
Vulnerability Management Engineer – ServiceNow
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Design, configure, and provide support for ServiceNow Vulnerability Response to oversee the complete vulnerability lifecycle.
• Create and sustain remediation workflows, vulnerability groups, assignment rules, and calculators utilizing Flow Designer, Business Rules, and other ServiceNow technologies.
• Set up risk scoring and prioritization models based on CVSS, threat intelligence, exploitability, and the criticality of business/assets.
• Develop custom automation and workflows employing JavaScript, HTML/CSS, Python, and ServiceNow functionalities.
• Configure and manage ServiceNow Security Operations, encompassing Vulnerability Response and, as applicable, Security Incident Response and Configuration Compliance.
• Oversee vulnerability intake, correlation, prioritization, remediation tracking, verification, and reporting.
• Perform vulnerability analysis and prioritization while collaborating on remediation efforts with client infrastructure, security, and application teams.
• Design and maintain dashboards, KPIs, and SLA monitoring for ServiceNow Security Operations.
• Set up and manage vulnerability scanning and security tool integrations through APIs.
• Integrate threat intelligence and asset data sources into ServiceNow.
• Automate reporting, ticketing, notifications, and remediation tracking.
• Troubleshoot and enhance integrations, data imports, and scheduled jobs.
• Utilize CMDB, Discovery, and Service Mapping for asset intelligence and business-service context.
• Validate Configuration Item relationships and service dependencies.
• Enhance vulnerability-to-CI correlation and asset criticality ratings.
• Support exposure management initiatives that extend beyond conventional CVEs.
• Provide operational support, incident assistance, root cause analysis, and process optimization.
• Assist with SLA monitoring, risk management, and compliance reporting.
• Contribute to documentation, operational playbooks, and knowledge articles.
• Stay updated on ServiceNow Security Operations, Vulnerability Response, and exposure management trends and technologies.
• Deliver focused support to clients and/or internal customers, aiming to provide exceptional service.
• A minimum of 1–2+ years of experience in ServiceNow Security Operations and CMDB implementation and integration.
• Practical experience in configuring ServiceNow Vulnerability Response (VR) and Security Operations, including Flow Designer and workflow setup.
• Experience in integrating vulnerability scanners and security tools such as Qualys, Tenable, Rapid7, Microsoft Defender, and CrowdStrike with ServiceNow via APIs.
• Familiarity with vulnerability management principles, including CVSS, risk assessment, exploitability, and SLA-driven remediation.
• Understanding of ITOM concepts, including CMDB, Discovery, and Service Mapping, and their role in driving risk-based prioritization.
• Proficient programming skills in Python, JavaScript, HTML/CSS, and other ServiceNow technologies.
• Capacity to adapt to emerging technologies, including AI tools.
• Basic knowledge of vulnerability management and security operations processes and procedures.
• Experience with exposure management/risk-based vulnerability management (RBVM) and prioritization based on business impact.
• Familiarity with threat intelligence enrichment and Security Incident Response (SIR) workflows.
• Experience in creating executive-ready dashboards, KPIs, and SLA/compliance reports in ServiceNow.
• Strong analytical and problem-solving abilities.
• Excellent communication, documentation, and collaboration skills.
• Certification in one or more of the following: ServiceNow Certified System Administrator, ServiceNow Certified Application Developer, or ServiceNow Certified Application Specialist.
• ServiceNow Certified Implementation Specialist certification in one or more of the following areas: Risk and Compliance, Vendor Risk Management (VRM), Security Incident Response (SIR), or Vulnerability Response (VR).
• Ability to perform sedentary work.
• Significant movement of the wrists, hands, and/or fingers for at least 8 hours a day.
• Close visual acuity for viewing computer terminals and/or extensive reading for a minimum of 8 hours a day.
• Primarily remote workforce (U.S. based only).
• Group Medical Insurance options: Zero Deductible PPO Plan; GuidePoint covers 90% of the premium for employees and 70% for family plans.
• High Deductible Health Plan with HSA; GuidePoint pays 100% of employees’ premiums and 75% for family plans.
• HSA contribution of $850 per employee annually or $1750 per family annually.
• Group Dental Insurance; GuidePoint covers 100% of the premium for employees and 75% for family plans.
• 12 corporate holidays.
• Flexible Time Off (FTO) program.
• Healthy mobile phone allowance.
• Home internet allowance.
• Eligibility for retirement plan after 2 months at open enrollment.
• Pet Benefit Option.
• Up to 10% travel.
Guidehouse
Aoop Cloud Solutions
AAA
Guidehouse
Get handpicked remote jobs straight to your inbox weekly.