SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
ServiceNow is seeking a Solution Architect to lead the expansion of its Vulnerability Intelligence, Prioritization & Detection Response (VIPR/VMDR) capability across EMEA. This role combines vulnerability lifecycle management with exploit intelligence, detection automation, and cross-functional coordination to help customers detect, prioritize, and respond to vulnerabilities across their environments.
You will own the end-to-end vulnerability and detection lifecycle—from discovery and triage through remediation and reporting. Key responsibilities include:
• Leading the VIPR/VMDR function by integrating threat intelligence, exploit data, and asset context to drive data-backed security decisions
• Correlating internal vulnerability telemetry with external feeds (NVD, CISA KEV, EPSS, Mandiant, Shodan, VulnDB, Centrix) to assess exploitability and exposure
• Operating and tuning vulnerability and detection tools (Tenable, Qualys, Rapid7, Wiz, Prisma Cloud, ServiceNow VR) across hybrid customer environments
• Automating vulnerability scoring, detection correlation, and reporting pipelines using Python, PowerShell, REST APIs, or automation rules
• Partnering with Customer Success, Security Engineering, and Cloud Infrastructure teams to track remediation SLAs and MTTR improvements
• Building and publishing risk dashboards, customer-facing reports, and executive briefings using Splunk, Power BI, or Elastic
• Developing and maintaining the Armis Vulnerability Prioritization Model, aligning exploit intelligence with CVSS/EPSS scoring and business criticality
• Supporting penetration test remediation, red team findings, and security audits
• Authoring weekly vulnerability intelligence reports and zero-day summaries for leadership
• Collaborating with Product Security and Threat Intelligence teams to integrate vulnerability data into platform insights
• Delivering training sessions and enablement workshops for customers and internal teams
This is a strategic technical role requiring deep expertise in vulnerability management, threat intelligence, and security detection engineering. You will work independently and as part of a global team, translating complex technical findings into actionable executive insights.
REQUIREMENTS:
• 6–10+ years of experience in Vulnerability Management, Threat Intelligence, or Security Detection Engineering
• Deep expertise in CVSS, CWE/CVE, NVD, KEV, and exploit prediction (EPSS) frameworks
• Hands-on experience with vulnerability and detection management platforms (Tenable, Qualys, Rapid7, Wiz, Prisma Cloud, ServiceNow VR, Centrix)
• Proven ability to develop automation scripts and data pipelines (Python, PowerShell, Bash, REST APIs, JSON)
• Familiarity with risk-based vulnerability management (RBVM) and prioritization scoring models
• Strong understanding of cloud-native security, container scanning, and hybrid infrastructure (AWS, Azure, GCP)
• Exceptional data storytelling skills—turning technical findings into actionable executive insights
• Demonstrated ability to work independently and collaboratively
• Exceptional communication skills across technical, middle management, and executive levels
• Bachelor's or Master's degree in Information Security, Computer Science, or related discipline
• Previous experience in a "Voice of the Customer" (VoC) technical role embedded with Product Engineering
• Track record of mentoring senior technical staff (TCMs, TAMs, Solutions Engineers) and developing scalable knowledge-sharing frameworks
PREFERRED:
• Prior experience in enterprise SaaS or cybersecurity customer-facing technical programs
• Familiarity with Armis Centrix™ or similar asset intelligence and exposure management tools
• Certifications: CISSP, GCCC, GCTI, CEH, or CySA+
• Experience supporting compliance frameworks (SOC 2, ISO 27001, FedRAMP)
• Strong cross-cultural communication and collaboration skills across global and regional teams