ServiceNow SIR Engineer
ServiceNow Security Incident Response (SIR) Engineer - Contract
Contract: Initial contract engagement
Rate: £700 per/day
Specialism: ServiceNow SIR | SecOps | Cyber Security | Incident Response
(Remote working)
We are looking for an experienced ServiceNow Security Incident Response (SIR) Engineer to join a major cyber security programme, helping to strengthen and automate the organisation's security incident response capability.
Please note: Hands-on ServiceNow Security Incident Response (SIR) experience is an absolute requirement for this role. This is NOT a general ServiceNow Developer/Engineer position. Applicants without demonstrable ServiceNow SIR experience will not be considered.
The Role
Working at the intersection of ServiceNow engineering and cyber security operations, you will help design, configure, enhance and integrate ServiceNow SIR to support the end-to-end security incident life cycle - from initial detection and analysis through containment, remediation and recovery.
You will work closely with SOC, Cyber Security, Incident Response and ServiceNow teams to ensure security incidents are captured, prioritised and managed through effective, automated workflows.
Responsibilities will include:
-
Configure, develop and enhance ServiceNow Security Incident Response (SIR) capabilities.
-
Design and optimise security incident workflows covering detection, triage, investigation, containment, remediation and closure.
-
Develop automation to accelerate incident handling and reduce manual intervention.
-
Integrate ServiceNow SIR with third-party cyber security technologies and data sources.
-
Configure incident prioritisation, categorisation, assignment and escalation processes.
-
Support the ingestion and enrichment of security alerts and incidents within ServiceNow.
-
Work closely with SOC and Cyber Incident Response teams to translate operational requirements into effective ServiceNow workflows.
-
Identify opportunities to improve security response through workflow automation and orchestration.
-
Troubleshoot SIR configuration, integration and workflow issues.
-
Ensure appropriate documentation, governance and operational handover of implemented capabilities.
Essential Experience
To be considered, you MUST have:
-
Strong, demonstrable hands-on experience with ServiceNow Security Incident Response (SIR).
-
Experience configuring and implementing SIR rather than simply using ServiceNow as an end user.
-
Good understanding of the cyber security incident response life cycle.
-
Experience designing and configuring security incident workflows within ServiceNow.
-
Experience integrating ServiceNow with third-party cyber security platforms and tools.
-
Strong understanding of workflow automation and incident orchestration.
-
Ability to work effectively with SOC analysts, security engineers, incident responders and ServiceNow specialists.
-
Strong problem-solving and troubleshooting capability.
-
Excellent stakeholder communication skills.
Highly Desirable
-
ServiceNow SIR/Security Operations certification.
-
Broader ServiceNow Security Operations (SecOps) experience.
-
Experience integrating SIR with SIEM, SOAR, EDR or other security monitoring technologies.
-
ServiceNow Scripting and development experience.
-
Experience working within large, complex or regulated enterprise environments.
-
Previous experience delivering ServiceNow security capabilities within financial services would be advantageous.
The Key Requirement
We want to be extremely clear about the profile required:
You must be a ServiceNow Engineer/Consultant with genuine hands-on ServiceNow Security Incident Response (SIR) implementation experience.
General ServiceNow ITSM, ITOM, CSM or platform development experience without SIR experience will not be sufficient.
If you have designed, configured and implemented ServiceNow SIR within a complex enterprise cyber security environment, we would be very interested in speaking with you.