> Markdown version of [/jobs/ext/2073437-servicenow-ot-security-vulnerability-response-solution-architect](https://www.wearedevelopers.com/jobs/ext/2073437-servicenow-ot-security-vulnerability-response-solution-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ServiceNow OT Security / Vulnerability Response Solution Architect - **Company:** ICONMA LLC - **Location:** Glide, OR, United States - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Application Programming Interfaces (APIs), Application Integration Architecture, Audit Trail, Configuration Management Databases, Computerized Maintenance Management Systems, Cyber Security, Data Integrity, Supervisory Control and Data Acquisition (SCADA), IBM Maximo, Network Segmentation, OAuth, Runbook, Server Administration, Simple Object Access Protocol (SOAP), Software Vulnerability Management, Data Logging, Mttr, SOAPAPI, Tanium Platform Expertise, Forescout, Build Management, Enterprise Integration, Restful APIs, IoT Security, Network Server, Qualys, Servicenow - **Published:** August 15, 2026 - **Apply:** https://www.careerjet.com/job/us97c8c0f6f133e3a13df86e39e5a44ca2/eaa ## About the Role * 4+ years of experience administering or engineering on the ServiceNow platform, including: Vulnerability Response (VR) and/or OT/IoT Security modules; Flow Designer / Workflow Editor; Integration Hub, REST/SOAP Message integrations, MID Server configuration; CMDB/CSDM data modeling. * Demonstrated experience building twoway integrations with two or more of the following: Tanium, Qualys, Forescout, Maximo (or comparable CMMS/EAM). * Solid understanding of vulnerability management lifecycle concepts: scanning, risk scoring (CVSS/VPR), prioritization, remediation SLAs, and exception management. * Working knowledge of OT/ICS/SCADA environments and the operational constraints that differentiate OT vulnerability management from traditional IT patching. * Experience with JavaScript (Glide API, Scripted REST APIs, Business Rules) for custom ServiceNow development. * Strong understanding of API authentication methods (OAuth2, mutual TLS, API keys) and secure integration design. * Excellent documentation skills and ability to translate technical workflows into auditready records. * Years of Experience: 17.00 Years of Experience * ServiceNow certifications: CSA (Certified System Administrator; CISVR (Vulnerability Response), or CISSecOps, OT Discovery and OT VM Certifications ## Description * Integration Architecture & Development * Design and build bidirectional integrations between ServiceNow and Tanium, Maximo, Forescout, and Qualys using REST/SOAP APIs, MID Servers, IntegrationHub spokes, and custom scripted APIs. * Ensure data integrity and synchronization for asset, configuration, and vulnerability data flowing between ServiceNow CMDB/CSDM and source systems. * Build and maintain integration error handling, retry logic, logging, and monitoring/alerting for all connected systems. * Map and normalize data schemas across platforms (e.g., Qualys QID to ServiceNow Vulnerable Item, Forescout device classification to CMDB CI, Tanium asset/patch data to CI attributes, Maximo asset/work order data to OT asset records). * Vulnerability Management Process Automation * Architect and automate the full vulnerability management lifecycle in ServiceNow: ingestion * asset/CI correlation * risk scoring/prioritization * assignment * remediation workflow * verification * closure. * Build ServiceNow Flow Designer/Workflow automations to orchestrate remediation tasks, approvals, exception/riskacceptance processes, and SLAbased escalations. * Configure automated ticketing and work order creation in Maximo for OT asset remediation, tied back to ServiceNow vulnerability records. * Implement automated network segmentation/containment triggers leveraging Forescout for highrisk or unpatchable OT assets. * Build logic to reconcile Tanium patch/configuration data with Qualys scan results to reduce false positives and validate remediation. * Documentation & Audit Trail * Configure ServiceNow to automatically document all actions taken (system and human) across the vulnerability lifecycle - including timestamps, source system, decision rationale, approvals, and remediation evidence - to support audit, compliance, and regulatory reporting (e.g., IEC 62443, NIST 80082). * Build reporting dashboards and performance analytics (MTTR, SLA compliance, risk exposure trends) using ServiceNow Performance Analytics/Reporting. * Maintain integration and workflow documentation, runbooks, and data flow diagrams. * OTSpecific Considerations * Apply OTappropriate remediation strategies (compensating controls, segmentation, virtual patching) when direct patching is not feasible due to safety, uptime, or vendor constraints. * Partner with OT engineering and plant/site teams to validate that automated actions do not disrupt production or safety systems. * Maintain a unified IT/OT asset and vulnerability inventory within the ServiceNow CMDB/CSDM. * Collaboration & Governance * Work with Security Operations, IT, OT Engineering, and Compliance teams to define workflow requirements, escalation paths, and risk acceptance criteria. * Support change management and testing (dev/test/prod) for all integration and workflow changes. * Provide subject matter expertise on ServiceNow Vulnerability Response and OT Security module capabilities and roadmap. ## Related Videos - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)