Principal Security Engineer | Cyber Defense Engineering
Job description
It all started when engineer Fred Luddy wrote code that automated a tedious task for his coworker, Phyllis. She cried tears of joy. That moment inspired Fred to build a company that could do that for everyone—freeing people from busywork so they could focus on meaningful work. Today, ServiceNow is the AI control tower for business reinvention. Our ServiceNow AI platform brings together any AI, any data, and any workflow— helping 85% of the Fortune 500® work smarter, faster, and better. We're building an AI-native culture where technology and talent are unstoppable together. And we're just getting started. Join us to put AI to work for people. The ServiceNow Security Organization (SSO) The ServiceNow Security Organization (SSO) delivers world-class, innovative security solutions to reduce risk and protect the company and our customers. We enable our customers to migrate their most sensitive data and workloads to the cloud, accelerating our business so that we are the most trusted SaaS provider. We create an environment where our employees are proud to work and can make a positive impact This is a hands-on engineering and architecture role within Cyber Defense Engineering (CDE), applied to some of the hardest, least-defined problems in cyber defense, protecting a platform trusted by thousands of the world's largest enterprises. You'll operate with minimal direction and broad latitude to set the technical agenda. You'll start by tackling one of the highest-stakes problems in enterprise security today: how do you secure a company's own employees and systems as they adopt AI faster than anyone can govern it? Think compromised internal agents, AI copilots that leak sensitive data, and shadow AI tools appearing before any policy exists. You'll architect the threat models, controls, and secure-by-design standards other teams build against, partnering with ServiceNow's product AI security research team to apply frontier research internally, and you'll be the technical authority Security, IT, and Engineering rely on for internal AI threats. Beyond internal AI security, you'll also lead initiatives that use AI to transform cyber defense more broadly, such as modernizing blue and red team practices or solving problems that don't have a name yet. This role is for engineers who want to keep solving cyber defense's hardest, least-defined problems at the frontier of the field, not run a single program indefinitely. What You'll Do Architect Internal AI Security Strategy: Own the security architecture for internal AI adoption across ServiceNow, including agentic tools, LLMs, copilots, and the automation built on them Drive Execution Excellence: Push your architecture and standards through to adopted, production-grade outcomes, not just documentation, holding IAM, endpoint security, cloud security, IT, and infrastructure teams accountable for secure implementation Lead AI Threat Modeling: Threat model the most complex internal AI surfaces, from compromised or misdirected agents to attack classes not yet standardized in the industry Define AI Governance and Policy: Partner with Legal, Privacy, IT, and Engineering leadership to define what's safe to use, and translate that into enforceable, scalable controls for sanctioned and shadow AI alike Partner on Frontier AI Threat Research: Collaborate with ServiceNow's product AI security team to bring emerging attack research into ServiceNow internal AI security, and surface real-world internal findings back to them Drive Broader Cyber Defense Initiatives: Apply AI to modernize blue and red team practices, consolidate detection platforms, or take on the next problem that doesn't have a name yet Mentor and Raise the Bar: Mentor engineers across CDE and raise the technical bar on whatever problem you're driving Required Qualifications: Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving. This may include using AI-powered tools, automating workflows, analyzing AI-driven insights, or exploring AI’s potential impact on the function or industry. 15+ years in security engineering, spanning security operations, architecture, threat modeling, and design reviews, with a recent focus on AI-specific threats. Or similar experience with education 5+ years of software engineering experience, with a proven track record of owning complex system architecture at enterprise scale Demonstrated ability to set technical direction and architect security solutions across multiple security domains (for example, AI security, IAM, endpoint security, infra security, detection engineering, and incident response) Clear communication and a bias toward learning fast in a field that changes constantly Preferred Qualifications: Bachelor's / Master's degree or PhD in Computer Science or a related technical field, with a specialization in Security or AI/ML, or an exceptional, well-evidenced track record substituting for it Hands-on experience threat modeling and securing modern AI systems (LLMs, agents, RAG pipelines), with evidence of platform-level impact Deep hands-on experience with agentic AI frameworks (e.g., LangChain, LangGraph) Built or open-sourced security tooling/automation for AI systems adopted beyond one team Prior experience setting AI security strategy at a platform or company level #SecurityJobs For positions in this location, we offer a base pay of $221,200 - $387,100 , plus equity (when applicable), variable/incentive compensation and benefits. Sales positions generally offer a competitive On Target Earnings (OTE) incentive compensation structure. Please note that the base pay shown is a guideline, and individual total compensation will vary based on factors such as qualifications, skill level, competencies, and work location. We also offer health plans, including flexible spending accounts, a 401(k) Plan with company match, ESPP, matching donations, a flexible time away plan and family leave programs. Compensation is based on the geographic location in which the role is located and is subject to change based on work location. Work Personas We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here . To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service. Equal Opportunity Employer ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, age, disability, gender identity, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements. Accommodations We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact globaltalentss@servicenow.com for assistance. Export Control Regulations For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities. From Fortune. ©2026 Fortune Media IP Limited. All rights reserved. Used under license.
Apply kit
Sign in to copy a field card for the employer’s ATS. We never submit applications for you.