Senior Manager, Systems Engineering - Vulnerability
ServiceNowAbout the role
Company Description
It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today — ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500®. Our intelligent cloud-based platform seamlessly connects people, systems, and processes to empower organizations to find smarter, faster, and better ways to work. But this is just the beginning of our journey. Join us as we pursue our purpose to make the world work better for everyone.
Job Description
Please Note:
This position requires passing ServiceNow’s USFedPASS background screening (US Federal Personnel Authorization Screening Standards), which includes a credit check, criminal/misdemeanor check, and drug test. Employment is contingent upon successful completion. Due to federal requirements, candidates must be U.S. citizens, naturalized citizens, or permanent residents holding a valid green card.
This role is ideally based in our San Diego, CA or Orlando, FL office, with the expectation of working in a hybrid environment.
Role Overview
As Senior Manager of Systems Engineering – Vulnerability Management, you will lead a team of infrastructure engineers responsible for ensuring compliance and reducing risk across ServiceNow’s Commercial and Regulated Markets environments. This role blends technical leadership with people management, requiring the ability to drive a transition from reactive operations to proactive, engineering-first practices while developing a high-performing team. Success in this role demands strong cross-functional collaboration and the ability to champion a “shift left” security mindset across the organization.
What you get to do in this role:
- Team Leadership & Development
- Lead, coach, and grow a team of highly effective engineers, fostering a culture of continuous learning and high performance through inclusive hiring practices, goal setting, individual development plans, and performance management.
- Operational Excellence & SLAs
- Own the end-to-end vulnerability lifecycle, ensuring the organization meets strict remediation SLAs and prioritizes risks based on actual business impact.
- Oversee the resolution of vulnerabilities across hybrid-cloud environments (AWS/Azure/GCP) and traditional on-premise infrastructure.
- “Shift Left” Advocacy
- Partner with DevOps and Engineering teams to integrate security earlier in the SDLC, ensuring vulnerabilities are identified and remediated during the design and build phases.
- Automation & AI Integration
- Identify opportunities to leverage AI and automation to streamline scanning, reporting, and triage, enabling the team to focus on complex risk analysis.
- Process & Program Improvement
- Identify and execute systems and process optimization opportunities that improve reliability, performance at scale, and operational efficiency.
- Stakeholder Partnership
- Act as a liaison between Security, Engineering, and Business leaders, translating technical debt into business risk to drive executive buy-in for remediation priorities.
- Operational Rigor
- Own early intervention, triage, and escalation response to ensure targets are met, driving cross-functional resolution with urgency and transparency.
Qualifications
To be successful in this role you have:
- Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving. This may include using AI-powered tools, automating workflows, analyzing AI-driven insights, or exploring AI's potential impact on the function or industry.
- 12+ years of related experience with a Bachelor's degree; or 8 years and a Master's degree; or a PhD with 5 years experience; or equivalent experience.
- 8 years of experience in vulnerability management, information security, or related cybersecurity roles, with 3+ years of people management experience.
- Deep understanding of vulnerability management tools and processes (e.g., Tenable, Trivy, Anchore), CI/CD pipelines, and cloud security across AWS, GCP, and Azure.
- Solid understanding of infrastructure services including Puppet, Ansible, Imaging, Artifactory, GitLab, and Kubernetes.
- Track record of effective cross-functional collaboration and level-appropriate communication to build consensus and drive complex initiatives.
- Strong communication skills, empa
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s