Job DescriptionThe Global Incident Response (GIR) team consists of 4 units: Triage, Incident Response, Threat Hunting and Insider Threat Program. You will be joining the Triage team as an Information Security Analyst monitoring the tools and systems that defend ServiceNow's production and corporate environment.Global Triage team is responsible to provide 24x7x365 continuous monitoring of correlated security event feeds and the appropriate triage and escalation in case of an identified security incident.Triage team is the primary contact for any suspected security incident and works together with the Incident Response team on resolving incidents and remediating threats across Servicenow enterpriseDefine relationships between seemingly unrelated events through deductive reasoning, come up with ways to do things faster, better and more effectively while maintaining a laser focus on quality.You will work on a geographically diverse team to respond to threats that may arise against our infrastructure, and track incidents to closure, working across functional teams.You may be called upon to assist with the deployment, integration and initial configuration of new security solutions or enhancements to existing security solutions; including network, and systems to improve overall platform security.The Incident Response Analyst must able to work outside of normal business hours (evening/weekend shifts, holidays) as needed.
You will be required to engage an escalation point of contact in the On-Call rotation, to ensure that Global Incident Response team can respond to priority incidents in a timely manner, and must be willing to work weekend shift and hours outside of standard business hours, if necessary.QualificationsTo be successful in this role you have:Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving.
This may include using AI-powered tools, automating workflows, analyzing AI-driven insights, or exploring AI's potential impact on the function or industry years related experience or equivalent combination of education and experienceDeep understanding of Security Operations Center and Security Incident Response Team protocols and proceduresA solid foundation in networking fundamentals, with a deep understanding of TCP/IP and other core protocolsBackground working with data logging applications (e.g.
Splunk)Knowledge of internet security protocols and technologiesThe ability to analyze event and systems logs, perform forensic analysis (good to have), analyze malware, and other incident response related data, as neededFamiliarity with intrusion detection systems and different layers of defense across Endpoint, Email & Network level layersKnowledge of latest attack vectors, threat tactics and attacker techniques targeting SaaS companiesUnderstanding of Windows and Linux operating systems and command line toolsEnterprise level analysis and defense experience are a plusWillingness to work in weekend shift (no night shifts
)CompTIA Security+, GSEC, CEH (Practical) certifications are good to have Not sure if you meet every qualification?
We still encourage you to apply
We value inclusivity, welcoming candidates from diverse backgrounds, including non-traditional paths.
Unique experiences enrich our team, and the willingness to dream big makes you an exceptional candidateAdditional InformationWork PersonasWe approach our distributed world of work with flexibility and trust.
Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work. Learn more here.Equal Opportunity EmployerServiceNow is an equal opportunity employer.
All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status, or any other category protected by law.
In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements. AccommodationsWe strive to create an accessible and inclusive experience for all candidates.
If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact ****** for assistance. Export Control RegulationsFor positions requiring access to controlled technology subject to export control regulations, including the U.S.
Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals.
All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities. From Fortune.
2024 Fortune Media IP Limited.
All rights reserved.
Used under license.