ServiceNow Security Incident Response Lead
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Our client is seeking a hands-on ServiceNow Security Incident Response Lead to support a proposed Department of Energy engagement involving the implementation and configuration of ServiceNow Security Incident Response. The selected professional will configure ServiceNow SIR, integrate security-alert sources, implement incident-response processes aligned with NIST and SANS frameworks, configure risk scoring and service-level agreements, develop playbooks, establish threat-intelligence feeds, and configure incident workspaces, reporting, and knowledge-management capabilities. This is a senior, hands-on implementation position. Depending on the final team composition, one of the three ServiceNow professionals supporting the project may also assume broader Solution Architect responsibilities. The anticipated start date is September 1, 2026, or as close to that date as possible., * Install and configure the ServiceNow Security Incident Response plug-in.
- Integrate Microsoft Azure Sentinel, Palo Alto Networks NGFW, and Splunk for alert ingestion.
- Configure inbound email-ingestion rules for the creation of security incidents.
- Configure groups, roles, and permissions for incident response.
- Implement an SIR process aligned with NIST and SANS frameworks.
- Configure two assignment and escalation rules.
- Implement severity calculators and risk scoring to prioritize security incidents.
- Configure up to three service-level agreements for security incidents.
- Configure one post-incident review process.
- Configure ServiceNow analysis tools.
- Configure security tagging for access restriction.
- Establish threat-intelligence feeds using STIX/TAXII sources.
- Configure the ingestion of cyber-threat intelligence from email sources.
- Configure out-of-the-box notifications and up to five additional customized notifications.
- Configure two task playbooks of moderate complexity.
- Establish a runbook knowledge base and import existing runbooks.
- Configure SIR fields and workspaces.
- Enable out-of-the-box reports and dashboards.
- Create up to five additional SIR reports.
- Configure the security-incident catalog.
- Provide staff training and knowledge transfer., This position is being recruited as hybrid while final work-location guidance is pending from DOE. Candidates should be prepared for onsite work in Morgantown, West Virginia. The final onsite schedule and remote-work availability will be based on DOE requirements and cannot be guaranteed at this stage. Security and Citizenship Requirements Applicants must be U.S. citizens due to federal contract requirements. No active security-clearance level is currently specified. Selected personnel must successfully complete applicable background screening and DOE identity-verification and badging requirements. Additional access requirements may be established by the DOE Contracting Officer. Contract Contingency This position supports an active proposal and is contingent upon contract award. The anticipated period of performance is September 1, 2026 through July 12, 2027. The anticipated start date and work arrangement remain subject to contract award and final DOE direction.
Requirements
- Minimum three years of ServiceNow implementation experience.
- Minimum five years of software-development experience.
- Minimum three years of ServiceNow architecture experience involving solution design, development, and customization.
- Minimum three years of ServiceNow Security Incident Response experience.
- Minimum three years of experience integrating ServiceNow with Microsoft Azure Sentinel, Splunk, or Palo Alto Networks NGFW.
- Minimum three years of experience configuring threat-intelligence feeds.
- Minimum three years of experience configuring ServiceNow SIR fields and workspaces.
- Minimum three years of experience configuring security-incident catalogs, reports, or dashboards.
- Hands-on experience implementing and configuring ServiceNow solutions.
- Current ServiceNow certification.
- Must be a U.S. citizen due to federal contract requirements.
- Must be willing and able to complete applicable background screening and DOE badging requirements.
- Must be prepared for onsite presence in Morgantown, West Virginia, if required by DOE., * Bachelor’s degree.
- Previous federal government or Department of Energy experience.
- Ability to commute to Morgantown, WV.
Benefits & conditions
$150,000-$200,000 per year, based on experience and contingent upon contract award., * Medical insurance
- Dental insurance
- Vision insurance
- 401(k)
- Unpaid sick leave and personal time off in accordance with company policy
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Is Software Engineering Over-Saturated?
A Guide to Green Tech and Green IT Careers
9 Ways to Make Money Hacking