TOMORROW HIRE

ServiceNow Security Incident Response Lead

TOMORROW HIRE  •  $150k - $200k/yr  •  Morgantown, WV (Remote)  •  1 day ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Work Type: Hybrid, subject to final DOE direction
Location: Morgantown, WV
Salary: $150,000–$200,000 per year, based on experience
Employment Type: Full-Time W-2
Anticipated Period of Performance: September 1, 2026–July 12, 2027
Contract Status: Contingent upon contract award

Our client is seeking a hands-on ServiceNow Security Incident Response Lead to support a proposed Department of Energy engagement involving the implementation and configuration of ServiceNow Security Incident Response.

The selected professional will configure ServiceNow SIR, integrate security-alert sources, implement incident-response processes aligned with NIST and SANS frameworks, configure risk scoring and service-level agreements, develop playbooks, establish threat-intelligence feeds, and configure incident workspaces, reporting, and knowledge-management capabilities.

This is a senior, hands-on implementation position. Depending on the final team composition, one of the three ServiceNow professionals supporting the project may also assume broader Solution Architect responsibilities.

The anticipated start date is September 1, 2026, or as close to that date as possible.

Key Responsibilities

  • Install and configure the ServiceNow Security Incident Response plug-in.
  • Integrate Microsoft Azure Sentinel, Palo Alto Networks NGFW, and Splunk for alert ingestion.
  • Configure inbound email-ingestion rules for the creation of security incidents.
  • Configure groups, roles, and permissions for incident response.
  • Implement an SIR process aligned with NIST and SANS frameworks.
  • Configure two assignment and escalation rules.
  • Implement severity calculators and risk scoring to prioritize security incidents.
  • Configure up to three service-level agreements for security incidents.
  • Configure one post-incident review process.
  • Configure ServiceNow analysis tools.
  • Configure security tagging for access restriction.
  • Establish threat-intelligence feeds using STIX/TAXII sources.
  • Configure the ingestion of cyber-threat intelligence from email sources.
  • Configure out-of-the-box notifications and up to five additional customized notifications.
  • Configure two task playbooks of moderate complexity.
  • Establish a runbook knowledge base and import existing runbooks.
  • Configure SIR fields and workspaces.
  • Enable out-of-the-box reports and dashboards.
  • Create up to five additional SIR reports.
  • Configure the security-incident catalog.
  • Provide staff training and knowledge transfer.

Requirements

Minimum Qualifications

  • Minimum three years of ServiceNow implementation experience.
  • Minimum five years of software-development experience.
  • Minimum three years of ServiceNow architecture experience involving solution design, development, and customization.
  • Minimum three years of ServiceNow Security Incident Response experience.
  • Minimum three years of experience integrating ServiceNow with Microsoft Azure Sentinel, Splunk, or Palo Alto Networks NGFW.
  • Minimum three years of experience configuring threat-intelligence feeds.
  • Minimum three years of experience configuring ServiceNow SIR fields and workspaces.
  • Minimum three years of experience configuring security-incident catalogs, reports, or dashboards.
  • Hands-on experience implementing and configuring ServiceNow solutions.
  • Current ServiceNow certification.
  • Must be a U.S. citizen due to federal contract requirements.
  • Must be willing and able to complete applicable background screening and DOE badging requirements.
  • Must be prepared for onsite presence in Morgantown, West Virginia, if required by DOE.

Preferred Qualifications

  • Bachelor’s degree.
  • Previous federal government or Department of Energy experience.
  • Ability to commute to Morgantown, WV.

Benefits

Compensation

$150,000–$200,000 per year, based on experience and contingent upon contract award.

Benefits

  • Medical insurance
  • Dental insurance
  • Vision insurance
  • 401(k)
  • Unpaid sick leave and personal time off in accordance with company policy

Work Location

This position is being recruited as hybrid while final work-location guidance is pending from DOE.

Candidates should be prepared for onsite work in Morgantown, West Virginia The final onsite schedule and remote-work availability will be based on DOE requirements and cannot be guaranteed at this stage.

Security and Citizenship Requirements

Applicants must be U.S. citizens due to federal contract requirements.

No active security-clearance level is currently specified. Selected personnel must successfully complete applicable background screening and DOE identity-verification and badging requirements. Additional access requirements may be established by the DOE Contracting Officer.

Contract Contingency

This position supports an active proposal and is contingent upon contract award. The anticipated period of performance is September 1, 2026 through July 12, 2027. The anticipated start date and work arrangement remain subject to contract award and final DOE direction.

TOMORROW HIRE

About TOMORROW HIRE

Welcome to Tomorrow Hire, where we are transforming the staffing landscape. Our approach combines the precision of AI with the nuanced understanding of our human experts to create unmatched staffing solutions. Whether you are looking for contract, permanent, or contract-to-permanent placements, we strive to make every hire the perfect fit for your organization's needs.

Industry
HR & Recruiting
Company Size
Unknown
Headquarters
Great Falls, VA
Year Founded
2024
Social Media