资深应用安全工程师(ServiceNow实例安全)
Staff Application Security Engineer (ServiceNow Instance Security)
#### 公司简介
一切始于工程师Fred Luddy为同事Phyllis编写了一段代码,自动化了一个繁琐的任务。她感动得热泪盈眶。这一时刻激发了Fred创建一家公司,让每个人都能摆脱琐事,专注于有意义的工作。如今,ServiceNow是企业转型的AI控制中心。我们的ServiceNow AI平台整合任何AI、任何数据和任何工作流,帮助85%的财富500强®企业更聪明、更快、更好地工作。我们正在打造一个以AI为核心的文化,让技术和人才 unstoppable 一起前进。而我们才刚刚开始。
加入我们,让AI为人们工作。
#### 职位描述
**ServiceNow 安全组织(SSO)**
ServiceNow 安全组织(SSO)提供世界级的创新安全解决方案,降低风险并保护公司及客户。我们帮助客户将最敏感的数据和工作负载迁移到云端,加速我们的业务发展,使我们成为最受信赖的SaaS提供商。我们创造一个员工自豪工作的环境,并能产生积极影响。
**团队介绍**
全球安全支持中心(GSSC)在加强ServiceNow的内部和外部安全态势方面发挥关键作用,并作为与客户在安全相关事务上的主要接口。
GSSC AppSec 是一个全球分布的团队,负责管理客户渗透测试与安全发现(CPT & SF)计划,与其他安全组织合作,降低风险,处理升级问题,并代表客户的利益。
此职位专注于ServiceNow实例安全,帮助客户和内部团队识别、理解并修复不安全的配置和实例级安全漏洞。
**职位概要**
作为GSSC AppSec 的高级应用安全工程师,您将通过识别基于配置的安全风险、验证客户报告的发现,并推动清晰、可操作的修复建议来保障ServiceNow实例的安全。
这是一个需要亲自动手的技术岗位,结合应用安全的专业知识和对ServiceNow平台的深入理解。在该职位的高级阶段,您将在较少指导的情况下开展工作,独立解决复杂的实例安全问题空间,并影响GSSC AppSec在全球范围内提升实例安全指导和安全态势的方式。
主要职责
- ServiceNow 实例安全与加固
- 评估
查看英文原文
#### Company Description
It all started when engineer Fred Luddy wrote code that automated a tedious task for his coworker, Phyllis. She cried tears of joy. That moment inspired Fred to build a company that could do that for everyone—freeing people from busywork so they could focus on meaningful work. Today, ServiceNow is the AI control tower for business reinvention. Our ServiceNow AI platform brings together any AI, any data, and any workflow— helping 85% of the Fortune 500® work smarter, faster, and better. We're building an AI-native culture where technology and talent are unstoppable together. And we're just getting started.
Join us to put AI to work for people.
#### Job Description
**The ServiceNow Security Organization (SSO)**
The ServiceNow Security Organization (SSO) delivers world-class, innovative security solutions to reduce risk and protect the company and our customers. We enable our customers to migrate their most sensitive data and workloads to the cloud, accelerating our business so that we are the most trusted SaaS provider. We create an environment where our employees are proud to work and can make a positive impact
**About the Team**
The Global Security Support Center (GSSC) plays a critical role in strengthening ServiceNow’s internal and external security posture and acts as a key interface with customers on security‑related matters.
GSSC AppSec is a globally distributed team responsible for owning the Customer Penetration Testing & Security Findings (CPT & SF) program, partnering across the Security Organization to reduce risk, handle escalations, and represent the voice of the customer.
This role is focused on ServiceNow instance security, helping customers and internal teams identify, understand, and remediate insecure configurations and instance‑level security gaps.
**Role Summary**
As an Staff Application Security Engineer in GSSC AppSec, you will secure ServiceNow instances by identifying configuration‑driven security risks, validating customer‑reported findings, and driving clear, actionable remediation guidance.
This is a hands‑on technical role that blends application security expertise with deep ServiceNow platform knowledge. At the senior end of the range, you will operate with minimal direction, own complex instance‑security problem spaces, and influence how GSSC AppSec scales instance security guidance and posture improvements globally.
Key Responsibilities
- ServiceNow Instance Security & Hardening
- Assess ServiceNow instance configurations against security baselines and identify misconfigurations that impact confidentiality, integrity, or availability.
- Develop and maintain prescriptive instance‑hardening guidance covering authentication, access controls, encryption, logging, monitoring, and operational security.
- Translate security requirements and risk into clear, customer‑consumable recommendations that can be implemented by teams with varying security maturity.
- Identify recurring misconfiguration patterns and drive systemic improvements (guidance, tooling, checks).
- AppSec & Customer Security Findings (CPT & SF)
- Triage, validate, and contextualize customer‑reported security findings where instance configuration or deployment patterns are a contributing factor.
- Distinguish between product vulnerabilities vs. configuration issues, documenting impact and appropriate remediation paths.
- Partner with Product Security, Engineering, and other Security teams to resolve complex or high‑impact findings.
- Support escalations and high‑visibility customer interactions as an instance‑security subject‑matter expert.
**Required Qualifications**
- Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving. This may include using AI-powered tools, automating workflows, analyzing AI-driven insights, or exploring AI’s potential impact on the function or industry.
- 8+ years with strong foundation in application security (vulnerability analysis, secure design principles, threat modeling mindset). Or similar experience with education
- Ability to read, write, and debug code to validate findings and understand security impact.
- Experience translating security risk into actionable remediation guidance.
- Excellent written and verbal communication skills, especially for customer‑facing or executive‑visible content.
#### Qualifications
**Preferred Qualifications**
- Hands‑on experience with the ServiceNow platform, especially platform security features, configuration, and administration.
- Familiarity with SaaS security posture management and misconfiguration risk.
- Prior experience supporting customer‑reported security findings, escalations, or external security reviews.
- Experience influencing security outcomes without direct authority (cross‑functional collaboration).
**What Success Looks Like**
- Customers and internal teams receive clear, accurate, and actionable guidance to secure their ServiceNow instances.
- Reduced repeat instance‑security issues through improved baselines, guidance, and detection.
- Faster, higher‑confidence triage of customer‑reported security findings tied to instance configuration.
- GSSC AppSec becomes more scalable and consistent in how it addresses instance‑level security risk.
**#SecurityJobs**
**West Palm Beach Florida (WPB) is available to for Relocation. Full relocation costs are provided by ServiceNow**
JV20
For positions in this location, we offer a base pay of **$176,100 - $308,200**, plus equity (when applicable), variable/incentive compensation and benefits. Sales positions generally offer a competitive On Target Earnings (OTE) incentive compensation structure. Please note that the base pay shown is a guideline, and individual total compensation will vary based on factors such as qualifications, skill level, competencies, and work location. We also offer health plans, including flexible spending accounts, a 401(k) Plan with company match, ESPP, matching donations, a flexible time away plan and family leave programs. Compensation is based on the geographic location in which the role is located and is subject to change based on work location.
#### Additional Information
**Work Personas**
We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. [Learn more here](https://careers.servicenow.com/life-at-servicenow#workpersonas). To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.
**Equal Opportunity Employer**
ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, age, disability, gender identity, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.
**Accommodations**
We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact [globaltalentss@servicenow.com](mailto:globaltalentss@servicenow.com) for assistance.
**Export Control Regulations**
For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.
From Fortune. ©2026 Fortune Media IP Limited. All rights reserved. Used under license.