Lead Consultant VRM

Greater London

  ServiceNow - Consultant

0

Contract

Our client, a specialist IT consultancy, is hiring a Lead VRM Consultant to join their team in London on a contract basis. The successful candidate will develop practical ServiceNow solutions that address security requirements, helping enterprise organizations strengthen vulnerability management, speed up remediation and build greater cyber resilience.

Responsibilities

  • Implement and configure ServiceNow Vulnerability Response and Security Incident Response, including VR groups, remediation rulesets and risk scoring informed by CMDB data.

  • Connect vulnerability scanners, such as Tenable Nessus, and patching tools, including Tanium, Ansible and Microsoft Intune/MCM, with ServiceNow.

  • Turn vulnerability management priorities into effective platform rules, automated workflows and clear remediation targets.

  • Enable rapid patching of newly disclosed vulnerabilities and improve remediation timelines across legacy infrastructure.

  • Collaborate with client security and platform teams to clarify requirements, challenge assumptions and propose practical solutions.

  • Deliver pilots, MVPs and phased implementations, keeping scope focused and delivery priorities on track.

  • Create clear high-level designs, technical documentation and user acceptance testing summaries.

Skillset

  • Extensive hands-on experience with ServiceNow Vulnerability Response and/or Security Incident Response, alongside familiarity with Unified Security Exposure Management (USEM).

  • ServiceNow CSA, CIS-VR, an equivalent USEM/Security Operations qualification and/or relevant ITOM/CMDB certifications.

  • A strong understanding of the broader ServiceNow platform, including CMDB, ITOM, ITSM, REST APIs and IntegrationHub.

  • Experience working with CI matching, service mapping, Incident Management and Change Management.

  • Proven ability to integrate vulnerability scanning platforms and patch deployment or orchestration tools with ServiceNow.

  • Solid knowledge of vulnerability management principles, including known exploited vulnerabilities (KEVs), CVSS/VPR scoring, exploitability, blast radius and remediation governed by SLAs and OLAs.

  • Experience managing the technical and operational challenges of urgent patch deployment at scale within complex enterprise environments.

  • A consultative mindset, with the ability to evaluate options, communicate trade-offs and establish trust with client stakeholders.

  • A track record of delivering pilots, MVPs or phased implementations.

  • Clear written and verbal communication skills, with the ability to explain technical information to both technical and non-technical audiences.

related jobs