> Markdown version of [/jobs/ext/1683818-servicenow-developer-vulnerability-operations-automation](https://www.wearedevelopers.com/jobs/ext/1683818-servicenow-developer-vulnerability-operations-automation). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ServiceNow Developer (Vulnerability Operations Automation) - **Company:** Harvey Nash - **Location:** Charlotte, NC, United States - **Experience:** Starter - **Salary:** $118,560.0 - $124,800.0 - **Contract:** Permanent contract - **Skills:** Clean Code Principles, JavaScript (Programming Language), Application Programming Interfaces (APIs), Cloud Computing, Configuration Management Databases, Software Documentation, Cyber Security, Custom Software, Data Deduplication, JSON, Release Management, ServiceNow Application Engine, Software Vulnerability Management, Extensible Markup Language (XML), Client Side Scripting, Facebook Flow, SOAPAPI, Patch Management, Restful APIs, Prisma Cloud Platform, Qualys, Servicenow, Vulnerability Analysis - **Published:** July 27, 2026 - **Apply:** https://www.careerjet.com/jobad/us9228d67f2bbc41c736ee56d5a9e2d761 ## About the Role * 5+ years of hands-on ServiceNow development experience in enterprise environments. * Strong experience with ServiceNow ITSM, CMDB, Flow Designer, Integration Hub, Service Catalog, reports, dashboards, and custom application development. * Experience with ServiceNow Vulnerability Response or Security Operations is strongly preferred. * Proficiency in JavaScript, Glide APIs, REST APIs, SOAP web services, JSON, XML, and data integration patterns. * Understanding of vulnerability management lifecycle, CVSS scoring, risk-based prioritization, remediation SLAs, patch management, and exception workflows. * Ability to write clean, maintainable code and follow ServiceNow development, testing, deployment, and documentation standards. * Strong analytical, troubleshooting, communication, and stakeholder management skills. Preferred / Nice-to-Have Skills * Service Now Developer * Security+ or other cybersecurity certification exposure. * Experience in banking, financial services, healthcare, or other regulated environments. ## Description We are seeking an experienced ServiceNow (SNOW) Developer to support the Vulnerability Operations Automation project from the Charlotte office. The role will focus on designing, developing, and maintaining automated workflows in ServiceNow to improve vulnerability intake, triage, assignment, remediation tracking, SLA monitoring, dashboards, and audit-ready reporting. Key Responsibilities * Design, develop, test, and maintain ServiceNow applications, workflows, and custom modules supporting vulnerability operations. * Configure and enhance ServiceNow Vulnerability Response, ITSM, CMDB, Flow Designer, Integration Hub, Business Rules, Script Includes, Client Scripts, UI Policies, and Scheduled Jobs. * Automate vulnerability assignment, remediation tracking, escalation, closure validation, and exception handling processes. * Build dashboards, reports, and metrics to provide visibility into vulnerability backlog, remediation SLA performance, aging, risk exposure, and operational trends. * Partner with Cybersecurity, Infrastructure, Application, Cloud, and Operations teams to streamline vulnerability management and remediation governance. * Support platform upgrades, release management, defect fixes, production support, documentation, and ServiceNow development best practices. Integration & Automation Scope * Integrate ServiceNow with vulnerability scanning, security, asset, and remediation systems using REST/SOAP APIs, MID Server, Integration Hub, imports, and scheduled synchronizations. * Support ingestion, normalization, deduplication, enrichment, and correlation of vulnerability data against CMDB and asset ownership information. * Create reusable automation patterns for notification, escalation, SLA breach prevention, remediation evidence capture, and closure workflows. * Work with tools such as Tenable, Qualys, Rapid7, Microsoft Defender, Prisma Cloud, or similar vulnerability/security platforms where applicable. ## Related Videos - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Introducing JSON Structure](https://www.wearedevelopers.com/videos/100219-introducing-json-structure) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) - [Navigating the Corporate Jungle: Life as a Developer in a large Company](https://www.wearedevelopers.com/videos/621-navigating-the-corporate-jungle-life-as-a-developer-in-a-large-company) - [JSON and Beyond](https://www.wearedevelopers.com/videos/968-json-and-beyond) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)