About The Position

At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. In the digital economy, it takes more than good ideas and strong leadership to thrive. Upgrading outdated processes, systems and information is vital – but can be a risky investment in such a rapidly changing environment. That’s why some of the most prestigious businesses worldwide look to us for authoritative, agile, and efficient solutions for business decision-making. As a ServiceNow Consulting Manager you’ll play a leading role in that mission, providing the competitive edge our clients need to overcome some of the biggest creative and technical challenges around. The opportunity We are seeking a highly skilled and experienced ServiceNow SecOps Architect with extensive experience of vulnerability management to join our team. The ideal candidate will be responsible for designing, implementing, and managing the ServiceNow Vulnerability Response module to enhance our organization's security posture. This role requires a deep understanding of vulnerability management processes, strong technical expertise in ServiceNow, and the ability to collaborate effectively with various stakeholders. In this capacity, the successful candidate will function as the principal subject matter expert, bridging the domains of cybersecurity and IT operations. Your key responsibilities As a Manager in Application Design and Development, you will lead the effective management and delivery of processes, solutions, and projects, ensuring a strong focus on quality and risk management. This role presents exciting challenges and opportunities for growth, allowing you to apply your expertise in guiding others and recommending quality solutions. You will engage regularly with external clients, actively participating in working sessions and leading workstreams from planning through execution and closure. Travel may be required as needed by external clients.

Requirements

  • A bachelor's degree, preferably in Computer Science, Information Systems Management, Engineering or similar discipline
  • Typically, no less than 4 - 6 years of relevant experience in IT or cybersecurity including extensive experience with hands-on ServiceNow development or architectural capacities.
  • At least 3 years of direct experience solutioning the ServiceNow Security Operations suite (Vulnerability Response, SIR, Configuration Compliance).
  • Demonstrated, in-depth understanding of the vulnerability management lifecycle, including scanning, prioritization, remediation tracking, and exception management.
  • Advanced proficiency with ServiceNow development tools: Flow Designer, Business Rules, Script Includes, REST integrations, and scheduled jobs.
  • Proven experience integrating ServiceNow with vulnerability scanners such as Tenable.io/Nessus, Qualys, Rapid7 InsightVM, or cloud-native security solutions.
  • Comprehensive understanding of the CMDB data model and best practices in Configuration Management.
  • Familiarity with established cybersecurity frameworks and standards (NIST CSF, CIS Controls, ISO 27001, SOC 2).
  • Possession of the ServiceNow Certified Implementation Specialist - Vulnerability Response is mandatory.
  • Prior consulting experience
  • Excellent soft skills – executive communication (written/verbal), adaptability, problem solving, teamwork, relationship building, dependability, and organization
  • Experience leading teams and supervising others
  • A driver’s license valid in the U.S.
  • Ability to travel to meet client needs and based out of Chicago, IL

Nice To Haves

  • ServiceNow Certified Implementation Specialist – Security Incident Response (CIS-SIR)
  • ServiceNow Certified Technical Architect (CTA) or Certified Master Architect (CMA)
  • Experience with Security Orchestration, Automation, and Response (SOAR) platforms or integrations with threat intelligence feeds (such as MITRE ATT&CK, TAXII/STIX).
  • Familiarity with cloud security posture management (CSPM) tools and their incorporation into vulnerability management workflows.
  • Prior experience within regulated sectors, including financial services, healthcare, or government.
  • Knowledge of Agile or SAFe delivery methodologies.
  • Holding CISSP, CISM, or an equivalent security certification is regarded as a significant asset.
  • Experience with Platform foundations, CMDB, ITOM and ITAM is preferred.
  • Familiarity with other modules such as IRM and SPM is a plus.

Responsibilities

  • Architecture & Design Design and take end-to-end ownership of ServiceNow Security Operations (SecOps) modules, encompassing Vulnerability Response (VR), Security Incident Response (SIR), Configuration Compliance, and Threat Intelligence.
  • Define robust integration patterns between ServiceNow and third-party vulnerability scanners (such as Tenable, Qualys, Rapid7, Wiz, Defender for Endpoint) utilizing REST APIs, ITSM connectors, and MID Server configurations.
  • Develop workflows, Service Level Agreement (SLA) definitions, and remediation playbooks that are aligned with the organization’s risk profile and compliance mandates.
  • Establish scalable data models, CI/CMDB enrichment strategies, and asset attribution mechanisms to ensure vulnerability data remains precise, deduplicated, and actionable.
  • Prepare ServiceNow SecOps roadmap with stake holders Implementation & Delivery Lead the configuration and bespoke development of Vulnerability Response modules, including group management, exception handling, and the integration of risk scoring systems (such as CVSS, EPSS, and asset criticality metrics).
  • Construct and maintain robust integration pipelines from scanner outputs into ServiceNow, ensuring data integrity and timeliness at all stages.
  • Develop and oversee dashboards, KPIs, and executive reporting to monitor vulnerability posture, SLA adherence, and remediation trends.
  • Champion CMDB hygiene initiatives to enhance asset coverage and ensure the veracity of vulnerability-to-asset mapping processes.
  • Propose and provide solution options business cases, prototypes and walk-throughs to all required levels of stakeholders Governance & Strategy Collaborate with Security, IT Operations, and Risk & Compliance teams to define and formalize vulnerability management policies, SLA hierarchies, and escalation protocols.
  • Develop and enforce comprehensive platform governance standards, encompassing change management, rigorous testing protocols, and release management for the SecOps product suite.
  • Serve as a technical adviser in strategic roadmap development, evaluating new features within ServiceNow SecOps and determining optimal adoption pathways.
  • Mentor and guide junior platform engineers and administrators, fostering adherence to SecOps best practices and ServiceNow development standards.
  • Stakeholder Engagement Translate both business and security requirements into tangible technical capabilities on the platform, presenting architectural options and associated trade-offs to audiences of varying technical backgrounds.
  • Engage collaboratively with SOC, vulnerability management, and red/blue teams to drive continual improvements in detection, prioritization, and response workflows.
  • Lead platform demonstrations, workshops, and instructional sessions for end users and IT stakeholders to ensure effective platform utilization.

Benefits

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business.
  • The base salary range for this job in all geographic locations in the US is $142,600 to $261,500.
  • The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $171,200 to $297,200.
  • Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography.
  • In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances.
  • You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service