ServiceNow Security Incident Response Lead

TOMORROW HIRE

$150K — $200K *
Energy & Utilities
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Minimum 3 years of ServiceNow implementation experience.
  • Minimum 5 years of software development experience.
  • Minimum 3 years of ServiceNow architecture experience for solution design and customization.
  • Minimum 3 years of ServiceNow Security Incident Response experience.
  • Experience integrating ServiceNow with Microsoft Azure Sentinel, Splunk, or Palo Alto Networks NGFW.
  • Hands-on experience implementing ServiceNow solutions.
  • Current ServiceNow certification.

Responsibilities

  • Install and configure ServiceNow Security Incident Response plug-in.
  • Integrate security tools like Microsoft Azure Sentinel and Splunk for alert ingestion.
  • Implement incident response processes in line with NIST and SANS frameworks.
  • Establish threat-intelligence feeds and configure service-level agreements.
  • Create customized reports and dashboards for security incident management.
  • Provide training and knowledge transfer to staff.
  • Configure and manage security incident catalogs and workflows.

Benefits

  • Medical insurance
  • Dental insurance
  • Vision insurance
  • 401(k) plan
  • Unpaid sick leave and personal time off according to company policy
Full Job Description
Work Type: Hybrid, subject to final DOE direction
Location: Morgantown, WV
Salary: $150,000-$200,000 per year, based on experience
Employment Type: Full-Time W-2
Anticipated Period of Performance: September 1, 2026-July 12, 2027
Contract Status: Contingent upon contract award

Position Overview

Our client is seeking a hands-on ServiceNow Security Incident Response Lead to support a proposed Department of Energy engagement involving the implementation and configuration of ServiceNow Security Incident Response.

The selected professional will configure ServiceNow SIR, integrate security-alert sources, implement incident-response processes aligned with NIST and SANS frameworks, configure risk scoring and service-level agreements, develop playbooks, establish threat-intelligence feeds, and configure incident workspaces, reporting, and knowledge-management capabilities.

This is a senior, hands-on implementation position. Depending on the final team composition, one of the three ServiceNow professionals supporting the project may also assume broader Solution Architect responsibilities.

The anticipated start date is September 1, 2026, or as close to that date as possible.

Key Responsibilities
  • Install and configure the ServiceNow Security Incident Response plug-in.
  • Integrate Microsoft Azure Sentinel, Palo Alto Networks NGFW, and Splunk for alert ingestion.
  • Configure inbound email-ingestion rules for the creation of security incidents.
  • Configure groups, roles, and permissions for incident response.
  • Implement an SIR process aligned with NIST and SANS frameworks.
  • Configure two assignment and escalation rules.
  • Implement severity calculators and risk scoring to prioritize security incidents.
  • Configure up to three service-level agreements for security incidents.
  • Configure one post-incident review process.
  • Configure ServiceNow analysis tools.
  • Configure security tagging for access restriction.
  • Establish threat-intelligence feeds using STIX/TAXII sources.
  • Configure the ingestion of cyber-threat intelligence from email sources.
  • Configure out-of-the-box notifications and up to five additional customized notifications.
  • Configure two task playbooks of moderate complexity.
  • Establish a runbook knowledge base and import existing runbooks.
  • Configure SIR fields and workspaces.
  • Enable out-of-the-box reports and dashboards.
  • Create up to five additional SIR reports.
  • Configure the security-incident catalog.
  • Provide staff training and knowledge transfer.

Requirements

Minimum Qualifications
  • Minimum three years of ServiceNow implementation experience.
  • Minimum five years of software-development experience.
  • Minimum three years of ServiceNow architecture experience involving solution design, development, and customization.
  • Minimum three years of ServiceNow Security Incident Response experience.
  • Minimum three years of experience integrating ServiceNow with Microsoft Azure Sentinel, Splunk, or Palo Alto Networks NGFW.
  • Minimum three years of experience configuring threat-intelligence feeds.
  • Minimum three years of experience configuring ServiceNow SIR fields and workspaces.
  • Minimum three years of experience configuring security-incident catalogs, reports, or dashboards.
  • Hands-on experience implementing and configuring ServiceNow solutions.
  • Current ServiceNow certification.
  • Must be a U.S. citizen due to federal contract requirements.
  • Must be willing and able to complete applicable background screening and DOE badging requirements.
  • Must be prepared for onsite presence in Morgantown, West Virginia, if required by DOE.

Preferred Qualifications
  • Bachelor's degree.
  • Previous federal government or Department of Energy experience.
  • Ability to commute to Morgantown, WV.

Benefits

Compensation

$150,000-$200,000 per year, based on experience and contingent upon contract award.

Benefits
  • Medical insurance
  • Dental insurance
  • Vision insurance
  • 401(k)
  • Unpaid sick leave and personal time off in accordance with company policy

Work Location

This position is being recruited as hybrid while final work-location guidance is pending from DOE.

Candidates should be prepared for onsite work in Morgantown, West Virginia. The final onsite schedule and remote-work availability will be based on DOE requirements and cannot be guaranteed at this stage.

Security and Citizenship Requirements

Applicants must be U.S. citizens due to federal contract requirements.

No active security-clearance level is currently specified. Selected personnel must successfully complete applicable background screening and DOE identity-verification and badging requirements. Additional access requirements may be established by the DOE Contracting Officer.

Contract Contingency

This position supports an active proposal and is contingent upon contract award. The anticipated period of performance is September 1, 2026 through July 12, 2027. The anticipated start date and work arrangement remain subject to contract award and final DOE direction.

Similar Jobs

More Jobs at TOMORROW HIRE

More Energy & Utilities Jobs

Find similar ServiceNow Security Incident Response Lead jobs: