Role - ServiceNow Security Operations (SecOps) Consultant/Architect
Location North Carolina, US (Remote work is also fine, but the candidate must be able to go to the office when required)
Security Operations Role Overview
The ServiceNow Security Operations (SecOps) Consultant/Architect is responsible for designing, implementing, and optimizing security response workflows on the ServiceNow platform. The role focuses on Security Incident Response (SIR), Vulnerability Response (VR), and Threat Intelligence, enabling organizations to detect, prioritize, and remediate security threats faster through automation and collaboration between Security and IT teams.
ServiceNow SecOps acts as a system of action that bridges cybersecurity tools and IT remediation workflows.
Key Responsibilities
- Design and implement ServiceNow Security Operations (SecOps) solutions using out-of-the-box best practices
Configure and optimize core SecOps capabilities: Security Incident Response (SIR)
Vulnerability Response (VR)
Threat Intelligence
Integrate ServiceNow with SIEM, SOAR, vulnerability scanners, and threat intelligence feeds to enable end-to-end security workflows
Automate alert triage, enrichment, prioritization, and remediation across security and IT teams
Enable risk-based prioritization by leveraging CMDB context and business impact
Build security dashboards, KPIs, and executive reporting for incident trends, vulnerability posture, and response effectiveness
Collaborate with SOC, IT, Risk, and Compliance teams to align security operations with enterprise processes
Participate in pre-sales, solution workshops, and architecture discussions when required
Required Skills & Experience
- Strong hands-on experience with ServiceNow Security Operations (SecOps)
Solid understanding of: Security incident management
Vulnerability management lifecycle
Threat intelligence and SOC operations
Experience integrating ServiceNow with security tools (SIEM, scanners, identity platforms)
Proficiency in ServiceNow configuration and scripting (Flow Designer, Business Rules, Script Includes, Reporting)
Strong stakeholder engagement skills across Security, IT, and Risk teams
Certifications (Preferred)
- ServiceNow CSA (Certified System Administrator) Must
- CIS Security Incident Response (CIS-SIR)
- CIS Vulnerability Response (CIS-VR)
- Security certifications (ITIL, CISSP, CISM preferred)
- CTA / CMA for senior architect roles