NEW JOB OPENING
IT SECURITY ENGINEER - SERVICENOW SIR & DETECTION ENGINEERING
IN Frisco, TX, USA!

 

Date Posted: 09/29/2026
Hiring Organization: Rose International
Position Number: 508391
Industry: Software/Financial Services/IT Company
Job Title: IT Security Engineer - ServiceNow SIR & Detection Engineering
Job Location: Frisco, TX, USA, 75034
Work Model: Hybrid
Work Model Details: Hybrid: 3 days/week onsite
Shift: Standard Business Hours
Employment Type: Temporary
FT/PT: Full-Time
Estimated Duration (In months): 12
Min Hourly Rate($): 50.00
Max Hourly Rate($): 56.00
Must Have Skills/Attributes: Security Administration
Nice To Have Skills/Attributes: ServiceNow, Splunk, Zscalar
Experience Desired: Hands-on experience administering the ServiceNow Security Incident Response (SIR) module (3-5+ yrs); Splunk Enterprise Security (SIEM), ServiceNow Security Incident Response (SOC case management) (3-5+ yrs); CrowdStrike Falcon (EDR), Zscaler (Network/DLP), Wiz (Cloud/Kubernetes) (3-5+ yrs); Mate Security & Onyx (AI SOC), Sublime (Email Security), Akamai (WAF/CDN), Splunk ES (SIEM) (3-5+ yrs)
Preferred Certifications/Licenses: ServiceNow certifications relevant to the platform (e.g., Certified System Administrator)

**C2C is not available**

 

Job Description


Preferred Certification:

• ServiceNow certifications relevant to the platform (e.g., Certified System Administrator)



Required Skills:

• Proven SOC experience (detection engineering, security engineering, or senior analyst capacity) with a demonstrable engineering mindset

• Hands-on experience administering the ServiceNow Security Incident Response (SIR) module: configuring security incident workflows, business rules, assignment logic, and SIEM/SOAR/API integrations, and maintaining the module in a production SOC environment (3-5+ years)

• Hands-on automation and scripting, primarily Python, and experience building or contributing to Detection-as-Code pipelines

• Strong grounding in MITRE ATT&CK, Pyramid of Pain, Cyber Kill Chain, and the incident response process and its phases

• Deep understanding of at least one of: endpoint security (macOS and Windows internals, telemetry, detection) or cloud infrastructure (cloud-native services, Kubernetes, runtime detection)

• Solid networking fundamentals, including DNS

• Working knowledge of IAM, SSO (SAML/OIDC), and Zero Trust architecture concepts

• Working knowledge of Data Loss Prevention concepts and detection use cases

• Understanding of AI Detection & Response: securing and monitoring AI/LLM usage in the enterprise

• Familiarity with agentic AI frameworks and applying AI to SOC operations and detection engineering workflows



Preferred Skills:

• Security Incident Response implementation experience

• CI/CD tooling (Git, GitHub Actions or similar) for security content deployment

• Experience integrating AI/LLM capabilities into SOC triage or detection pipelines

• Familiarity with Risk-Based Alerting concepts

• Our stack: CrowdStrike Falcon (EDR), Zscaler (network and DLP), Wiz (cloud and Kubernetes runtime detection), Mate Security (AI SOC), Sublime (email security), Akamai (WAF and CDN), Onyx (AI detection and response), Splunk Enterprise Security (SIEM), ServiceNow Security Incident Response (SOC case management)- 3-5+ years. Direct experience with these specific tools is a plus, but strong fundamentals and the ability to ramp quickly matter more



Duties:

• Administer and enhance the ServiceNow Security Incident Response (SIR) module: security incident workflows, assignment and escalation rules, SLA definitions, form and UI configuration, and integrations with SIEM, SOAR, and threat intelligence sources

• Design, build, and maintain the Detection-as-Code (DaC) pipeline: detection development, version control, CI/CD-based testing, and automated deployment

• Develop and tune detections across EDR, cloud, network, email, and DLP telemetry

• Build SOAR playbooks, API integrations, and automation to streamline SOC workflows

• Support administration and optimization of the SIEM/SOAR platform stack

• Contribute to AI SOC initiatives: investigation coverage expansion, alert triage automation, and integration health

• Apply MITRE ATT&CK mapping, FP-rate gating, and detection lifecycle standards to all deployed content

• Partner with SOC analysts and incident response to translate operational gaps into engineering solutions



Job Details:

Contractor supporting Detection & Platform Engineering within Threat Operations. The team owns the technology backbone of the SOC across SIEM and SOAR platform management, AI SOC, automation, and detection deployment.

This is an engineering role, not a pure analyst role. It combines detection engineering with hands-on ownership of the SOC's case management platform. We are looking for someone who builds pipelines, automates repetitive work, develops and enhances the detection-as-code pipeline, administers ServiceNow Security Incident Response, and applies AI to improve day-to-day SOC productivity.

  • **Only those lawfully authorized to work in the designated country associated with the position will be considered.**

  • **Please note that all Position start dates and duration are estimates and may be reduced or lengthened based upon a client’s business needs and requirements.**


 

Benefits:
For information and details on employment benefits offered with this position, please visit here. Should you have any questions/concerns, please contact our HR Department via our secure website.

California Pay Equity:
For information and details on pay equity laws in California, please visit the State of California Department of Industrial Relations' website here.

Rose International is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, sexual orientation, gender (expression or identity), national origin, arrest and conviction records, disability, veteran status or any other characteristic protected by law. Positions located in San Francisco and Los Angeles, California will be administered in accordance with their respective Fair Chance Ordinances.

If you need assistance in completing this application, or during any phase of the application, interview, hiring, or employment process, whether due to a disability or otherwise, please contact our HR Department.

Rose International has an official agreement (ID #132522), effective June 30, 2008, with the U.S. Department of Homeland Security, U.S. Citizenship and Immigration Services, Employment Verification Program (E-Verify). (Posting required by OCGA 13/10-91.).

 

Apply Now

 

About Rose

  • Founded in 1993
  • Office Locations Across the U.S.
  • 150+ Clients: Corporations and Government Agencies
  • Employee Oriented Company
  • Challenging Assignments Across the U.S.
  • Continuous Professional Development

I believe the best thing that Rose HR has going for it is the incredible responsiveness. Everyone is very quick to reply to any concerns, and contacts the contracted employees very quickly and efficiently.

Kevin, Consultant

You are customer service oriented. No matter whether it was the Recruiter or someone in Human Resources/Payroll, you were responsive. That to me is key!

Tonya, Consultant

Rose International has been great to me. I thank everyone there for all of their hard work; it has not gone unnoticed.

Melody, Consultant

My on-boarding with Rose was outstanding. The packets of information, the process, and great attention to detail each person gave me allowed me to get started quickly.I appreciated each person's friendly and helpful attitude.

Diana, Consultant

The interactions that I have had with your representatives have always been prompt and very professional. I am very pleased and impressed with your company and services.

Sioe, Consultant

EMPLOYEE COMMENTS

  • We want you to work with us, but don't take our word for it. Take a look at this sampling of employee comments. They speak for themselves.