Requirements :
1. ServiceNow certifications: CSA (Certified System Administrator;
2. CIS-VR (Vulnerability Response), ), or CIS-SecOps
3. OT Discovery and OT VM Certifications
Job Description/ Responsibilities :
Integration Architecture & Development
* Design and build bi-directional integrations between ServiceNow and Tanium, Maximo, Forescout, and Qualys using REST/SOAP APIs, MID Servers, IntegrationHub spokes, and custom scripted APIs.
* Ensure data integrity and synchronization for asset, configuration, and vulnerability data flowing between ServiceNow CMDB/CSDM and source systems.
* Build and maintain integration error handling, retry logic, logging, and monitoring/alerting for all connected systems.
* Map and normalize data schemas across platforms (e.g., Qualys QID to ServiceNow Vulnerable Item, Forescout device classification to CMDB CI, Tanium asset/patch data to CI attributes, Maximo asset/work order data to OT asset records).
Vulnerability Management Process Automation
* Architect and automate the full vulnerability management lifecycle in ServiceNow: ingestion → asset/CI correlation → risk scoring/prioritization → assignment → remediation workflow → verification → closure.
* Build ServiceNow Flow Designer/Workflow automations to orchestrate remediation tasks, approvals, exception/risk-acceptance processes, and SLA-based escalations.
* Configure automated ticketing and work order creation in Maximo for OT asset remediation, tied back to ServiceNow vulnerability records.
* Implement automated network segmentation/containment triggers leveraging Forescout for high-risk or unpatchable OT assets.
* Build logic to reconcile Tanium patch/configuration data with Qualys scan results to reduce false positives and validate remediation.
Documentation & Audit Trail
* Configure ServiceNow to automatically document all actions taken (system and human) across the vulnerability lifecycle — including timestamps, source system, decision rationale, approvals, and remediation evidence — to support audit, compliance, and regulatory reporting (e.g., IEC 62443, NIST 800-82).
* Build reporting dashboards and performance analytics (MTTR, SLA compliance, risk exposure trends) using ServiceNow Performance Analytics/Reporting.
* Maintain integration and workflow documentation, runbooks, and data flow diagrams.
OT-Specific Considerations
* Apply OT-appropriate remediation strategies (compensating controls, segmentation, virtual patching) when direct patching is not feasible due to safety, uptime, or vendor constraints.
* Partner with OT engineering and plant/site teams to validate that automated actions do not disrupt production or safety systems.
* Maintain a unified IT/OT asset and vulnerability inventory within the ServiceNow CMDB/CSDM.
Collaboration & Governance
* Work with Security Operations, IT, OT Engineering, and Compliance teams to define workflow requirements, escalation paths, and risk acceptance criteria.
* Support change management and testing (dev/test/prod) for all integration and workflow changes.
* Provide subject matter expertise on ServiceNow Vulnerability Response and OT Security module capabilities and roadmap.
Required Qualifications
* 4+ years of experience administering or engineering on the ServiceNow platform, including: Vulnerability Response (VR) and/or OT/IoT Security modules; Flow Designer / Workflow Editor; IntegrationHub, REST/SOAP Message integrations, MID Server configuration; CMDB/CSDM data modeling.
* Demonstrated experience building two-way integrations with two or more of the following: Tanium, Qualys, Forescout, Maximo (or comparable CMMS/EAM).
* Solid understanding of vulnerability management lifecycle concepts: scanning, risk scoring (CVSS/VPR), prioritization, remediation SLAs, and exception management.
* Working knowledge of OT/ICS/SCADA environments and the operational constraints that differentiate OT vulnerability management from traditional IT patching.
* Experience with JavaScript (Glide API, Scripted REST APIs, Business Rules) for custom ServiceNow development.
* Strong understanding of API authentication methods (OAuth2, mutual TLS, API keys) and secure integration design.
* Excellent documentation skills and ability to translate technical workflows into audit-ready records.