Staff Security Engineer, Security Operations
Job Description
Level up your security impact with autonomous, AI-driven SOC capabilities. In this Staff Security Engineer role on ServiceNow’s Moveworks Security team, you will design and implement incident response and proactive threat hunting powered by multi-agent frameworks and Model Context Protocol (MCP). The work is highly engineering-focused, with opportunities to architect resilient automation that helps corporate systems become “automation-ready,” while partnering across Security Engineering, DevOps, DevSecOps, Compliance, Cloud, and Infrastructure.
Location: Mountain View, CA (onsite).
Minimum experience: 5 years.
Responsibilities
- Build and orchestrate agentic security workflows: move beyond basic tool configuration to develop, code, design, and research advanced framework-level approaches for chaining MCP servers and AI agents.
- Stand up proactive threat hunting: architect and scale a proactive threat hunting program from scratch.
- Close the security feedback loop: create a high-signal feedback loop between the Blue Team and ServiceNow’s internally developed AI Red Team Agent.
- Partner across engineering and compliance: collaborate with IT, Security Engineering, DevOps, DevSecOps, Compliance, Cloud, and Infrastructure teams to ensure corporate systems are natively automation-ready.
- Own the incident response engineering roadmap: drive the end-to-end incident response lifecycle (Detection, Triage, Containment, Recovery) and replace traditional SOAR workflows with resilient, agentic orchestration.
- Escalation for complex incidents: serve as a high-tier technical escalation point for active, complex incidents.
- Prove reliability with simulation testing: design, execute, and validate automated simulation tests to demonstrate that agentic workflows and detection pipelines trigger reliably against real-world attack behaviors.
Requirements
- U.S. Citizenship Required: must meet strict compliance/FedRAMP criteria.
- Experience: 8–10 years in Security Operations, Systems Engineering, or DevSecOps (minimum 5 years of highly relevant engineering experience required).
- Cross-functional mastery: 3–5 years of proven experience working closely across Cloud Infrastructure, DevOps, DevSecOps, Compliance, and IT.
- AI and agentic fluency: deep familiarity with modern LLM agent frameworks, including active research into application, performance trade-offs, and behavioral guardrails.
- Automation engineering: high proficiency in Python and software engineering principles.
- Cloud and infrastructure depth: hands-on architectural familiarity with AWS security ecosystems (IAM, CloudTrail, GuardDuty) and containerized environments (Kubernetes/EKS).
- FedRAMP and trust awareness: communication skills and security compliance maturity to translate framework controls into automated, code-driven evidence generation pipelines.
- Team and collaboration dynamics: high-autonomy, high-collaboration mindset.
Technologies
Python, Model Context Protocol (MCP), LLM agent frameworks, MCP servers, AWS security ecosystems, IAM, CloudTrail, GuardDuty, Kubernetes, EKS, SOAR.
Work Persona / Location Notes
- Work personas (flexible, remote, or required in office) are assigned based on work nature and assigned work location.
- To determine eligibility, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.