- Contracted directly by ServiceNow as design authority for a greenfield Vulnerability Response implementation at Japan Tobacco International, following a previous unsuccessful attempt.
- Led the as-is assessment and to-be workshops, defined the target operating model across infrastructure and application VR, and shaped a backlog of 43 user stories, all delivered by build close.
- Designed an out-of-the-box-first classification and assignment model on the Qualys integration, fixing the root cause of the earlier failure.
ServiceNow Security Operations and Risk Consultancy.
Streamline Consultancy Group is a ServiceNow consultancy led by Cameron Heckstall-Smith, specialising in Vulnerability Response, Security Incident Response and Integrated Risk Management, with Performance Analytics reporting across all three. We work with enterprises, partners and ServiceNow's own Professional Services team, as design authority, architect or hands-on engineer.
- 8+ yearsdelivering ServiceNow end to end
- 11 CIS certificationsplus CAD and CSA
- SecOps and IRMVR, SIR, Threat Intelligence, GRC
- BPSS clearedwith UK government delivery experience
Over eight years of engagements
Five years at a ServiceNow partner, then contracting through Streamline Consultancy Group since 2023, often running a long SecOps engagement alongside shorter ones.
- Security Operations
- Integrated Risk Management
- ITSM, CSM and wider platform
Client: Japan Tobacco International
May to Oct 2026
Via Wrangu
Apr to Aug 2026
Direct to Client
Jan 2023 to Apr 2026
Via Wrangu
Apr 2025 to Jan 2026
Via Capgemini
Sep 2024 to Mar 2025
Direct to Client
Mar to Aug 2024
2017 to 2022
What we can take on
Full lifecycle work, from discovery workshops through to go-live and handover, either leading the engagement or embedded in your team.
Vulnerability Response
Greenfield builds and recoveries of implementations that have stalled. Scanner ingestion, CMDB matching, classification and assignment, risk scoring, exception approvals and remediation workflows.
Security Incident Response and Threat Intelligence
SOC process design, automation playbooks and integrations with SIEM and threat intelligence sources, with reporting that a CISO can act on.
Integrated Risk Management
Policy and compliance, risk and control configuration, scripting and workflow development, delivered in banking and UK government environments.
Performance Analytics and reporting
Indicators, breakdowns and dashboards that turn platform data into something leadership can act on, from vulnerability and SOC metrics to risk and service performance. Backed by a Performance Analytics Implementation Specialist certification.
Design authority and architecture
As-is assessments, to-be workshops, target operating models and prioritised backlogs, then guiding your developers through the build. Also sole architect or technical lead on multi-year programmes, setting standards and mentoring teams.
Wider platform engineering
ITSM, CSM and HR, including custom applications, integrations and bespoke workflows.
Integrations we have experience with
- Qualys
- Orca
- GitHub
- Splunk
- Tenable
- ThreatConnect
- ZeroFox
- Flashpoint
- Bugcrowd
Experience
- Sole architect and senior engineer on a ServiceNow award-winning SecOps transformation for one of Europe's largest airlines.
- Designed and delivered the architecture across Vulnerability Response, Security Incident Response and Threat Intelligence.
- Built eight security tool integrations, reaching 95%+ CMDB asset match rates globally.
- Wrote automation playbooks that cut the SOC's mean time to respond to near-zero.
Lead developer on a greenfield ServiceNow IRM implementation for a highly secure UK Government department. Further details are withheld due to the nature of the work.
Developer on a large-scale Integrated Risk Management implementation for one of the UK's leading banks, delivering configuration, scripting and workflow development in a tightly governed environment.
Core engineer on a successful ITSM rollout for Smart DCC, part of the UK's critical national infrastructure.
Extended an existing CSM solution with an automated end-to-end process for direct debit payments.
Five years at a ServiceNow partner, leading workstreams on multi-stream enterprise programmes and delivering greenfield implementations across ITSM, SecOps, HR and CSM for clients in banking, telecoms and government. Also supported pre-sales, scoping and estimating.
Certifications
Certified Implementation Specialist
- Security Incident Management
- Vulnerability Response
- Vendor Risk Management
- Governance, Risk and Compliance
- Event Management
- ITSM
- CSM
- Performance Analytics
- Cloud Management
- Human Resources
- Software Asset Management
ServiceNow platform
- Certified Application Developer
- Certified System Administrator
- Complete Suite: ITSM
- Complete Suite: CSM
- Complete Suite: HR Professional
- Complete Suite: HR Enterprise
Micro-certifications in Agent Intelligence, Enterprise Onboarding and Transitions, Performance Analytics and Virtual Agent.
Other
- BPSS cleared
- ITIL Foundation
- Professional Scrum Master (PSM I)
- SAIF Fundamentals
- BSc Computing, First Class Honours, University of Kent
Get in touch
If you have a ServiceNow SecOps or IRM contract, or a programme that needs a design authority, email is the quickest way to reach us. Send the role details and we'll come back to you with availability and a CV.
Email us- linkedin.com/in/cameronhs
- Location
- London, United Kingdom. Remote or hybrid.
- Engagement
- Contract, through Streamline Consultancy Group LTD