ServiceNow Developer (Vulnerability Operations Automation)

Harvey Nash
Charlotte, NC, United States
17 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Starter
Experience required
5 years minimum
Compensation
$118,560.0 - $124,800.0
Working hours
Regular working hours

Tech stack

Clean Code Principles JavaScript (Programming Language) Application Programming Interfaces (APIs) Cloud Computing Configuration Management Databases Software Documentation Cyber Security Custom Software Data Deduplication JSON Release Management ServiceNow Application Engine
+11 more
Software Vulnerability Management Extensible Markup Language (XML) Client Side Scripting Facebook Flow SOAPAPI Patch Management Restful APIs Prisma Cloud Platform Qualys Servicenow Vulnerability Analysis

Job description

We are seeking an experienced ServiceNow (SNOW) Developer to support the Vulnerability Operations Automation project from the Charlotte office. The role will focus on designing, developing, and maintaining automated workflows in ServiceNow to improve vulnerability intake, triage, assignment, remediation tracking, SLA monitoring, dashboards, and audit-ready reporting. Key Responsibilities

  • Design, develop, test, and maintain ServiceNow applications, workflows, and custom modules supporting vulnerability operations.

  • Configure and enhance ServiceNow Vulnerability Response, ITSM, CMDB, Flow Designer, Integration Hub, Business Rules, Script Includes, Client Scripts, UI Policies, and Scheduled Jobs.

  • Automate vulnerability assignment, remediation tracking, escalation, closure validation, and exception handling processes.

  • Build dashboards, reports, and metrics to provide visibility into vulnerability backlog, remediation SLA performance, aging, risk exposure, and operational trends.

  • Partner with Cybersecurity, Infrastructure, Application, Cloud, and Operations teams to streamline vulnerability management and remediation governance.

  • Support platform upgrades, release management, defect fixes, production support, documentation, and ServiceNow development best practices.

Integration & Automation Scope

  • Integrate ServiceNow with vulnerability scanning, security, asset, and remediation systems using REST/SOAP APIs, MID Server, Integration Hub, imports, and scheduled synchronizations.

  • Support ingestion, normalization, deduplication, enrichment, and correlation of vulnerability data against CMDB and asset ownership information.

  • Create reusable automation patterns for notification, escalation, SLA breach prevention, remediation evidence capture, and closure workflows.

  • Work with tools such as Tenable, Qualys, Rapid7, Microsoft Defender, Prisma Cloud, or similar vulnerability/security platforms where applicable.

Requirements

  • 5+ years of hands-on ServiceNow development experience in enterprise environments.

  • Strong experience with ServiceNow ITSM, CMDB, Flow Designer, Integration Hub, Service Catalog, reports, dashboards, and custom application development.

  • Experience with ServiceNow Vulnerability Response or Security Operations is strongly preferred.

  • Proficiency in JavaScript, Glide APIs, REST APIs, SOAP web services, JSON, XML, and data integration patterns.

  • Understanding of vulnerability management lifecycle, CVSS scoring, risk-based prioritization, remediation SLAs, patch management, and exception workflows.

  • Ability to write clean, maintainable code and follow ServiceNow development, testing, deployment, and documentation standards.

  • Strong analytical, troubleshooting, communication, and stakeholder management skills.

Preferred / Nice-to-Have Skills

  • Service Now Developer

  • Security+ or other cybersecurity certification exposure.

  • Experience in banking, financial services, healthcare, or other regulated environments.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

2:03 min

Distinguishing type definition constructs from data validation routines

Clemens Vasters Clemens Vasters · WWC 2025

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

4:58 min

Scaling security teams through developer advocates

Tanya Janca · WWC 2021

1:03 min

Understanding the complexity and traps of JSON schema

Clemens Vasters Clemens Vasters · WWC 2025

Videos

See all

Related articles

See all