Skip to main content
IBM

IBM

Project Manager, ServiceNow / Watson AIOps integrations

May 2022 - April 2023CanadaEnterprise IT operations across telecommunications, healthcare, and finance

Led ServiceNow integrations with Watson AIOps, SevOne, and QRadar for enterprise clients across three regulated industries

A year of enterprise ServiceNow work: ITSM, ITOM, and CSM feature rollouts in Agile environments, plus three certifications (ITIL 4 Foundation, ServiceNow Certified Application Developer, Certified System Administrator).

ServiceNowWatson AIOpsSevOneQRadarITSMITOMCSMAgile / Scrum

The problem

Clients had strong point tools sitting in silos. Watson AIOps found anomalies. SevOne monitored the network. QRadar caught the security events. ServiceNow logged the incidents. None of them talked to each other, so the person triaging an alert had to open four consoles to see the full picture.

The word 'incident' meant three different things across those four tools. What a detector called an anomaly, an operator called an incident, and a business called an outage.

Why it was hard

Every client's definition of an 'incident' was different, and every source tool had its own severity ladder. Aligning the three ladders onto one ITSM priority scheme meant translating three vocabularies into one, without losing the audit trail back to the tool that raised the event.

Regulated industries have hard boundaries on what leaves which system. A telecom outage note that mentions a customer ID cannot be pasted into a healthcare ticket. The integration had to know the difference.

Agile cadence across three parallel client teams meant the same fortnight had three different definitions of 'done'. Sequencing releases so a fix landed in the right client's ITSM without leaking into the others was a scheduling problem, not a coding one.

The approach

Led integration projects that made ServiceNow the single pane for incident context. Watson AIOps findings arrived as enriched incidents with the anomaly signature attached. SevOne alerts pre-populated the affected configuration item. QRadar security events routed through CSM workflows.

Delivered ITSM, ITOM (Discovery and Event Management), and CSM feature rollouts across telecom, healthcare, and finance clients, all in Agile environments. Sat between developers building the integrations and clients defining what 'resolved' actually meant to them.

During the same year, completed three certifications: ITIL 4 Foundation, ServiceNow Certified Application Developer (CAD), and ServiceNow Certified System Administrator (CSA).

The outcome

Enterprise service delivery improved because the incident record actually knew what the detection tool had already found. The triage handoff got shorter by exactly the amount of context that used to be missing.

Three certifications earned in the same window, filed under one role: ITIL 4 Foundation, ServiceNow CAD, ServiceNow CSA.

Cross-functional delivery cadence held across three regulated industries in parallel.

You have this problem if

  • Your detection tools and your ticketing system don't share the same vocabulary for the same event
  • Analysts open four consoles to triage one alert, so the first ten minutes of every incident are just re-typing
  • Compliance requires an audit trail from the ticket back to the source detection, and you don't have one
  • You operate across regulated verticals where the same integration has to know which fields cannot cross a boundary

What I take from this

The hardest part of enterprise integration is not the API. It's the language mismatch. Somebody needs to write the translation table. That was the project manager's job at IBM, and it's the same job now in every AI integration I take on: what the model calls an entity is not what the CRM calls a record, and reconciling those two languages is where the value shows up.

How this shows up in my work today

The translation-table job is what most AI integrations are, once you strip the marketing. An LLM calls something an entity, your CRM calls it a record, your billing system calls it a customer. The reconciliation is the deliverable. A 48h demo is the fastest way to find out whether the reconciliation is one afternoon of prompt engineering or three weeks of schema work, and to tell you honestly which one your project actually is.