Search by job, company or skills

ServiceNow Vulnerability Response (VR) Engineer

5-7 Years
  • Posted 11 hours ago
  • Be among the first 10 applicants

Job Description

ServiceNow Vulnerability Response (VR) Engineer

 

Experience: 5-6 Years

Relevant ServiceNow Experience: 4+ Years in ServiceNow Security Operations / SecOps

Contract: 3 Months, Extendable

Location: Remote — Candidates from Chennai, Bangalore, or Pune preferred

Communication: Excellent verbal and written communication skills required

 

 Position Summary

 

We are looking for an experienced *ServiceNow Vulnerability Response (VR) Engineer* to implement, configure, integrate, and support ServiceNow Vulnerability Response solutions in an enterprise environment.

 

The candidate will be responsible for managing the end-to-end vulnerability lifecycle, developing remediation workflows, integrating ServiceNow with enterprise security tools, and improving risk-based vulnerability prioritization.

 

The role requires strong knowledge of *ServiceNow SecOps and Vulnerability Response, along with a good functional understanding of **ITOM, CMDB, Discovery, Service Mapping, configuration management, and asset lifecycle management*.

 

The ideal candidate should be capable of connecting vulnerability findings with accurate infrastructure and business-service context to enable effective, risk-based remediation.

 

Key Responsibilities

 

ServiceNow Vulnerability Response

 

* Configure and maintain *ServiceNow Vulnerability Response* applications and modules.

* Configure vulnerability groups, assignment rules, remediation targets, and workflows.

* Develop and maintain remediation workflows using *Flow Designer* and ServiceNow workflow capabilities.

* Configure and optimize vulnerability risk scoring and prioritization models.

* Manage vulnerability findings, remediation tasks, exceptions, and remediation status.

* Support vulnerability identification, analysis, prioritization, assignment, and closure.

* Ensure vulnerability remediation processes align with organizational security policies and SLAs.

 

Vulnerability Management & Security Operations

 

* Manage the complete vulnerability lifecycle from detection through remediation and closure.

* Analyze vulnerability findings and prioritize remediation based on risk, severity, asset criticality, and business impact.

* Work closely with security, infrastructure, application, and operations teams to drive remediation.

* Track remediation progress and identify aging or SLA-breaching vulnerabilities.

* Support root-cause analysis for vulnerability-related operational issues.

* Assist in improving vulnerability management processes and operational efficiency.

* Prepare vulnerability metrics, KPI dashboards, SLA reports, and compliance reports.

 

ITOM, CMDB & Asset Context

 

* Leverage *CMDB information* to improve vulnerability prioritization and remediation decisions.

* Understand relationships between Configuration Items (CIs), applications, infrastructure components, and business services.

* Work with CMDB and Discovery teams to ensure accurate asset information.

* Validate CI relationships and service dependencies used for vulnerability analysis.

* Ensure vulnerability findings are correctly correlated with discovered assets and CIs.

* Support business-service-aware vulnerability remediation.

* Collaborate with ITOM teams to improve asset visibility and data quality.

 

ServiceNow ITOM Knowledge

 

The candidate should have a strong functional understanding of:

 

* CMDB

* Discovery

* Service Mapping

* Configuration Management

* Asset Management / Asset Lifecycle

* Event Management — preferred

* CI relationships and dependency mapping

* Business services and service dependencies

 

The candidate should understand how security findings and vulnerabilities relate to infrastructure assets, applications, Configuration Items, and business services.

 

 Security Tool Integrations

 

Hands-on experience integrating ServiceNow Vulnerability Response with security and vulnerability management platforms is required.

 

Preferred integration experience includes:

 

  • Qualys
  • Tenable
  • Rapid7
  • Microsoft Defender
  • CrowdStrike

 

The candidate should understand vulnerability data ingestion, mapping/correlation, CI identification, synchronization, remediation task creation, and status updates between ServiceNow and external security tools.

 

 Collaboration

 

The engineer will work closely with:

 

  • Security Operations / Cybersecurity Teams
  • Vulnerability Management Teams
  • CMDB Teams
  • ServiceNow Platform Teams
  • Discovery / ITOM Teams
  • Infrastructure Operations
  • Network Teams
  • Application Support Teams
  • Compliance and Risk Teams

 

 Operational Responsibilities

 

  • Provide production support for ServiceNow Vulnerability Response.
  • Troubleshoot incidents related to vulnerability integrations, workflows, data synchronization, and remediation processes.
  • Perform root-cause analysis and implement corrective actions.
  • Monitor vulnerability processing and remediation SLAs.
  • Identify opportunities for automation and process optimization.
  • Support operational reporting and security governance activities.
  • Participate in enhancement and continuous-improvement initiatives.

 

 Mandatory Technical Skills

 

  • ServiceNow SecOps
  • ServiceNow Vulnerability Response
  • ServiceNow Security Operations / SecOps
  • Vulnerability lifecycle management
  • Vulnerability remediation
  • Vulnerability groups
  • Assignment rules
  • Risk scoring
  • Remediation workflows
  • Flow Designer
  • ServiceNow configuration and administration

 

 Vulnerability Management

 

  • Vulnerability assessment and prioritization
  • CVSS
  • Risk assessment
  • Vulnerability remediation processes
  • Security operations processes
  • SLA-based remediation

 

 Integration Experience
Hands-on experience with one or more of the following:

  • Qualys
  • Tenable
  • Rapid7
  • Microsoft Defender
  • CrowdStrike

 

 Preferred Skills

 

  • ServiceNow Security Incident Response (SIR)
  • Threat Intelligence
  • GRC
  • ITOM
  • CMDB
  • Discovery
  • Service Mapping
  • Event Management
  • ITIL processes

 

 Certifications

Mandatory:

ServiceNow Certified System Administrator (CSA)

Preferred:

  • ServiceNow Certified Implementation Specialist - Vulnerability Response (CIS-VR)
  • CompTIA Security+
  • ITIL Foundation

 

 Candidate Profile

 

* 5-6 years of overall IT experience.

* Minimum 3+ years of hands-on ServiceNow SecOps experience.

* Strong hands-on experience with *ServiceNow Vulnerability Response*.

* Good understanding of enterprise vulnerability management processes.

* Strong understanding of CMDB, Discovery, Service Mapping, and asset relationships.

* Experience working with vulnerability/security tool integrations.

* Strong analytical and troubleshooting skills.

* Ability to work independently in a remote environment.

* Excellent verbal and written communication skills.

* Strong stakeholder management and collaboration skills.

 

Key Requirements at a Glance

Must Have:

* ServiceNow Vulnerability Response

* ServiceNow SecOps

* Vulnerability Management

* Flow Designer / Workflow Configuration

* CVSS & Risk Assessment

* Qualys / Tenable / Rapid7 integration experience

* CMDB knowledge

* ITOM understanding

* CSA certification

* Excellent communication skills

 

Good to Have:

* ServiceNow SIR

* Threat Intelligence

* GRC

* Discovery

* Service Mapping

* Event Management

* CIS-Vulnerability Response

* Security+

* ITIL Foundation

More Info

Job Type:
Industry:
Employment Type:

Job ID: 153886891

Beware of Scammers

We don’t charge money for job offers