> Markdown version of [/jobs/ext/2715069-soc-analyst](https://www.wearedevelopers.com/jobs/ext/2715069-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC analyst - **Company:** ServiceNow - **Location:** United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Systems Engineering, Cloud Computing, Cyber Security, Data Security, DevOps, Identity and Access Management, Python (Programming Language), Red Team (Cyber Security), Software Engineering, Large Language Models, Software Security, Containerization, Kubernetes, Purple Team (Cyber Security), Devsecops, Blue Team (Cyber Security), Servicenow - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/staff-security-engineer-security-operations-moveworks-servicenow-9756401 ## About the Role * Experience: 8-10 years of experience in Security Operations, Systems Engineering, or DevSecOps (Minimum 5 years of highly relevant engineering experience required). * Cross-Functional Mastery: 3-5 years of proven track record working closely across multidisciplinary teams including Cloud Infrastructure, DevOps, DevSecOps, Compliance, and IT. Bonus points for direct collaboration experience with Product Security or Data Security teams. * AI & Agentic Fluency: Deep familiarity with modern LLM agent frameworks, including active research into their application, performance trade-offs, and behavioral guardrails. You know how to deeply integrate LLMs, orchestrate custom MCP servers, and build autonomous technical workflows. * Automation Engineering: High proficiency in Python and software engineering principles. You have extensive past experience with traditional workflow engines and legacy SOAR tooling, giving you the context needed to successfully replace them with AI-native alternatives. * Cloud & Infrastructure Depth: Strong, hands-on architectural familiarity with AWS security ecosystems (IAM, CloudTrail, GuardDuty) and containerized environments (Kubernetes/EKS). * FedRAMP & Trust Awareness: While an engineer first, you possess the communication skills and security compliance maturity to translate framework controls into automated, code-driven evidence generation pipelines. * Team & Collaboration Dynamics: A high-autonomy, high-collaboration mindset. You thrive in a lean, elite, fast-moving team environment where you independently drive massive technical impact while mentoring and leveling up surrounding engineers. ## Description * Building and AI Orchestration: Move beyond basic tool configuration to build, code, design and research advanced, framework-level approaches for chaining MCP servers and AI agents. You will optimize agentic networks for maximum performance, multi-step reasoning accuracy, and deterministic outcomes in high-stress security scenarios. * Proactive Threat Hunting Program: Architect and scale a proactive threat hunting program from scratch. You will leverage custom agents, MCP capabilities, and security tooling to proactively discover complex vulnerabilities, configuration drift, and hidden threats across the infrastructure network. * Advanced Purple Team Synergies: Forge a cutting-edge feedback loop between the Blue Team and our internally developed AI Red Team Agent. You will seamlessly bridge automated offense and defense, turning threat hunting insights into self-healing infrastructure. * Cross-Functional Influence & Leadership: Act as a strategic engineering partner across IT, Security Engineering, DevOps, DevSecOps, Compliance, Cloud, and Infrastructure teams to ensure corporate systems are natively "automation-ready." * E2E IR Automation Architecture: Own the overarching engineering roadmap for the end-to-end incident response lifecycle (Detection * Triage * Containment * Recovery), replacing traditional SOAR workflows with resilient, agentic orchestration. * Incident Commander Escalation: Serve as a high-tier technical escalation point for active, complex incidents. Use every incident as an adversarial data point to design superior automated immune responses. * Validate the Defense: Design, execute, and validate automated simulation testing to systematically prove that agentic workflows and detection pipelines trigger reliably against real-world attack behaviors., We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here. To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service., For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [From Prototype to Production: Build AI Agents with This Free 4-Course Learning Path](https://www.wearedevelopers.com/magazine/655-from-prototype-to-production-build-ai-agents-with-this-free-4-course-learning-path) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)