Staff Security Engineer | Security Configuration Management
ServiceNowAbout the role
Company Description
It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today — ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500®. Our intelligent cloud-based platform seamlessly connects people, systems, and processes to empower organizations to find smarter, faster, and better ways to work. But this is just the beginning of our journey. Join us as we pursue our purpose to make the world work better for everyone.
Job Description
The ServiceNow Security Organization (SSO):
The ServiceNow Security Organization (SSO) delivers world-class, innovative security solutions to reduce risk and protect the company and our customers. We enable our customers to migrate their most sensitive data and workloads to the cloud, accelerating our business so that we are the most trusted SaaS provider. We create an environment where our employees are proud to work and can make a positive impact.
Role Overview:
ServiceNow’s Security Configuration Management team ensures secure configuration across our global environments by defining, monitoring, and improving configuration baselines across operating systems, cloud platforms, and containerized workloads.
We use and help shape our own ServiceNow SecOps products while integrating with modern scanning and security tools. We are also advancing toward an AI-driven future for proactive, self-healing configuration security.
What You’ll Do:
- Lead the implementation and improvement of secure configuration baselines across multiple environments and technologies, including containerized workloads and Kubernetes.
- Integrate and optimize scanning tools (e.g., Tenable, Wiz, Trivy) and support evaluation of emerging technologies.
- Enhance and operate ServiceNow’s SecOps Configuration Compliance workflows, reporting, and data quality.
- Develop and refine risk-based prioritization and remediation models.
- Partner with product, platform, compliance, and security engineering teams to drive practical remediation and influence roadmap improvements.
- Support the strategic vision for AI-assisted configuration management, automation, and policy-driven remediation.
Qualifications
To be successful in this role you have:
- Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving. This may include using AI-powered tools, automating workflows, analyzing AI-driven insights, or exploring AI’s potential impact on the function or industry.
- 8+ Years Experience managing configuration compliance or vulnerability scanning tools (e.g., Tenable, Wiz, Qualys, OpenSCAP, Trivy) or a Bachelor’s degree in Computer Science, Engineering, or equivalent professional experience.
- Strong knowledge of Linux/Unix and/or Mac/Windows operating systems and secure hardening principles.
- Programming or scripting proficiency (Python, PowerShell, Java, C, or similar) to automate workflows and analyze data.
- Hands-on experience with AWS, Azure, and/or Google Cloud environments.
- Experience with container platforms (Docker, Kubernetes, OpenShift) and related configuration/security considerations.
- Familiarity with CIS Benchmarks, STIGs, PCI, NIST, or other security configuration frameworks.
- Understanding of infrastructure vulnerabilities, risk assessment methods, and remediation priorities.
- Fundamental understanding of systems and network engineering, including operating system configuration and network communication (OSI model).
- Strong foundation in AI concepts, including how to use, integrate, and automate workflows with AI agents, and awareness of how AI can accelerate configuration management.
- Experience collaborating in distributed/remote environments with cross-functional technical teams globally.
- Ability to articulate complex technical issues to both engineers and executive stakeholders.
- Strong analytical and problem-solving approach; able to think both technically and strategically.
- Effective written and verbal communication skills and ability to build trust with diverse partners.
- Comfortable working with evolving requirements and adapting to change.
- Minimum of 5 years of experience performing Vulnerability and/or Security Configuration Management
- Understanding and experience with Federal, PCI Compliance and Security Frameworks
- Familiarity with the ServiceNow Platform, especially SecOps Configuration Compliance, is a plus.
- Proficiency working in an Agile environment, includin
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s