Staff Application Security Engineer (ServiceNow Instance Security)

ServiceNow
Santa Clara, CA, United States
2 days ago
Apply on jobs.smartrecruiters.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$176,100.0 - $308,200.0
Working hours
Shift work

Tech stack

Artificial Intelligence Software System Penetration Testing User Authentication Software as a Service Cloud Computing Security Software Debugging Information Security Management Data Logging Application Enhancement Tool Software Security Servicenow Vulnerability Analysis

Job description

The ServiceNow Security Organization (SSO) delivers world-class, innovative security solutions to reduce risk and protect the company and our customers. We enable our customers to migrate their most sensitive data and workloads to the cloud, accelerating our business so that we are the most trusted SaaS provider. We create an environment where our employees are proud to work and can make a positive impact

About the Team

The Global Security Support Center (GSSC) plays a critical role in strengthening ServiceNow’s internal and external security posture and acts as a key interface with customers on security-related matters.

GSSC AppSec is a globally distributed team responsible for owning the Customer Penetration Testing & Security Findings (CPT & SF) program, partnering across the Security Organization to reduce risk, handle escalations, and represent the voice of the customer.

This role is focused on ServiceNow instance security, helping customers and internal teams identify, understand, and remediate insecure configurations and instance-level security gaps.

Role Summary

As an Staff Application Security Engineer in GSSC AppSec, you will secure ServiceNow instances by identifying configuration-driven security risks, validating customer-reported findings, and driving clear, actionable remediation guidance.

This is a hands-on technical role that blends application security expertise with deep ServiceNow platform knowledge. At the senior end of the range, you will operate with minimal direction, own complex instance-security problem spaces, and influence how GSSC AppSec scales instance security guidance and posture improvements globally.

Key Responsibilities

  • ServiceNow Instance Security & Hardening
  • Assess ServiceNow instance configurations against security baselines and identify misconfigurations that impact confidentiality, integrity, or availability.
  • Develop and maintain prescriptive instance-hardening guidance covering authentication, access controls, encryption, logging, monitoring, and operational security.
  • Translate security requirements and risk into clear, customer-consumable recommendations that can be implemented by teams with varying security maturity.
  • Identify recurring misconfiguration patterns and drive systemic improvements (guidance, tooling, checks).
  • AppSec & Customer Security Findings (CPT & SF)
  • Triage, validate, and contextualize customer-reported security findings where instance configuration or deployment patterns are a contributing factor.
  • Distinguish between product vulnerabilities vs. configuration issues, documenting impact and appropriate remediation paths.
  • Partner with Product Security, Engineering, and other Security teams to resolve complex or high-impact findings.
  • Support escalations and high-visibility customer interactions as an instance-security subject-matter expert., * Customers and internal teams receive clear, accurate, and actionable guidance to secure their ServiceNow instances.
  • Reduced repeat instance-security issues through improved baselines, guidance, and detection.
  • Faster, higher-confidence triage of customer-reported security findings tied to instance configuration.
  • GSSC AppSec becomes more scalable and consistent in how it addresses instance-level security risk., We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here. To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.

Requirements

  • Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving. This may include using AI-powered tools, automating workflows, analyzing AI-driven insights, or exploring AI’s potential impact on the function or industry.
  • 8+ years with strong foundation in application security (vulnerability analysis, secure design principles, threat modeling mindset). Or similar experience with education
  • Ability to read, write, and debug code to validate findings and understand security impact.
  • Experience translating security risk into actionable remediation guidance.
  • Excellent written and verbal communication skills, especially for customer-facing or executive-visible content., * Hands-on experience with the ServiceNow platform, especially platform security features, configuration, and administration.
  • Familiarity with SaaS security posture management and misconfiguration risk.
  • Prior experience supporting customer-reported security findings, escalations, or external security reviews.
  • Experience influencing security outcomes without direct authority (cross-functional collaboration).

Benefits & conditions

For positions in this location, we offer a base pay of $176,100 - $308,200, plus equity (when applicable), variable/incentive compensation and benefits. Sales positions generally offer a competitive On Target Earnings (OTE) incentive compensation structure. Please note that the base pay shown is a guideline, and individual total compensation will vary based on factors such as qualifications, skill level, competencies, and work location. We also offer health plans, including flexible spending accounts, a 401(k) Plan with company match, ESPP, matching donations, a flexible time away plan and family leave programs. Compensation is based on the geographic location in which the role is located and is subject to change based on work location.

About the company

It all started when engineer Fred Luddy wrote code that automated a tedious task for his coworker, Phyllis. She cried tears of joy. That moment inspired Fred to build a company that could do that for everyone-freeing people from busywork so they could focus on meaningful work. Today, ServiceNow is the AI control tower for business reinvention. Our ServiceNow AI platform brings together any AI, any data, and any workflow- helping 85% of the Fortune 500® work smarter, faster, and better. We’re building an AI-native culture where technology and talent are unstoppable together. And we’re just getting started.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.smartrecruiters.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 · World Congress 2025

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · World Congress 2025

3:55 min

Establishing blameless dialogue surrounding critical software security vulnerabilities

Chris Heilmann +2 · LIVE

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · World Congress 2023

Videos

See all

Related articles

See all