It all started when engineer Fred Luddy wrote code that automated a tedious task for his coworker, Phyllis. She cried tears of joy. That moment inspired Fred to build a company that could do that for everyone—freeing people from busywork so they could focus on meaningful work. Today, ServiceNow is the AI control tower for business reinvention. Our ServiceNow AI platform brings together any AI, any data, and any workflow— helping 85% of the Fortune 500® work smarter, faster, and better. We're building an AI-native culture where technology and talent are unstoppable together. And we're just getting started.
Join us to put AI to work for people.
Job Description
Armis is the leading unified asset visibility and cybersecurity intelligence platform — trusted by Fortune 100 enterprises and governments to protect unmanaged, IoT, OT, and IT environments.
Our AI-powered Armis Centrix™ platform delivers real-time asset intelligence to secure the unseen — enabling organizations to understand their entire attack surface and act fast against emerging threats.
We are expanding our Vulnerability Intelligence, Prioritization & Detection Response (VIPR/VMDR) capability to elevate Armis’ cyber defense posture globally.
This role will lead the integration of vulnerability discovery, detection, intelligence enrichment, prioritization, and coordinated response into a unified, high-impact customer program across APJ/APAC.
Role Overview
The VIPR & VMDR Expert serves as an architect,, strategic analyst and technical operator — combining vulnerability lifecycle management with exploit intelligence, detection automation, and cross-functional coordination (ITSM).
You’ll lead how Armis detects, prioritizes, and responds to vulnerabilities across customer environments, infrastructure, SaaS ecosystems, and the Armis platform — ensuring our customers stay ahead of emerging exploits, threats, and exposures.
Key Responsibilities
Own the end-to-end vulnerability and detection lifecycle — from discovery, triage, and prioritization through remediation and reporting.
Lead the Vulnerability Intelligence, Prioritization & Detection Response (VIPR/VMDR) function, integrating threat intel, exploit data, and asset context to drive data-backed decisions.
Correlate internal vulnerability telemetry with external feeds (NVD, CISA KEV, EPSS, Mandiant, Shodan, VulnDB, Centrix for Early Warning) to assess exploitability and exposure.
Operate and tune vulnerability and detection tools (e.g., Tenable, Qualys, Rapid7, Wiz, Prisma Cloud, ServiceNow VR) across hybrid customer environments.
Automate vulnerability scoring, detection correlation, and reporting pipelines using Python, PowerShell, REST APIs, or automation rules within AMS/VIPR.
Partner with Customer Success, Security Engineering, and Cloud Infrastructure teams to track remediation SLAs, exposure metrics, and MTTR improvements.
Build and publish risk dashboards, customer-facing reports, and executive briefings using Splunk, Power BI, Elastic, or AMS/VIPR.
Develop and maintain the Armis Vulnerability Prioritization Model (VPM) — aligning exploit intelligence, CVSS/EPSS scoring, Armis Proprietary Risk Scoring, and business criticality to guide customer risk posture.
Support penetration test remediation, red team findings, and customer security audits.
Author weekly vulnerability intelligence reports, zero-day summaries, and leadership briefings for APJ/APAC stakeholders.
Collaborate with Product Security and Threat Intelligence teams to integrate vulnerability and detection data into Armis platform insights.
Deliver training sessions and enablement workshops for customers, engineers, and analysts on vulnerability trends, tools, and operational best practices.
6–10+ years of experience in Vulnerability Management, Threat Intelligence, or Security Detection Engineering.
Deep expertise in CVSS, CWE/CVE, NVD, KEV, and exploit prediction (EPSS) frameworks.
Hands-on experience with vulnerability and detection management platforms (Tenable, Qualys, Rapid7, Wiz, Prisma Cloud, ServiceNow VR, Centrix for VMDR).
Proven ability to develop automation scripts and data pipelines (Python, PowerShell, Bash, REST APIs, JSON).
Familiarity with risk-based vulnerability management (RBVM) and prioritization scoring models.
Strong understanding of cloud-native security, container scanning, and hybrid infrastructure (AWS, Azure, GCP).
Exceptional data storytelling skills — turning technical findings into actionable executive insights.
Demonstrated ability to work independently and as part of a team.
Exceptional communication skills across all levels of technical, middle management, and executive leadership personnel.
Bachelor’s or Master’s degree in Information Security, Computer Science, or related discipline.
Previous experience operating in a "Voice of the Customer" (VoC) technical role directly embedded with Product Engineering pods.
A track record of mentoring senior technical staff (TCMs, TAMs, or Solutions Engineers) and developing scalable knowledge-sharing frameworks.
Preferred Experience
Prior experience in enterprise SaaS, cybersecurity, or customer-facing technical programs.
Familiarity with Armis Centrix™ or similar asset intelligence and exposure management tools.
Certifications such as CISSP, GCCC, GCTI, CEH, or CySA+.
Experience supporting compliance frameworks (SOC 2, ISO 27001, FedRAMP) in enterprise environments.
Strong cross-cultural communication and collaboration skills across global and regional teams (APJ/APAC).
Work Personas
We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here. To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.
Equal Opportunity Employer
ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, age, disability, gender identity, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.
Accommodations
We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact [email protected] for assistance.
Export Control Regulations
For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.
From Fortune. ©2026 Fortune Media IP Limited. All rights reserved. Used under license.
ServiceNow Dublin, Leinster, IRL Office
60 Dawson St, Dublin, Leinster, Ireland, D02 K330

