Important: ServiceNow SIR certification is mandatory for this role. Candidates who do not hold a current, relevant ServiceNow SIR/Security Incident Response certification cannot be considered.
ServiceNow Security Incident Response (SIR) Engineer - Contract
£700 per day | Initial 6 months | Major Cyber Security Programme
We are looking for a specialist ServiceNow Security Incident Response Engineer to join a major enterprise cyber security programme and help build, automate and strengthen its security incident response capability.
This is not a general ServiceNow development role. We need someone who genuinely specialises in ServiceNow Security Operations and Security Incident Response, who can work directly with SOC and Cyber Incident Response teams to turn operational security requirements into effective, automated workflows.
Important: ServiceNow SIR certification is mandatory for this role. Candidates who do not hold a current, relevant ServiceNow SIR/Security Incident Response certification cannot be considered.
The opportunity
You will work at the intersection of ServiceNow engineering, SecOps and cyber incident response, taking responsibility for designing, configuring and enhancing ServiceNow SIR across the end-to-end security incident life cycle.
The focus is on using ServiceNow SIR to make security operations faster, more automated and more effective - improving how incidents are detected, enriched, prioritised, investigated, escalated and ultimately resolved.
You will:
Design, configure and enhance ServiceNow Security Incident Response (SIR)
Build and optimise workflows covering triage, investigation, containment, remediation, recovery and closure
Automate security incident processes to reduce manual intervention and accelerate response
Integrate SIR with SIEM, SOAR, EDR and other enterprise cyber security technologies
Configure alert and incident ingestion, enrichment, categorisation, prioritisation, assignment and escalation
Work directly with SOC analysts and Incident Response teams to understand operational requirements
Translate those requirements into practical ServiceNow workflows and automation
Identify opportunities to improve incident response through orchestration and process automation
Troubleshoot complex SIR configuration, integration and workflow issues
Produce appropriate technical documentation and support the operational handover of new capabilities
What you MUST have
Current, relevant ServiceNow SIR/Security Incident Response certification - this is mandatory
Strong hands-on ServiceNow Security Incident Response implementation experience
Experience configuring and engineering SIR, rather than simply using ServiceNow as an end user
Strong understanding of the cyber security incident response life cycle
Experience designing security incident workflows within ServiceNow
Experience integrating ServiceNow with third-party cyber security platforms
Strong workflow automation and orchestration experience
Ability to work effectively with SOC, Incident Response, Cyber Engineering and ServiceNow teams
Excellent troubleshooting, problem-solving and stakeholder communication skills
It would be great if you also have
Broader ServiceNow Security Operations/SecOps experience
Integration experience across SIEM, SOAR, EDR and security monitoring platforms
ServiceNow Scripting and development experience
Experience within large-scale, complex or regulated enterprise environments
Financial services or banking cyber security experience
Who we're looking for
We are specifically looking for a ServiceNow SIR specialist - not a general ServiceNow Developer who has occasionally worked around security.
If you are SIR certified and have personally designed, configured and implemented ServiceNow Security Incident Response within a complex cyber security environment, we would be very interested in speaking with you.
No SIR certification = unfortunately, no consideration for this particular role.