ServiceNow OT Security / Vulnerability Response Solution Architect

ICONMA LLC
Glide, OR, United States
8 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
0 years minimum
Working hours
Regular working hours

Tech stack

JavaScript (Programming Language) Application Programming Interfaces (APIs) Application Integration Architecture Audit Trail Configuration Management Databases Computerized Maintenance Management Systems Cyber Security Data Integrity Supervisory Control and Data Acquisition (SCADA) IBM Maximo Network Segmentation OAuth
+16 more
Runbook Server Administration Simple Object Access Protocol (SOAP) Software Vulnerability Management Data Logging Mttr SOAPAPI Tanium Platform Expertise Forescout Build Management Enterprise Integration Restful APIs IoT Security Network Server Qualys Servicenow

Job description

  • Integration Architecture & Development
  • Design and build bidirectional integrations between ServiceNow and Tanium, Maximo, Forescout, and Qualys using REST/SOAP APIs, MID Servers, IntegrationHub spokes, and custom scripted APIs.
  • Ensure data integrity and synchronization for asset, configuration, and vulnerability data flowing between ServiceNow CMDB/CSDM and source systems.
  • Build and maintain integration error handling, retry logic, logging, and monitoring/alerting for all connected systems.
  • Map and normalize data schemas across platforms (e.g., Qualys QID to ServiceNow Vulnerable Item, Forescout device classification to CMDB CI, Tanium asset/patch data to CI attributes, Maximo asset/work order data to OT asset records).
  • Vulnerability Management Process Automation
  • Architect and automate the full vulnerability management lifecycle in ServiceNow: ingestion * asset/CI correlation * risk scoring/prioritization * assignment * remediation workflow * verification * closure.
  • Build ServiceNow Flow Designer/Workflow automations to orchestrate remediation tasks, approvals, exception/riskacceptance processes, and SLAbased escalations.
  • Configure automated ticketing and work order creation in Maximo for OT asset remediation, tied back to ServiceNow vulnerability records.
  • Implement automated network segmentation/containment triggers leveraging Forescout for highrisk or unpatchable OT assets.
  • Build logic to reconcile Tanium patch/configuration data with Qualys scan results to reduce false positives and validate remediation.
  • Documentation & Audit Trail
  • Configure ServiceNow to automatically document all actions taken (system and human) across the vulnerability lifecycle - including timestamps, source system, decision rationale, approvals, and remediation evidence - to support audit, compliance, and regulatory reporting (e.g., IEC 62443, NIST 80082).
  • Build reporting dashboards and performance analytics (MTTR, SLA compliance, risk exposure trends) using ServiceNow Performance Analytics/Reporting.
  • Maintain integration and workflow documentation, runbooks, and data flow diagrams.
  • OTSpecific Considerations
  • Apply OTappropriate remediation strategies (compensating controls, segmentation, virtual patching) when direct patching is not feasible due to safety, uptime, or vendor constraints.
  • Partner with OT engineering and plant/site teams to validate that automated actions do not disrupt production or safety systems.
  • Maintain a unified IT/OT asset and vulnerability inventory within the ServiceNow CMDB/CSDM.
  • Collaboration & Governance
  • Work with Security Operations, IT, OT Engineering, and Compliance teams to define workflow requirements, escalation paths, and risk acceptance criteria.
  • Support change management and testing (dev/test/prod) for all integration and workflow changes.
  • Provide subject matter expertise on ServiceNow Vulnerability Response and OT Security module capabilities and roadmap.

Requirements

  • 4+ years of experience administering or engineering on the ServiceNow platform, including: Vulnerability Response (VR) and/or OT/IoT Security modules; Flow Designer / Workflow Editor; Integration Hub, REST/SOAP Message integrations, MID Server configuration; CMDB/CSDM data modeling.
  • Demonstrated experience building twoway integrations with two or more of the following: Tanium, Qualys, Forescout, Maximo (or comparable CMMS/EAM).
  • Solid understanding of vulnerability management lifecycle concepts: scanning, risk scoring (CVSS/VPR), prioritization, remediation SLAs, and exception management.
  • Working knowledge of OT/ICS/SCADA environments and the operational constraints that differentiate OT vulnerability management from traditional IT patching.
  • Experience with JavaScript (Glide API, Scripted REST APIs, Business Rules) for custom ServiceNow development.
  • Strong understanding of API authentication methods (OAuth2, mutual TLS, API keys) and secure integration design.
  • Excellent documentation skills and ability to translate technical workflows into auditready records.
  • Years of Experience: 17.00 Years of Experience
  • ServiceNow certifications: CSA (Certified System Administrator; CISVR (Vulnerability Response), or CISSecOps, OT Discovery and OT VM Certifications

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:08 min

Aligning engineering processes with core business impact metrics

Chris Riley · World Congress 2021

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

3:07 min

Establishing service level agreements directly for internal platforms

Pawel Piwosz · LIVE

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

52 sec

Defining application, pipeline, and security operations roles

Aarno Aukia · LIVE

Videos

See all

Related articles

See all