What I delivered

Monitoring and vulnerability data lived in their own tools, disconnected from the platform where the work actually gets tracked. I brought those feeds into ServiceNow so operations and security could act on them without tool-hopping.

  • A LogicMonitor path that turns monitoring alerts into outage and incident records.
  • Normalized Tenable vulnerability naming so findings are consistent and searchable in-platform.
  • A clean mapping between external signal and the ServiceNow records the team already lives in.
  • Readiness notes so the same pattern extends to the next monitoring or security source.

How it came together

Each integration is a mapping problem first and a plumbing problem second: deciding what an alert means as a ServiceNow record before wiring the REST path that creates it. An in-house agentic AI system sped up the mapping and naming-normalization work — drafting the field alignments and catching inconsistencies — which I reviewed and finalized against how the ops and security teams actually triage. Getting the naming right is what makes the data usable instead of noisy.

Impact

Operations sees monitoring alerts as incidents they can route and resolve, and security sees vulnerabilities under consistent names instead of a scattered feed. Both teams work from one source of truth in ServiceNow — fewer tabs, less manual translation, and a pattern that's ready to absorb the next data source when it arrives.