About this role
Salary: £? - ? per year
Requirements: Strong experience implementing and configuring ServiceNow Security Incident Response (SIR).Expertise across ServiceNow Security Operations (SecOps).Experience integrating ServiceNow with SIEM, SOAR, and Threat Intelligence platforms.Strong knowledge of ITSM, including Incident, Change, and Problem Management.Experience designing and automating security workflows and incident response processes.Strong dashboard, reporting, and analytics capabilities within ServiceNow.Excellent stakeholder management, documentation, and knowledge transfer skills.ServiceNow SIR/SecOps certifications are desirable.SC Cleared / BPSS. Responsibilities: Design and configure end-to-end Security Incident Response workflows.Build workflows covering incident triage, escalation, investigation, and case management.Develop evidence management processes and structured incident lifecycles.Align workflows with Cyber Operations requirements, industry best practice, and NCSC-aligned incident response processes.Test, refine, and optimise workflows to improve operational efficiency.Support the design, implementation, and optimisation of a Security Incident Response capability for a Cyber Security Operations Centre.Enhance cyber incident management processes and automate security workflows.Integrate ServiceNow Security Operations with wider security tooling. Technologies: SupportITSMSecurityServiceNow More:
We are a highly reputable corporation hiring an experienced ServiceNow Security Incident Response (SIR) Consultant for a 6-month contract, likely to extend, on a hybrid working basis. This is an outside IR35 / LTD engagement paying £700 per day. You will join a high-profile cyber security programme where you will have a direct impact on strengthening our incident response capability, improving automation, and helping shape the future Security Operations environment.
last updated 29 week of 2026