Senior Staff AI Security Engineer
Company Description
It all started when engineer Fred Luddy wrote code that automated a tedious task for his coworker, Phyllis. She cried tears of joy. That moment inspired Fred to build a company that could do that for everyone—freeing people from busywork so they could focus on meaningful work. Today, ServiceNow is the AI control tower for business reinvention. Our ServiceNow AI platform brings together any AI, any data, and any workflow— helping 85% of the Fortune 500® work smarter, faster, and better. We're building an AI-native culture where technology and talent are unstoppable together. And we're just getting started.
Join us to put AI to work for people.
Job Description
Role
This is a hands-on architecture role: deep research, secure systems design, and prototyping, applied across multiple product lines with limited direction and significant latitude in shaping the technical approach. You will help drive the security architecture for the AI development lifecycle across multiple teams, define how agents and models are secured in the systems you own, and help shape ServiceNow's AI security point of view. You'll be a go-to technical expert engineers and partner teams look to on emerging AI-specific threats, working in close partnership with the AI security research team - drawing on their findings and feeding real-world attack surfaces back into their agenda.
What you'll do
- Drive the security architecture for our Agentic AI ecosystem, LLMs, and models across multiple product lines
- Lead threat modeling for the most complex and novel GenAI/agentic surfaces: cross-agent autonomy, multi-agent tool orchestration, and emerging attack classes not yet standardised in the industry
- Design and implement secure model/RAG/data pipelines, including access-control and data-boundary patterns other teams can adopt
- Apply and extend secure-by-design practices for agentic systems, and drive adoption with partner engineering teams
- Communicate our AI security posture to internal stakeholders, and contribute externally (industry publications, conferences) where it advances the work
- Mentor and technically guide engineers on AI-specific security work
Qualifications
To succeed in this role, you’ll need:
- Bachelor’s / Master's degree or PhD in Computer Science or a related technical field, specialisation in Security or AI/ML or a well-evidenced track record substituting for it
- 8+ years of software engineering experience, with a track record of designing and building complex systems at enterprise scale
- A track record of setting technical direction beyond your own team - architecture or standards other teams adopted, senior engineers you've levelled up, and comfort operating where the problem isn't yet defined
- 5+ years in security engineering - network and systems security, security protocols, design reviews, and threat modeling - with a focus on AI-specific work in recent years
- Multiple demonstrated engagements in threat modeling and/or securing LLM, GenAI, or agentic systems, with evidence of platform-level or cross-team impact
- Personal ownership of prompt injection/jailbreak defense, guardrail architecture, or AI red-teaming work
- Applied experience securing model, RAG, or data pipelines, including access-control and data-governance design
- Fluency with the OWASP LLM Top 10 (or equivalent), and the judgment to know where such frameworks fall short in practice
- Hands-on experience with agentic AI frameworks (e.g., LangChain, LangGraph)
- Clear communication, a collaborative default, and a bias toward learning fast in a field that changes constantly
Bonus
- Strong command of auth protocols (OAuth 2.0, OIDC, PKCE, API Keys) and agentic protocols (MCP, A2A), including having worked on identity/consent models for them
- Built security tooling or automation for AI systems that was adopted beyond your own team
- CVEs, publications, or conference talks in AI/ML or LLM security
- Experience shaping AI security strategy beyond a single product
- 5+ years of programming experience in Java or Python
Additional Information
Work Personas
We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here. To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.
Equal Opportunity Employer
ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.
Accommodations
We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact [email protected] for assistance.
Export Control Regulations
For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.
From Fortune. ©2026 Fortune Media IP Limited. All rights reserved. Used under license. .