Sr. Dir., Product Security and AI
ServiceNowAbout the role
Company Description
It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today — ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500®. Our intelligent cloud-based platform seamlessly connects people, systems, and processes to empower organizations to find smarter, faster, and better ways to work. But this is just the beginning of our journey. Join us as we pursue our purpose to make the world work better for everyone.
Job Description
Senior Director, Product Security and AI
ServiceNow is seeking a high energy, high EQ Security Leader who thrives in a highly cross-functional, rapid velocity environment. As a direct report to Vice President of Application Security, you'll have the opportunity to work with world-class security experts and cutting-edge technology to secure our product portfolio. You will play a pivotal role in leading ServiceNow’s product security strategy, execution, and risk management initiatives.
This senior leadership position is responsible for ensuring that security is embedded throughout the ecosystem and entire product development lifecycle, including design, development, testing, and deployment of ServiceNow’s products and services. You will collaborate closely with engineering, product management, core infrastructure, security operations, and executive leadership to ensure that the company's product security posture is industry leading.
You will:
- Drive scale
- Transform culture
- Design end-to-end global enterprise security solutions, technologies, and strategies across a broad set of security disciplines incorporating AI technologies.
- Design and implement an integrated security ecosystem blanket to deter, detect, defend, and respond to ServiceNow’s business impacting security, operational security, and risk issues.
Responsibilities:
- Define and implement the long-term vision, strategy, and roadmap for product and application security aligned with company objectives and industry best practices.
- Lead efforts to integrate security into the Software Development Life Cycle (SDLC) and DevSecOps pipelines, ensuring that security is considered from inception through deployment.
- Take an adversary perspective to identify, prioritize, and mitigate vulnerabilities in our products across both pre- and post-production environments and establish clear processes for vulnerability management.
- Develop best-in-class security controls frameworks to enable new initiatives such as our Generative AI efforts.
- Manage, mentor, and grow a team of product security engineers and architects responsible for application security testing, vulnerability assessments, and code reviews.
- Foster a culture of innovation, collaboration, and continuous improvement within the product security organization.
- Partner with product management, engineering, and other relevant teams to ensure that security requirements are clearly defined and implemented within all product offerings.
- Work closely with legal and compliance teams to ensure product security meets regulatory requirements (e.g., GDPR, CCPA, and other industry-specific regulations).
- Lead the response to critical product security incidents, vulnerabilities, and threats, ensuring timely mitigation and communication to stakeholders.
- Oversee threat modeling, vulnerability scanning, and penetration testing to identify and mitigate risks in products and applications.
- Ensure that security risk assessments are conducted regularly and that remediation efforts are tracked and closed in a timely manner.
- Champion security best practices within the organization, driving awareness and education for product teams and stakeholders on secure coding practices and emerging threats.
- Represent product security efforts in customer-facing engagements, providing confidence to clients regarding our security posture.
- Stay current with emerging threats, vulnerabilities, and security technologies, and incorporate learnings into product security strategies.
- Drive research and adoption of new security technologies, methodologies, and tools to enhance product security capabilities.
Qualifications
Qualifications:
- 15+ experience leading a security application development engineering organization and securing the overall enterprise and security posture in a large-scale environment
- 12+ years of experience driving security product vision, design roadmaps, and digital design transformation and products.
- Subject matter expertise in cybersecurity within cloud, enterprise, and across industry platforms
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s