Summary
GuidePoint Security provides cybersecurity expertise, solutions, and services that help organizations identify threats, optimize resources, and mitigate risk. The Vulnerability Management Engineer - ServiceNow will design, configure, and operate ServiceNow Security Operations and Vulnerability Response capabilities, develop automated vulnerability lifecycle workflows and integrations, and support risk-based remediation and exposure management programs for clients and internal customers.
Responsibilities
- Design, configure, and support ServiceNow Vulnerability Response (VR) to manage the end-to-end vulnerability lifecycle — from ingestion and de-duplication through assignment, remediation, exception handling, and closure
- Build and maintain remediation workflows, vulnerability groups, assignment rules, and calculators using Flow Designer, Business Rules, and other ServiceNow technologies
- Configure risk scoring and prioritization models that combine CVSS, threat intelligence, exploitability, and business/asset criticality to drive risk-based remediation
- Develop custom automation and workflows using JavaScript, HTML/CSS, Python, and ServiceNow platform capabilities to reduce manual triage effort
- Configure and maintain the ServiceNow Security Operations suite, including Vulnerability Response and, where in scope, Security Incident Response (SIR) and Configuration Compliance
- Manage the vulnerability lifecycle end-to-end: intake, correlation, prioritization, remediation tracking, verification, and reporting
- Conduct vulnerability analysis and prioritization, coordinating remediation with client infrastructure, security, and application teams
- Design and maintain ServiceNow Security Operations dashboards, KPIs, and SLA monitoring to give security leadership visibility into remediation performance and risk posture
- Configure and manage vulnerability scanning and security tool integrations via APIs — including Qualys, Tenable, Rapid7, Microsoft Defender, and CrowdStrike — and normalize their data into ServiceNow
- Integrate threat intelligence and asset data sources to enrich findings with exploit and exposure context
- Automate reporting, ticketing, notifications, and remediation tracking to reduce noise and accelerate response
- Troubleshoot and optimize integrations, data imports, and scheduled jobs to ensure data accuracy and platform reliability
- Leverage CMDB, Discovery, and Service Mapping to establish accurate asset intelligence and business-service context for vulnerability prioritization
- Validate Configuration Item (CI) relationships and service dependencies so that discovered assets are correctly mapped to vulnerability findings
- Improve vulnerability-to-CI correlation and asset criticality ratings to support business-service-aware, risk-based remediation
- Support exposure management initiatives by extending coverage beyond traditional CVEs and helping unify asset, vulnerability, and exposure data for prioritized action
- Provide operational support including incident support, root cause investigations, and process optimization
- Support governance activities such as SLA monitoring, risk management, and compliance reporting
- Contribute to documentation, operational playbooks, and knowledge articles for repeatable delivery
- Keep up to date with emerging trends and technologies in ServiceNow Security Operations, Vulnerability Response, and exposure management, and apply them to client environments
Skills
- At least 1-2+ years of experience in ServiceNow Security Operations and CMDB implementation and integration
- Hands-on experience configuring ServiceNow Vulnerability Response (VR) and Security Operations, including Flow Designer and workflow configuration
- Experience integrating vulnerability scanners and security tools (e.g., Qualys, Tenable, Rapid7, Microsoft Defender, CrowdStrike) with ServiceNow via APIs
- Working knowledge of vulnerability management concepts — CVSS, risk assessment, exploitability, and SLA-driven remediation
- Understanding of ITOM concepts — CMDB, Discovery, and Service Mapping — and how asset context drives risk-based prioritization
- Strong programming skills in Python, JavaScript, HTML/CSS, and other ServiceNow technologies
- Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes
- Bachelor's degree in computer science, Information Systems, or a related field is preferred
- Basic understanding of vulnerability management and security operations processes and procedures
- Experience with exposure management / risk-based vulnerability management (RBVM) and prioritizing findings by business impact
- Familiarity with threat intelligence enrichment and Security Incident Response (SIR) workflows
- Experience building executive-ready dashboards, KPIs, and SLA/compliance reporting in ServiceNow
- Strong problem-solving and analytical skills
- Excellent communication, documentation and collaboration skills
- ServiceNow Certified System Administrator
- ServiceNow Certified Application Developer
- ServiceNow Certified Application Specialist
- Risk and Compliance
- Vendor Risk Management (VRM)
- Security Incident Response (SIR)
- Vulnerability Response (VR)
Qualifications
Must Haves
- At least 1-2+ years of experience in ServiceNow Security Operations and CMDB implementation and integration
- Hands-on experience configuring ServiceNow Vulnerability Response (VR) and Security Operations, including Flow Designer and workflow configuration
- Experience integrating vulnerability scanners and security tools (e.g., Qualys, Tenable, Rapid7, Microsoft Defender, CrowdStrike) with ServiceNow via APIs
- Working knowledge of vulnerability management concepts — CVSS, risk assessment, exploitability, and SLA-driven remediation
- Understanding of ITOM concepts — CMDB, Discovery, and Service Mapping — and how asset context drives risk-based prioritization
- Strong programming skills in Python, JavaScript, HTML/CSS, and other ServiceNow technologies
- Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes
Nice to Haves
- Bachelor's degree in computer science, Information Systems, or a related field is preferred
- Basic understanding of vulnerability management and security operations processes and procedures
- Experience with exposure management / risk-based vulnerability management (RBVM) and prioritizing findings by business impact
- Familiarity with threat intelligence enrichment and Security Incident Response (SIR) workflows
- Experience building executive-ready dashboards, KPIs, and SLA/compliance reporting in ServiceNow
- Strong problem-solving and analytical skills
- Excellent communication, documentation and collaboration skills
- ServiceNow Certified System Administrator
- ServiceNow Certified Application Developer
- ServiceNow Certified Application Specialist
- Risk and Compliance
- Vendor Risk Management (VRM)
- Security Incident Response (SIR)
- Vulnerability Response (VR)
Benefits
- Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
- Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family).
- If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
- Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
- 12 corporate holidays and a Flexible Time Off (FTO) program
- Healthy mobile phone and home internet allowance
- Eligibility for retirement plan after 2 months at open enrollment
- Pet Benefit Option