Role description
Job Description – Senior ServiceNow Developer Focus: ITSM, Security Incident Response (SIR), Unified Security Exposure Management (USEM), Integrated Risk Management (IRM), and Integrations Role Summary The Senior ServiceNow Developer will design, build, and maintain solutions across IT Service Management (ITSM), the ServiceNow Security Operations suite — Security Incident Response (SIR) and Unified Security Exposure Management (USEM) — and Integrated Risk Management (IRM), with a strong emphasis on enterprise integrations. The candidate should have a deep background in ServiceNow development and customization and a proven ability to deliver secure, scalable solutions that connect service management, security operations, and risk processes with the wider enterprise tool landscape (SIEM/EDR, vulnerability scanners, threat intelligence, and GRC data sources). This role requires strong hands-on scripting, integration engineering, and platform-governance skills, and the judgement to protect sensitive security and risk data through robust access controls. Key Responsibilities Lead the design, development, and implementation of ITSM solutions, including Incident, Problem, Change, and Request Management, Service Catalog items, workflows, SLAs/OLAs, and request-fulfilment processes. Configure and extend Security Incident Response (SIR), including the security incident lifecycle, response playbooks and Flow Designer flows, automated enrichment, and analyst workspaces, aligned to frameworks such as MITRE ATT&CK. Build integrations that create and enrich security incidents from SIEM, EDR, threat-intelligence, and other security tooling, and orchestrate automated response actions. Implement and extend Unified Security Exposure Management (USEM) — ServiceNow's unified vulnerability and security-exposure management capability — including ingestion and normalization of findings from vulnerability scanners and security tools, risk- and business-context-based exposure prioritization, correlation of exposures to CIs and assets via the CMDB, and orchestration of remediation workflows. Design and maintain exposure and vulnerability dashboards, posture metrics, and reporting for security, IT, and operations stakeholders. Develop and configure Integrated Risk Management (IRM/GRC), including Policy and Compliance Management, Risk Management, Audit Management, and third-party/vendor risk, with automated controls, attestations, evidence collection, and issue/remediation workflows. Architect, develop, and maintain enterprise integrations using REST, SOAP, IntegrationHub (flows, actions, spokes, and ETL), MID Server, Service Graph Connectors, import sets, transform maps, and scripted REST APIs, with robust authentication, error-handling, and reconciliation. Integrate ServiceNow with security, risk, and IT tooling — including SIEM/EDR, vulnerability scanners, threat-intelligence platforms, identity providers, and GRC/regulatory data sources. Create and maintain business rules, Script Includes, client scripts, UI policies, data policies, and Flow Designer flows across all in-scope applications. Implement and govern security controls — ACLs, roles, and data segregation — with particular care for sensitive security-operations and risk data. Collaborate with security, risk, IT, and business stakeholders to gather requirements and translate them into scalable technical designs. Monitor and optimize platform performance, scalability, maintainability, and upgrade readiness. Provide technical leadership, code reviews, design assurance, and mentorship to developers and administrators. Stay current with ServiceNow releases and best practices across ITSM, Security Operations, IRM, and integrations, and continuously improve the platform. Required Skills Bachelor's degree in Computer Science, Information Technology, Engineering, or a related field. 5+ years of hands-on experience in ServiceNow development and administration, including enterprise-scale delivery. Strong proficiency in JavaScript, Glide APIs, HTML, CSS, XML, and ServiceNow scripting and configuration. Strong hands-on experience with ServiceNow ITSM (Incident, Problem, Change, Request, Service Catalog, workflows, and SLAs). Hands-on experience with ServiceNow Security Operations, including Security Incident Response (SIR) and vulnerability/exposure management via Unified Security Exposure Management (USEM) or its predecessor, Vulnerability Response. Experience with Integrated Risk Management (IRM/GRC), including policy and compliance, risk, audit, and control automation. Deep, hands-on experience building ServiceNow integrations using REST, SOAP, IntegrationHub, MID Server, scripted REST APIs, and other integration mechanisms, including integrations with security and GRC tooling. Solid understanding of security-operations concepts (vulnerability and exposure management, security incident response, MITRE ATT&CK) and risk/compliance frameworks. Strong understanding of ServiceNow access controls — ACLs, roles, and data segregation — applied to sensitive security and risk data. Proven experience developing and implementing scoped or custom applications on the ServiceNow platform. Excellent problem-solving skills and the ability to troubleshoot complex platform and integration issues. Strong communication and stakeholder-management skills, with the ability to work effectively across security, risk, IT, and business teams. ServiceNow Certified System Administrator (CSA) and Certified Application Developer (CAD), or equivalent demonstrable platform expertise. Preferred Skills Relevant ServiceNow implementation certifications, such as CIS – Security Incident Response, CIS – Vulnerability Response, CIS – Risk and Compliance, and CIS – ITSM (or the current Security Operations and IRM equivalents). Familiarity with security frameworks and standards such as MITRE ATT&CK, NIST, and ISO 27001, and with regulatory/compliance content used in IRM. Experience with Service Graph Connectors, IntegrationHub ETL, and multi-source data ingestion. Experience integrating SIEM/EDR platforms (e.g., Splunk, Microsoft Sentinel, CrowdStrike) and vulnerability scanners (e.g., Qualys, Tenable, Rapid7). Experience with Agile delivery methodologies, DevOps practices, CI/CD, source control, and ServiceNow application deployment. Familiarity with cloud services and infrastructure (e.g., AWS, Azure). Understanding of the ITIL framework and IT service management best practices. Experience with ServiceNow low-code/no-code capabilities, including Flow Designer, App Engine Studio, and UI Builder.
Skills
ServiceNow, Incident Response, GRC
About UST
UST is a global digital transformation solutions provider. For more than 20 years, UST has worked side by side with the world’s best companies to make a real impact through transformation. Powered by technology, inspired by people and led by purpose, UST partners with their clients from design to operation. With deep domain expertise and a future-proof philosophy, UST embeds innovation and agility into their clients’ organizations. With over 30,000 employees in 30 countries, UST builds for boundless impact—touching billions of lives in the process.