ServiceNow Security Incident Response Lead

TOMORROW HIREMorgantown, WV
$150,000 - $200,000Hybrid

About The Position

Our client is seeking a hands-on ServiceNow Security Incident Response Lead to support a proposed Department of Energy engagement involving the implementation and configuration of ServiceNow Security Incident Response. The selected professional will configure ServiceNow SIR, integrate security-alert sources, implement incident-response processes aligned with NIST and SANS frameworks, configure risk scoring and service-level agreements, develop playbooks, establish threat-intelligence feeds, and configure incident workspaces, reporting, and knowledge-management capabilities. This is a senior, hands-on implementation position. Depending on the final team composition, one of the three ServiceNow professionals supporting the project may also assume broader Solution Architect responsibilities. The anticipated start date is September 1, 2026, or as close to that date as possible.

Requirements

  • Minimum three years of ServiceNow implementation experience.
  • Minimum five years of software-development experience.
  • Minimum three years of ServiceNow architecture experience involving solution design, development, and customization.
  • Minimum three years of ServiceNow Security Incident Response experience.
  • Minimum three years of experience integrating ServiceNow with Microsoft Azure Sentinel, Splunk, or Palo Alto Networks NGFW.
  • Minimum three years of experience configuring threat-intelligence feeds.
  • Minimum three years of experience configuring ServiceNow SIR fields and workspaces.
  • Minimum three years of experience configuring security-incident catalogs, reports, or dashboards.
  • Hands-on experience implementing and configuring ServiceNow solutions.
  • Current ServiceNow certification.
  • Must be a U.S. citizen due to federal contract requirements.
  • Must be willing and able to complete applicable background screening and DOE badging requirements.
  • Must be prepared for onsite presence in Morgantown, West Virginia, if required by DOE.

Nice To Haves

  • Bachelor’s degree.
  • Previous federal government or Department of Energy experience.
  • Ability to commute to Morgantown, WV.

Responsibilities

  • Install and configure the ServiceNow Security Incident Response plug-in.
  • Integrate Microsoft Azure Sentinel, Palo Alto Networks NGFW, and Splunk for alert ingestion.
  • Configure inbound email-ingestion rules for the creation of security incidents.
  • Configure groups, roles, and permissions for incident response.
  • Implement an SIR process aligned with NIST and SANS frameworks.
  • Configure two assignment and escalation rules.
  • Implement severity calculators and risk scoring to prioritize security incidents.
  • Configure up to three service-level agreements for security incidents.
  • Configure one post-incident review process.
  • Configure ServiceNow analysis tools.
  • Configure security tagging for access restriction.
  • Establish threat-intelligence feeds using STIX/TAXII sources.
  • Configure the ingestion of cyber-threat intelligence from email sources.
  • Configure out-of-the-box notifications and up to five additional customized notifications.
  • Configure two task playbooks of moderate complexity.
  • Establish a runbook knowledge base and import existing runbooks.
  • Configure SIR fields and workspaces.
  • Enable out-of-the-box reports and dashboards.
  • Create up to five additional SIR reports.
  • Configure the security-incident catalog.
  • Provide staff training and knowledge transfer.

Benefits

  • Medical insurance
  • Dental insurance
  • Vision insurance
  • 401(k)
  • Unpaid sick leave and personal time off in accordance with company policy
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service