Role OverviewThe selected professional will configure ServiceNow SIR, integrate security-alert sources, implement incident-response processes aligned with NIST and SANS frameworks, configure risk scoring and service-level agreements, develop playbooks, establish threat-intelligence feeds, and configure incident workspaces, reporting, and knowledge-management capabilities.
What You Will Do
Install and configure the ServiceNow Security Incident Response plug-in, integrate Microsoft Azure Sentinel, Palo Alto Networks NGFW, and Splunk for alert ingestion, configure inbound email-ingestion rules for the creation of security incidents, and implement an SIR process aligned with NIST and SANS frameworks.
Why It Might Be a Fit
Must be a hands-on ServiceNow Security Incident Response Lead with a minimum of three years of ServiceNow implementation experience, current ServiceNow certification, and U.S. citizenship due to federal contract requirements.
Requirements
- Minimum three years of ServiceNow implementation experience
- Current ServiceNow certification
- Must be a U.S. citizen due to federal contract requirements
- Must be willing and able to complete applicable background screening and DOE badging requirements
Benefits
- Medical insurance
- Dental insurance
- Vision insurance
- 401(k)
- Unpaid sick leave and personal time off in accordance with company policy
]]>