> Markdown version of [/jobs/ext/2585812-solution-architect](https://www.wearedevelopers.com/jobs/ext/2585812-solution-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Solution Architect - **Company:** Spectraforce - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Temporary contract - **Skills:** JavaScript (Programming Language), Application Programming Interfaces (APIs), Application Integration Architecture, Audit Trail, Configuration Management Databases, Computerized Maintenance Management Systems, Cyber Security, Data Integrity, Supervisory Control and Data Acquisition (SCADA), IBM Maximo, Network Segmentation, OAuth, Runbook, Server Administration, Simple Object Access Protocol (SOAP), Systems Integration, Software Vulnerability Management, Data Logging, Mttr, SOAPAPI, Tanium Platform Expertise, Forescout, Build Management, Enterprise Integration, Restful APIs, IoT Security, Network Server, Qualys, Servicenow - **Published:** August 13, 2026 - **Apply:** http://leoforce.us/Careers/Spectraforce/JobDetails.html?jobid=65e5b239-1171-4603-820d-1c47f50bf260&OrgId=1&UserId=2285 ## About the Role * ServiceNow certifications: CSA (Certified System Administrator; * CIS-VR (Vulnerability Response), or CIS-SecOps * OT Discovery and OT VM Certifications, * 4+ years of experience administering or engineering on the ServiceNow platform, including: Vulnerability Response (VR) and/or OT/IoT Security modules; Flow Designer / Workflow Editor; IntegrationHub, REST/SOAP Message integrations, MID Server configuration; CMDB/CSDM data modeling. * Demonstrated experience building two-way integrations with two or more of the following: Tanium, Qualys, Forescout, Maximo (or comparable CMMS/EAM). * Solid understanding of vulnerability management lifecycle concepts: scanning, risk scoring (CVSS/VPR), prioritization, remediation SLAs, and exception management. * Working knowledge of OT/ICS/SCADA environments and the operational constraints that differentiate OT vulnerability management from traditional IT patching. * Experience with JavaScript (Glide API, Scripted REST APIs, Business Rules) for custom ServiceNow development. * Strong understanding of API authentication methods (OAuth2, mutual TLS, API keys) and secure integration design. * Excellent documentation skills and ability to translate technical workflows into audit-ready records. Years of Experience: 17 Years of Experience ## Description Integration Architecture & Development * Design and build bi-directional integrations between ServiceNow and Tanium, Maximo, Forescout, and Qualys using REST/SOAP APIs, MID Servers, IntegrationHub spokes, and custom scripted APIs. * Ensure data integrity and synchronization for asset, configuration, and vulnerability data flowing between ServiceNow CMDB/CSDM and source systems. * Build and maintain integration error handling, retry logic, logging, and monitoring/alerting for all connected systems. * Map and normalize data schemas across platforms (e.g., Qualys QID to ServiceNow Vulnerable Item, Forescout device classification to CMDB CI, Tanium asset/patch data to CI attributes, Maximo asset/work order data to OT asset records). Vulnerability Management Process Automation * Architect and automate the full vulnerability management lifecycle in ServiceNow: ingestion * asset/CI correlation * risk scoring/prioritization * assignment * remediation workflow * verification * closure. * Build ServiceNow Flow Designer/Workflow automations to orchestrate remediation tasks, approvals, exception/risk-acceptance processes, and SLA-based escalations. * Configure automated ticketing and work order creation in Maximo for OT asset remediation, tied back to ServiceNow vulnerability records. * Implement automated network segmentation/containment triggers leveraging Forescout for high-risk or unpatchable OT assets. * Build logic to reconcile Tanium patch/configuration data with Qualys scan results to reduce false positives and validate remediation. Documentation & Audit Trail * Configure ServiceNow to automatically document all actions taken (system and human) across the vulnerability lifecycle - including timestamps, source system, decision rationale, approvals, and remediation evidence - to support audit, compliance, and regulatory reporting (e.g., IEC 62443, NIST 800-82). * Build reporting dashboards and performance analytics (MTTR, SLA compliance, risk exposure trends) using ServiceNow Performance Analytics/Reporting. * Maintain integration and workflow documentation, runbooks, and data flow diagrams. OT-Specific Considerations * Apply OT-appropriate remediation strategies (compensating controls, segmentation, virtual patching) when direct patching is not feasible due to safety, uptime, or vendor constraints. * Partner with OT engineering and plant/site teams to validate that automated actions do not disrupt production or safety systems. * Maintain a unified IT/OT asset and vulnerability inventory within the ServiceNow CMDB/CSDM. Collaboration & Governance * Work with Security Operations, IT, OT Engineering, and Compliance teams to define workflow requirements, escalation paths, and risk acceptance criteria. * Support change management and testing (dev/test/prod) for all integration and workflow changes. * Provide subject matter expertise on ServiceNow Vulnerability Response and OT Security module capabilities and roadmap. ## Related Videos - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)