It all started when engineer Fred Luddy wrote code that automated a tedious task for his coworker, Phyllis. She cried tears of joy. That moment inspired Fred to build a company that could do that for everyone—freeing people from busywork so they could focus on meaningful work. Today, ServiceNow is the AI control tower for business reinvention. Our ServiceNow AI platform brings together any AI, any data, and any workflow— helping 85% of the Fortune 500® work smarter, faster, and better. We're building an AI-native culture where technology and talent are unstoppable together. And we're just getting started.
Join us to put AI to work for people.
Job Description
As an OT Expert, you will serve as the subject matter expert (SME) for OT cyber visibility, architecture, and governance. You’ll lead asset discovery, segmentation strategy, and integration of monitoring platforms across complex ICS environments. This is a client-facing role, engaging with multiple customers to enhance their OT security posture and demonstrate the business value of risk reduction.
You’ll work closely with infrastructure, compliance, product, and field teams to implement security best practices aligned to IEC 62443, NIST CSF, and CPwE frameworks.
Key Responsibilities
Lead the deployment, configuration, and tuning of OT security platforms across customer ICS environments.
Support TCSM teams with value delivery, operationalizing OT visibility solutions within the context of customer business priorities.
Drive asset inventory accuracy, passive discovery strategies, and enriched contextual mapping for PLCs, HMIs, and SCADA systems.
Align segmentation and network architecture to industry standards such as IEC 62443, CPwE, and NIST CSF 2.0.
Partner with internal and client-side IT/OT teams to facilitate patching, firmware updates, and configuration hardening across industrial assets.
Provide architectural input and hands-on guidance on OT threat detection, alert tuning, and event correlation via integration with SIEM and SOC tools.
Build dashboards, KPIs, and reports showcasing asset risk, segmentation posture, and threat trends across OT networks.
Lead OT-focused workshops, risk reviews, and client advisory sessions to promote awareness and maturity of ICS security programs.
Continuously assess the effectiveness of OT tools and advocate improvements via vendor and internal engineering collaboration.
Support compliance efforts (e.g., NERC CIP, ISA/IEC 62443, NIST 800-82) by generating asset visibility reports and vulnerability context.
Collaborate with stakeholders across multiple accounts to identify OT security gaps and design strategic roadmaps for improvement.
8+ years in OT cybersecurity, ICS/SCADA security, or industrial IT.
Experience with OT/ICS security platforms such as Armis, Claroty, Nozomi, Ordr, or similar.
Familiarity with industrial protocols (e.g., Modbus, OPC, DNP3, Profinet), ICS devices (PLCs, HMIs), and vendor ecosystems (Rockwell, Siemens, Schneider, etc.).
Strong understanding of network segmentation, passive monitoring, and ICS risk management frameworks (IEC 62443, NIST CSF).
Hands-on experience working in or securing OT/ICS environments in manufacturing, utilities, or critical infrastructure.
Capable of working in U.S. Federal/Government-compliant environments (U.S. Citizen or equivalent clearance eligible).
Understanding of CVEs/CVSS scoring and OT vulnerability prioritization.
Experience with scripting/automation (Python, Bash, PowerShell) and REST APIs for tool integration.
Strong communication skills with the ability to simplify complex ICS risks for technical and non-technical stakeholders.
Preferred Qualifications
Certifications such as GICSP, GRID, ISA/IEC 62443, CISSP, or OSCP.
Experience with patch management in OT environments.
Familiarity with integrating OT visibility tools with SIEM (e.g., Splunk, QRadar), CMDB, or SOC workflows.
Experience with RBVM or vulnerability tracking in ICS (Qualys, Tenable.ot, Rapid7, etc.).
Exposure to AppSec concepts and toolchains (optional, for hybrid environments).
Work Personas
We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here. To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.
Equal Opportunity Employer
ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, age, disability, gender identity, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.
Accommodations
We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact [email protected] for assistance.
Export Control Regulations
For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.
From Fortune. ©2026 Fortune Media IP Limited. All rights reserved. Used under license.
ServiceNow Dublin, Leinster, IRL Office
60 Dawson St, Dublin, Leinster, Ireland, D02 K330

