.
- Develop custom ServiceNow logic using JavaScript, Glide APIs, Script Includes, Business Rules, Client Scripts, UI Policies, UI Actions, Scheduled Jobs, ACLs, and scoped application development patterns.
- Configure Security Incident Response and Vulnerability Response workspaces, forms, lists, related records, dashboards, reports, and analyst views to improve usability and operational efficiency.
- Support threat intelligence use cases including IoC ingestion, enrichment, observable handling, MITRE ATT&CK; context, and correlation with incidents or vulnerabilities.
- Collaborate with security architects and process owners to align ServiceNow workflows with incident response playbooks, vulnerability management processes, escalation paths, operating model, and service levels.
- Support CMDB/CSDM alignment for security and vulnerability workflows, including CI matching, asset context, service ownership, business criticality, and routing logic.
- Develop and execute unit testing, integration testing, regression testing, UAT support, deployment validation, and post-production troubleshooting.
- Prepare technical documentation, configuration guides, integration runbooks, release notes, support documentation, and knowledge transfer materials.
- Monitor integration health, troubleshoot data ingestion failures, resolve mapping issues, optimize performance, and improve reliability of SecOps data flows.
- Participate in Agile delivery ceremonies, sprint planning, requirements refinement, solution design sessions, code reviews, release planning, and production readiness reviews.
- Maintain solutions in alignment with ServiceNow platform development best practices, security standards, governance requirements, upgradeability, and maintainability.
Required Qualifications 5+ years of ServiceNow platform development, administration, or implementation experience, including hands-on configuration and customization.
- 3+ years of experience with ServiceNow Security Operations, especially Security Incident Response (SIR) and Vulnerability Response / Vulnerability Response Management (VRM).
- Experience delivering at least two ServiceNow SecOps, SIR, VR, or related cybersecurity workflow implementations in enterprise environments.
- Robust hands-on experience configuring ServiceNow SIR and VRM capabilities, including workflows, forms, workspaces, roles, assignment rules, risk scoring, SLAs, dashboards, reports, and remediation processes.
- Experience integrating ServiceNow with third-party cybersecurity tools,
including CrowdStrike and at least one or more of the following categories:
- SOAR/orchestration platforms
- EDR/XDR platforms
- SIEM/security analytics platforms
- Vulnerability scanners
- Threat intelligence platforms
- Cloud security posture or exposure management tools
- Email security or phishing response tools
- Strong ServiceNow development skills using JavaScript, GlideRecord, GlideAjax, Script Includes, Business Rules, Client Scripts, UI Policies, UI Actions, Scheduled Jobs, ACLs, and scoped application development.
- Hands-on integration experience with REST APIs, SOAP APIs, JSON/XML payloads, OAuth 2.0, API keys, service accounts, MID Server, IntegrationHub, Flow Designer, Import Sets, Transform Maps, and error handling.
- Working knowledge of security operations concepts, including incident response, vulnerability management, threat intelligence, endpoint security, phishing response, malware response, threat enrichment, and remediation workflows.
- Familiarity with vulnerability management concepts such as CVE, CVSS, NVD, exploitability, asset criticality, risk-based prioritization, remediation tasks, exceptions, and false positives.
- Familiarity with SOC and incident response frameworks such as NIST, SANS, MITRE ATT&CK;, or equivalent security operations practices.
- Experience with CMDB/CSDM concepts, CI matching, asset ownership, business service context, and how CMDB data supports SecOps prioritization and routing.
- Ability to troubleshoot integration failures, data quality issues, role/permission problems, workflow defects, and platform performance issues.
- Strong documentation, communication, and stakeholder collaboration skills.
Required Technical Skills
- ServiceNow Security Operations: SIR, VRM / Vulnerability Response, Threat Intelligence, SecOps workspaces, playbooks, dashboards, reports, and Security Operations integrations.
- ServiceNow development: JavaScript, Glide APIs, Script Includes, Business Rules, Client Scripts, UI Policies, UI Actions, ACLs, Scheduled Jobs, scoped applications, and platform configuration.
- Workflow automation: Flow Designer, Workflow Studio, IntegrationHub, Playbooks, Runbooks, Process Automation Designer, approvals, notifications, SLAs, and assignment logic.
- Integration development: REST, SOAP, JSON, XML, OAuth 2.0, API keys, service accounts, MID Server, webhooks, Import Sets, Transform Maps, Scripted REST APIs, integration monitoring, and retry/failure handling.
- Cybersecurity platforms: CrowdStrike, SOAR platforms, SIEM/security analytics, EDR/XDR, vulnerability scanners, threat intelligence, email security, cloud security, and exposure management tools.
- Data and platform foundations: CMDB, CSDM, CI lookup rules, asset context, business service context, RBAC, audit logging, reporting, and data quality controls.
- Delivery practices: requirements analysis, solution design, technical documentation, test planning, UAT, release readiness, defect remediation, and production support.
📌 ServiceNow (SecOps) and (VRM) Developer
🏢 4AT CONSULTING
📍 Hyderabad