高级资深AI工程师
Sr Staff AI Engineer
#### 公司简介
Veza 是身份安全领域的先驱,专为回答企业面临的核心问题而构建:谁可以以及应该对哪些数据执行什么操作。Veza 的 Access Graph 平台可映射组织整个身份生态系统,涵盖用户、组、角色、策略、权限和资源,为企业提供对人类、非人类和代理身份的深度可见性和控制力,覆盖 SaaS、云、本地和自定义应用。在管理超过 300 亿个访问权限的情况下,包括 Blackstone、Expedia 和 Wynn Resorts 在内的全球企业都信任 Veza 来管理特权访问监控、非人类身份安全、访问授权管理和下一代身份治理。
Veza 成立于 2020 年,总部位于加利福尼亚州红木城,现已加入 ServiceNow 家族,收购于 2026 年 3 月完成。此次合并将 Veza 的原生 AI Access Graph 与 ServiceNow 的 AI Control Tower 和代理工作流相结合,使组织能够在应用程序、数据、云环境和 AI 代理中,基于最小权限原则实施端到端的身份安全。对于今天加入 Veza 的工程师来说,这意味着拥有企业级平台公司的规模和资源,同时具备安全创新者的快速产品迭代和以使命为导向的专注,在行业关键节点上发挥重要作用。
#### 职位描述
Access AI 团队是专注于客户需求的工程团队,负责构建代理 AI 和企业级处理平台,为所有身份安全产品中的访问管理代理提供支持。我们构建 AI 作为基础平台基础设施——优先考虑稳健性、性能、安全性以及在大规模真实客户场景中的影响。
你将参与解决的问题类型
你将设计、构建和运营生产级别的代理 AI 系统——自主代理能够对企业数据进行推理,并在财富 500 强规模下执行关键身份安全操作。作为代理研究与大规模后端系统交叉领域的顶级技术领导者,你将塑造架构模式、可扩展性保障措施和自主企业安全的战略愿景。
你的核心关注领域:
- 代理架构。设计并交付多代理系统——编排、工具使用、规划循环、记忆和故障恢复——这些系统应在生产环境中可靠运行,而非在笔记本中。
- 基于企业需求的推理。构建代理
查看英文原文
#### Company Description
Veza is the pioneer in identity security, purpose-built to answer the fundamental question enterprises face: who can and should take what action on what data.Veza's Access Graph platform maps an organization's entire identity ecosystem across users, groups, roles, policies, permissions, and resources providing deep visibility and control over human, non-human, and agentic identities across SaaS, cloud, on-prem, and custom applications.With over 30 billion access permissions under management, global enterprises including Blackstone, Expedia, and Wynn Resorts trust Veza to manage privileged access monitoring, non-human identity security, access entitlement management, and next-generation identity governance.
Founded in 2020 and headquartered in Redwood City, California, Veza is now part of the ServiceNow family, with the acquisition closing in March 2026.The combination brings together Veza's AI-native Access Graph with ServiceNow's AI Control Tower and agentic workflows, enabling organizations to enforce end-to-end identity security rooted in the principle of least privilege across applications, data, cloud environments, and AI agents. For engineers joining Veza today, this means the scale and resources of an enterprise platform company, with the product velocity and mission-driven focus of a security innovator at a pivotal moment in the industry.
#### Job Description
The Access AI team is the customer-obsessed engineering group building the agentic AI and enterprise-scale harness platform that powers agents for Access Management across all Identity Security Products. We build AI as foundational platform infrastructure — prioritizing robustness, performance, safety, and real-world customer impact at scale.
Types of problems you’ll get to work on
You will architect, build, and operate production-grade agentic AI systems—autonomous agents that reason over enterprise data and execute mission-critical identity security actions at Fortune 500 scale. As a tier-one technical leader at the intersection of Agent research and large-scale backend systems, you will shape the architectural patterns, scalability guardrails, and strategic vision for autonomous enterprise security.
Your core focus areas:
- Agentic architecture. Design and ship multi-agent systems — orchestration, tool use, planning loops, memory, and failure recovery — that operate reliably in production, not in notebooks.
- Enterprise-grounded reasoning. Build agents that leverage Access Graph, Access Reviews, and permission and risk data — to make decisions with context no frontier model has on its own.
- Trust, safety, and governance. Own the guardrails: observability, human-in-the-loop controls, and compliance infrastructure that make autonomous systems safe to deploy at scale.
- Retrieval and grounding. Work closely with our different product teams, platform and graph teams to ensure agents are grounded in accurate, low-latency retrieval — RAG pipelines, semantic search, re-ranking, and evaluation — as a critical dependency of agentic quality.
- Model integration and evaluation. Integrate frontier models, evaluate trade-offs across cost, latency, and capability for production use cases.
- Engineering leadership. Raise the technical bar through architecture decisions, code reviews, and coaching — particularly on agentic design patterns and production AI discipline.
#### Qualifications
Qualifications
To be successful in this role you have:
- 8+ years of software engineering with strong fundamentals in data structures, algorithms, and distributed systems.
- Hands-on depth designing, shipping, and operating agentic systems in production — multi-agent orchestration, tool calling, planning loops, memory, and failure recovery. Not prototypes.
- Production-grade Python. Systems language (Go, Java, or C++) is a plus.
- Working experience with frontier AI SDKs (Anthropic, Google, or OpenAI) — prompt engineering, structured outputs, and model evaluation in production settings.
- Familiarity with RAG and retrieval patterns in production — vector stores, hybrid search, and retrieval evaluation metrics.
- Track record of technical leadership: architecture ownership, code quality bar-raising, and mentoring engineers on production AI practices.
Nice to Have
- Deeper specialization in search and retrieval at scale or MLOps/model observability.
- Published work or open-source contributions in agentic systems or retrieval.
- Exposure to LLM fine-tuning or inference optimization in production.
Why join us
Intelligence is commoditizing. Context and execution are not. With over 30 billion access permissions under management, global enterprises in Fortune 500 trust Veza to manage privileged access monitoring, non-human identity security, access entitlement management, and next-generation identity governance, we are building the system that makes AI actually work inside the enterprise to secure Enterprises.
Redefining Agentic Identity Governance:
- Agentic Search: Provides natural language, context-aware discovery capabilities across complex permission graphs, enabling rapid identification of access risks and opportunities.
- Agentic Access Reviews: Streamlines certification processes by using autonomous agents to analyze risk and suggest remediation, significantly reducing reviewer fatigue and preventing rubber-stamping by automating User Access Reviews.
- Agentic LCM: Orchestrates end-to-end lifecycle management workflows, from provisioning to de-provisioning, using intelligent agents to ensure consistency and compliance.
- Agentic Risk insights: Leverages AI to continuously analyze access patterns, surfacing risks before they escalate.
- Agentic NHI and Agent Security: Monitors and secures non-human identities and AI agents by auditing their permissions, ownership and resources.
Autonomous Enterprise: Self-driving access management grounded on identity and permission data from different sources — context no frontier lab can replicate,
For positions in this location, we offer a base pay of **$171,900 - $300,800**, plus equity (when applicable), variable/incentive compensation and benefits. Sales positions generally offer a competitive On Target Earnings (OTE) incentive compensation structure. Please note that the base pay shown is a guideline, and individual total compensation will vary based on factors such as qualifications, skill level, competencies, and work location. We also offer health plans, including flexible spending accounts, a 401(k) Plan with company match, ESPP, matching donations, a flexible time away plan and family leave programs. Compensation is based on the geographic location in which the role is located and is subject to change based on work location.
#### Additional Information
**Work Personas**
We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. [Learn more here](https://careers.servicenow.com/life-at-servicenow#workpersonas). To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.
**Equal Opportunity Employer**
ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, age, disability, gender identity, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.
**Accommodations**
We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact [globaltalentss@servicenow.com](mailto:globaltalentss@servicenow.com) for assistance.
**Export Control Regulations**
For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.
From Fortune. ©2026 Fortune Media IP Limited. All rights reserved. Used under license.