ServiceNow SecOps Architect

Tata Consultancy Services

Phoenix (AZ)

On-site

USD 130,000 - 180,000

Full time

2 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Tata Consultancy Services is seeking a senior ServiceNow SecOps Architect to lead end-to-end SIR & VR implementations, spanning data modeling, governance, and scalable CMDB design. You will architect bi-directional ITSM integrations and partner with global teams to align with security frameworks and performance standards.

You will drive automation, dashboards, and KPI reporting for vulnerability management, coordinating with stakeholders to deliver secure, compliant operations across

Qualifications

  • 12+ years of hands-on development experience on the ServiceNow platform.
  • 5+ years of experience in Security Incident Response (SIR) and Vulnerability Response (VR).
  • Design, configure and customize SIR & VR modules.
  • Design and develop workflows, business rules, client scripts, and integrations for SIR & VR.
  • Integrate VR with external vulnerability scanners and CMDB for data import and correlation.
  • Configure MID Servers, data sources, and API connections for vulnerability data ingestion.
  • Design automation for vulnerability assignment, remediation tracking, and exception management.
  • Create dashboards, reports, and Performance Analytics indicators for vulnerability KPIs and trends.
  • Strong understanding of SOC operations & incident response frameworks (NIST, SANS).
  • Experience with SIEM, SOAR, EDR, and vulnerability tools.
  • Strong understanding of ServiceNow CMDB, Discovery, and ITSM processes.
  • Experience integrating with vulnerability scanners (Qualys, Tenable, Rapid7, Prisma Cloud).
  • Knowledge of JavaScript, Glide API, Flow Designer, and REST/SOAP integrations.
  • Work with stakeholders to own delivery of work.
  • ServiceNow Certified Technical Architect (CTA).
  • Certified Implementation Specialist – Security Incident Response (CIS-SIR).

Responsibilities

  • Lead end-to-end architecture for ServiceNow SecOps SIR & VR, including data model, scopes, and modular design aligned to platform guardrails and performance best practices.
  • Define SecOps governance standards and design patterns
  • Define prioritization models and Risk Score formulas to drive actionable SLAs and dashboards.
  • Design and develop robust CMDB relationships to tie vulnerabilities to assets, services, and business applications (CIs), enabling service-aware remediation and reporting.
  • Enable bi-directional integration between SIR and ITSM.
  • Integrate enterprise vulnerability scanners (e.g., Tenable, Qualys, Rapid7) and threat intel feeds; tune parsing, de-duplication, and matching logic.
  • Optimize Vulnerability Item (VI) normalization, de-duplication, suppression, false positive handling, and asset‑vuln correlation at scale.
  • Implement exception workflows (risk acceptance, compensating controls, deferrals) with risk justification and approvals.
  • Build executive and operational dashboards (exposure by service, asset tier, business unit, critical vulnerabilities, SLA breach, MTTR).
  • Establish multi-environment strategies (DEV/TEST/PROD), ATF coverage, upgrade readiness, and platform governance.

Skills

ServiceNow platform
SIR & VR
Workflow design
JavaScript & Glide API
REST/SOAP integrations
CMDB/ITSM understanding
SOC operations & incident response
SIEM/SOAR/EDR experience
Security automation
CTA certification
CIS-SIR certification

Tools

Qualys
Tenable
Rapid7
Prisma Cloud
Flow Designer
Discovery

Job description

Job Description
Must Have Technical/Functional Skills
  • 12+ years of hands‑on development experience in ServiceNow platform.
  • 5+ years of experience specifically in Security Incident Response (SIR) and Vulnerability Response (VR) implementation.
  • Design, configure and customize ServiceNow SIR & VR module
  • Design and develop workflows, business rules, client scripts, and integrations supporting the SIR & VR lifecycle.
  • Integrate VR with external vulnerability scanners and CMDB (Configuration Management Database) to automate import and correlation of vulnerability data.
  • Configure MID Servers, data sources, and API connections for vulnerability data ingestion.
  • Design and develop automation for vulnerability assignment, remediation tracking, and exception management.
  • Create custom dashboards, reports, and Performance Analytics indicators for vulnerability KPIs and trends.
  • Strong understanding of SOC operations & Incident response frameworks (NIST, SANS)
  • Experience working with SIEM, SOAR, EDR, and vulnerability tools.
  • Strong understanding of ServiceNow CMDB, Discovery, and ITSM processes.
  • Experience integrating with vulnerability scanners (Qualys, Tenable, Rapid7, Prisma Cloud, etc.).
  • Knowledge of JavaScript, Glide API, Flow Designer, and REST/SOAP integrations.
  • Work with business stakeholders, technical stakeholders, onsite and offshore team to own the delivery of work.
  • ServiceNow Certified Technical Architect (CTA)
  • Certified Implementation Specialist – Security Incident Response (CIS-SIR)
Roles & Responsibilities
  • Lead end-to-end architecture for ServiceNow SecOps SIR & VR, including data model, scopes, and modular design aligned to platform guardrails and performance best practices.
  • Define SecOps governance standards and design patterns
  • Define prioritization models and Risk Score formulas to drive actionable SLAs and dashboards.
  • Design and develop robust CMDB relationships to tie vulnerabilities to assets, services, and business applications (CIs), enabling service-aware remediation and reporting.
  • Enable bi‑directional integration between SIR and ITSM.
  • Integrate enterprise vulnerability scanners (e.g., Tenable, Qualys, Rapid7) and threat intel feeds; tune parsing, de‑duplication, and matching logic.
  • Optimize Vulnerability Item (VI) normalization, de‑duplication, suppression, false positive handling, and asset‑vuln correlation at scale.
  • Implement exception workflows (risk acceptance, compensating controls, deferrals) with risk justification and approvals.
  • Build executive and operational dashboards (exposure by service, asset tier, business unit, critical vulnerabilities, SLA breach, MTTR).
  • Establish multi-environment strategies (DEV/TEST/PROD), ATF coverage, upgrade readiness, and platform governance.
Salary Range- $130,000-$180,000 a year
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

ServiceNow SecOps Sr. Developer
ServiceNow SecOps Sr. Developer

Tata Consultancy Services • Phoenix (AZ)

On-site
USD 110,000 - 140,000
Security Operations Architect - ServiceNow
Security Operations Architect - ServiceNow

Visionet Systems • New Jersey

Hybrid
USD 110,000 - 170,000
ServiceNow VR Developer
ServiceNow VR Developer

Veriipro • Jersey City (NJ)

On-site
USD 100,000 - 130,000
ServiceNow SecOps / SIR Architect
ServiceNow SecOps / SIR Architect

Veriipro • Houston (TX)

On-site
USD 140,000 - 190,000
Senior ServiceNow SecOps Developer (SIR & VR)
Senior ServiceNow SecOps Developer (SIR & VR)

Veriipro • Houston (TX)

On-site
USD 100,000 - 130,000
ServiceNow Developer (Sr. Level)
ServiceNow Developer (Sr. Level)

Veriipro • Richardson (TX)

Hybrid
USD 120,000 - 150,000
ServiceNow Developer
ServiceNow Developer

Alldus • New York (NY)

On-site
USD 95,000 - 135,000
ServiceNow Architect (AI + CSDM + Automation)
ServiceNow Architect (AI + CSDM + Automation)

GovCIO • Arlington (VA)

Hybrid
USD 220,000 - 240,000
ServiceNow SecOps Project Manager
ServiceNow SecOps Project Manager

Tata Consultancy Services • Irving (TX)

On-site
USD 90,000 - 120,000
Salary commensurate with experience
ServiceNow SecOps Developer
ServiceNow SecOps Developer

TechDigital Group • Fremont (CA)

On-site
USD 120,000 - 160,000