ServiceNow SecOps Architect
Tata Consultancy Services · Phoenix, AZ · 1 wk ago
Art & Creative$130k–$180k/yrFull-time
About the Role
We are seeking a ServiceNow SecOps Architect with deep expertise in Security Incident Response (SIR) and Vulnerability Response (VR) to lead the design, configuration, and customization of the ServiceNow SecOps modules.
Responsibilities
- Lead end-to-end architecture for ServiceNow SecOps SIR & VR, including data model, scopes, and modular design aligned to platform guardrails and performance best practices.
- Define SecOps governance standards and design patterns.
- Design and develop workflows, business rules, client scripts, and integrations supporting the SIR & VR lifecycle.
- Define prioritization models and Risk Score formulas to drive actionable SLAs and dashboards.
- Design and develop robust CMDB relationships to tie vulnerabilities to assets, services, and business applications (CIs), enabling service-aware remediation and reporting.
- Enable bi-directional integration between SIR and ITSM.
- Integrate enterprise vulnerability scanners (e.g., Tenable, Qualys, Rapid7) and threat intel feeds; tune parsing, de-duplication, and matching logic.
- Optimize Vulnerability Item (VI) normalization, de-duplication, suppression, false positive handling, and asset-vuln correlation at scale.
- Implement exception workflows (risk acceptance, compensating controls, deferrals) with risk justification and approvals.
- Build executive and operational dashboards (exposure by service, asset tier, business unit, critical vulnerabilities, SLA breach, MTTR).
- Establish multi-environment strategies (DEV/TEST/PROD), ATF coverage, upgrade readiness, and platform governance.
- Configure MID Servers, data sources, and API connections for vulnerability data ingestion.
- Create custom dashboards, reports, and Performance Analytics indicators for vulnerability KPIs and trends.
- Work with business stakeholders, technical stakeholders, onsite, and offshore teams to own the delivery of work.
Requirements
- 12+ years of hands-on development experience in the ServiceNow platform.
- 5+ years of experience specifically in Security Incident Response (SIR) and Vulnerability Response (VR) implementation.
- Strong understanding of SOC operations & Incident response frameworks (NIST, SANS).
- Experience working with SIEM, SOAR, EDR, and vulnerability tools.
- Strong understanding of ServiceNow CMDB, Discovery, and ITSM processes.
- Experience integrating with vulnerability scanners (Qualys, Tenable, Rapid7, Prisma Cloud, etc.).
- Knowledge of JavaScript, Glide API, Flow Designer, and REST/SOAP integrations.
Qualifications
- ServiceNow Certified Technical Architect (CTA).
- Certified Implementation Specialist – Security Incident Response (CIS-SIR).
Pay
$130,000 - $180,000 a year