Security Incident Response (ServiceNow SIR) Engineer
Important: ServiceNow SIR certification is mandatory for this role. Candidates who do not hold a current, relevant ServiceNow SIR/Security Incident Response certification cannot be considered.
ServiceNow Security Incident Response (SIR) Engineer - Contract
£700 per day | Initial 6 months | Major Cyber Security Programme
We are looking for a specialist ServiceNow Security Incident Response Engineer to join a major enterprise cyber security programme and help build, automate and strengthen its security incident response capability.
This is not a general ServiceNow development role. We need someone who genuinely specialises in ServiceNow Security Operations and Security Incident Response, who can work directly with SOC and Cyber Incident Response teams to turn operational security requirements into effective, automated workflows.
Important: ServiceNow SIR certification is mandatory for this role. Candidates who do not hold a current, relevant ServiceNow SIR/Security Incident Response certification cannot be considered.
The opportunity
You will work at the intersection of ServiceNow engineering, SecOps and cyber incident response, taking responsibility for designing, configuring and enhancing ServiceNow SIR across the end-to-end security incident life cycle.
The focus is on using ServiceNow SIR to make security operations faster, more automated and more effective - improving how incidents are detected, enriched, prioritised, investigated, escalated and ultimately resolved.
You will:
-
Design, configure and enhance ServiceNow Security Incident Response (SIR)
-
Build and optimise workflows covering triage, investigation, containment, remediation, recovery and closure
-
Automate security incident processes to reduce manual intervention and accelerate response
-
Integrate SIR with SIEM, SOAR, EDR and other enterprise cyber security technologies
-
Configure alert and incident ingestion, enrichment, categorisation, prioritisation, assignment and escalation
-
Work directly with SOC analysts and Incident Response teams to understand operational requirements
-
Translate those requirements into practical ServiceNow workflows and automation
-
Identify opportunities to improve incident response through orchestration and process automation
-
Troubleshoot complex SIR configuration, integration and workflow issues
-
Produce appropriate technical documentation and support the operational handover of new capabilities
What you MUST have
-
Current, relevant ServiceNow SIR/Security Incident Response certification - this is mandatory
-
Strong hands-on ServiceNow Security Incident Response implementation experience
-
Experience configuring and engineering SIR, rather than simply using ServiceNow as an end user
-
Strong understanding of the cyber security incident response life cycle
-
Experience designing security incident workflows within ServiceNow
-
Experience integrating ServiceNow with third-party cyber security platforms
-
Strong workflow automation and orchestration experience
-
Ability to work effectively with SOC, Incident Response, Cyber Engineering and ServiceNow teams
-
Excellent troubleshooting, problem-solving and stakeholder communication skills
It would be great if you also have
-
Broader ServiceNow Security Operations/SecOps experience
-
Integration experience across SIEM, SOAR, EDR and security monitoring platforms
-
ServiceNow Scripting and development experience
-
Experience within large-scale, complex or regulated enterprise environments
-
Financial services or banking cyber security experience
Who we're looking for
We are specifically looking for a ServiceNow SIR specialist - not a general ServiceNow Developer who has occasionally worked around security.
If you are SIR certified and have personally designed, configured and implemented ServiceNow Security Incident Response within a complex cyber security environment, we would be very interested in speaking with you.
No SIR certification = unfortunately, no consideration for this particular role.