Cloudrho
ServiceNow Vulnerability Response (VR) Engineer
About This Role
Role Summary The Vulnerability Response Engineer will be responsible for implementing, configuring, and supporting ServiceNow Vulnerability Response solutions while driving vulnerability lifecycle management, remediation workflows, integrations with security tools, and operational support activities. The ideal candidate will possess strong expertise in vulnerability management processes, ServiceNow SecOps capabilities, security tool integrations, and IT Operations Management (ITOM) concepts including CMDB, Discovery, Service Mapping, and asset lifecycle management. The role will be responsible for enabling risk-based vulnerability remediation by leveraging accurate asset intelligence, business service context, and automated workflows while supporting enterprise security and operational excellence initiatives. Experience 5–6 years IT experience 3+ years ServiceNow Security Operations experience
Key Responsibilities
ServiceNow VR Engineering Configure Vulnerability Response applications. Develop remediation workflows. Manage vulnerability groups and assignment rules. Configure risk scoring models. Security Operations Manage vulnerability lifecycle. Support remediation tracking. Coordinate with infrastructure and security teams. Conduct vulnerability analysis and prioritization. ITOM & Asset Context Management Collaborate with ITOM teams to: Leverage CMDB data for vulnerability prioritization. Validate CI relationships and service dependencies. Improve vulnerability correlation against Configuration Items (CIs). Ensure discovered assets are properly mapped to vulnerability findings. Support business service-aware remediation activities.
Work closely with: CMDB teams Discovery teams Infrastructure Operations Application Support Teams ServiceNow ITOM Knowledge Strong functional understanding of: CMDB Discovery Service Mapping Event Management (preferred) Configuration Management Ability to understand how vulnerability findings relate to infrastructure assets and business services. Integrations Qualys Tenable Rapid7 Microsoft Defender CrowdStrike Operational
Responsibilities
Incident support Root cause investigations Process optimization KPI reporting Governance SLA monitoring Risk management Compliance reporting
Requirements
Mandatory Skills ServiceNow SecOps Vulnerability Response Security Operations Workflow Configuration Flow Designer Security Vulnerability Management CVSS Risk Assessment Security Operations Processes Integration Experience Qualys Tenable Rapid7
Preferred Skills
SIR Threat Intelligence GRC ITOM CMDB Discovery
Certifications
Mandatory: CSA
Preferred
CIS-Vulnerability Response Security+ ITIL Foundation