At a Glance
- Tasks: Design and optimise security workflows on the ServiceNow platform for incident response and threat intelligence.
- Company: Award-winning tech firm leading in security operations and compliance.
- Benefits: Inclusive workplace, competitive salary, and opportunities for professional growth.
- Other info: Flexible environment with a commitment to diversity and support for all applicants.
- Why this job: Join a dynamic team to make a real impact in cybersecurity automation.
- Qualifications: Experience with ServiceNow SecOps modules and integration tools like Splunk.
The predicted salary is between 55000 - 65000 £ per year.
A ServiceNow SecOps Engineer designs, implements, and optimizes security operations workflows within the ServiceNow platform. The role bridges security tooling and IT service management, enabling efficient incident response, vulnerability remediation, and threat intelligence handling through automation and orchestration. Working closely with SOC teams, this engineer ensures security events are actionable, traceable, and continuously improved.
Key Responsibilities
- Incident Response
- Configure and manage ServiceNow Security Incident Response (SIR) module
- Integrate SIEM tools (e.g., Splunk) for real-time alert ingestion
- Develop automated playbooks for triage, containment, and escalation
- Collaborate with SOC analysts to streamline response workflows
- Ensure proper documentation, tracking, and reporting of incidents
- Vulnerability Management
- Implement and maintain ServiceNow Vulnerability Response (VR)
- Integrate vulnerability scanners (e.g., Tenable, Qualys)
- Prioritize vulnerabilities using risk-based scoring models
- Automate remediation workflows and track SLA compliance
- Provide dashboards and reporting for security posture visibility
- Threat Intelligence
- Configure ServiceNow Threat Intelligence (TI) module
- Ingest and normalize threat feeds from external sources
- Correlate threat intelligence with incidents and vulnerabilities
- Support proactive threat hunting initiatives
- Maintain indicators of compromise (IOCs) and threat libraries
- Security Orchestration & Automation
- Design and implement workflows using ServiceNow Flow Designer and IntegrationHub
- Integrate endpoint security tools (e.g., CrowdStrike) and other security platforms
- Build orchestration playbooks to reduce manual intervention
- Continuously improve automation efficiency and coverage
- Ensure secure and scalable API integrations across systems
Required Skills & Experience
- Strong experience with ServiceNow SecOps modules (SIR, VR, TI)
- Hands-on integration experience with tools such as Splunk, CrowdStrike, Qualys, or Tenable
- Knowledge of security frameworks (e.g., NIST, ISO 27001)
- Experience with REST APIs, scripting (JavaScript), and automation tools
- Solid understanding of SOC operations and incident lifecycle
- Familiarity with cloud and endpoint security concepts
Preferred Qualifications
- ServiceNow Certified Implementation Specialist - Security Operations
- Experience with SOAR platforms and automation design
- Knowledge of threat intelligence frameworks (e.g., MITRE ATT&CK)
- Background in cybersecurity operations or engineering roles
LA International is an award-winning partner of choice for many of the world's most influential companies and government organisations. Holding Enhanced Government Security Accreditation, we are recognised as the European market leader in the delivery of Security Cleared talent to organisations that demand the very highest levels of security, compliance and assurance.
A multiple award-winning organisation, having secured the prestigious Queens Award for Enterprise: International Trade over consecutive years. We are committed to fostering an inclusive, equitable and accessible workplace where everyone feels valued and supported. We welcome applications from all individuals, regardless of background or identity, and we encourage candidates who may not meet every listed requirement to still apply. If you require any adjustments or support during the recruitment process, please let us know and we will work with you to ensure a fair and accessible experience.
Please Note: If a high volume of applications is received, only candidates shortlisted will be contacted.
ServiceNow SecOps Engineer: Automation & Incident Orchestration in City of Westminster employer: Onyx-Conseil
At LA International, we pride ourselves on being an award-winning employer that champions a culture of inclusivity and support. As a ServiceNow SecOps Engineer, you will thrive in a dynamic environment where your contributions directly impact security operations for leading global organisations. With a commitment to employee growth and development, we offer unique opportunities for professional advancement while ensuring a collaborative atmosphere that values every team member's input.
StudySmarter Expert Advice🤫
We think this is how you could land ServiceNow SecOps Engineer: Automation & Incident Orchestration in City of Westminster
✨Network Like a Pro
Get out there and connect with folks in the industry! Attend meetups, webinars, or even online forums related to ServiceNow and cybersecurity. You never know who might have the inside scoop on job openings or can refer you directly.
✨Show Off Your Skills
When you land an interview, don’t just talk about your experience—demonstrate it! Bring examples of your work, like automated playbooks or incident response workflows you've designed. This will show potential employers that you’re not just all talk.
✨Tailor Your Approach
Make sure to tailor your conversations and follow-ups to each company. Mention specific projects or tools they use, like Splunk or CrowdStrike, and how your experience aligns with their needs. This personal touch can really make you stand out!
✨Apply Through Our Website
Don’t forget to check out our website for the latest job openings! Applying directly through us not only shows your interest but also gives you a better chance of being noticed by our hiring team. Let’s get you that ServiceNow SecOps Engineer role!
We think you need these skills to ace ServiceNow SecOps Engineer: Automation & Incident Orchestration in City of Westminster
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience with ServiceNow SecOps modules and relevant tools. We want to see how your skills align with the role, so don’t hold back on showcasing your expertise!
Showcase Your Projects:If you've worked on any automation or incident orchestration projects, be sure to mention them! We love seeing real-world examples of how you've tackled challenges in security operations.
Be Clear and Concise:When writing your application, keep it straightforward. Use bullet points for key achievements and avoid jargon unless it's relevant. We appreciate clarity and want to understand your experience quickly!
Apply Through Our Website:Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it’s super easy!
How to prepare for a job interview at Onyx-Conseil
✨Know Your ServiceNow Inside Out
Make sure you’re well-versed in the ServiceNow SecOps modules, especially SIR, VR, and TI. Brush up on how these modules integrate with tools like Splunk and CrowdStrike, as this knowledge will be crucial during your interview.
✨Showcase Your Automation Skills
Prepare to discuss your experience with automation and orchestration. Bring examples of automated playbooks you've developed or workflows you've designed using ServiceNow Flow Designer. This will demonstrate your hands-on experience and problem-solving abilities.
✨Understand the Incident Lifecycle
Familiarise yourself with the incident response process and SOC operations. Be ready to explain how you’ve contributed to streamlining response workflows or improving incident tracking in previous roles. This shows you understand the bigger picture.
✨Be Ready for Technical Questions
Expect technical questions related to REST APIs, scripting, and security frameworks like NIST or ISO 27001. Brush up on these topics and prepare to discuss how you’ve applied them in real-world scenarios to showcase your expertise.