As the AI platform for business transformation, we're putting AI to work across organizations — freeing people for work that matters. Making old tech work with new tech. Reaching across departments, from the front office to the back office and every office in between. Our ambition? To become the AI defining enterprise software company of the 21st century (or "AI DESCO21C," as we like to call it). With more than 8,400+ customers, we serve approximately 90% of the Fortune 500®, and we're proud to be a Fortune 100 Best Companies to Work For® and World's Most Admired Companies™. Explore your future career with us, visit www.careers.servicenow.com From Fortune. ©2026 Fortune Media IP Limited. All rights reserved. Used under license.
Senior Security Engineer, Security Operations - Moveworks
Location
United States
Posted
65 days ago
Salary
0
Seniority
Senior
No structured requirement data.
Job Description
Senior Security Engineer, Security Operations - Moveworks
ServiceNow
Company Description Who we are Moveworks is the Agentic AI Assistant platform that empowers the entire workforce. Our platform enables employees to converse with all of their business systems through natural language to quickly find answers and automate tasks. Powered by the world's most advanced LLMs, our proprietary models, and a sophisticated Agentic AI platform, we're transforming how work gets done by allowing AI to take initiative, streamline complex workflows, and continuously learn and adapt. Moveworks is trusted by over 5.5 million employees at more than 350 of the world’s largest companies, including 10% of the Fortune 500, to automate everyday tasks and streamline business operations. Recognized on the Forbes Cloud 100 and AI 50 lists, Moveworks was also named one of Fast Company’s 2025 Most Innovative Companies and Inc’s Best in Business, in the Best in Innovation category. Moveworks was also recognized at Microsoft’s 2025 Partner of the Year and in 2024, received the AI Breakthrough Award. In December 2025, Moveworks was acquired by ServiceNow, marking a pivotal milestone in our journey to create a single front door to work for all business systems. By combining ServiceNow’s leading workflow automation with Moveworks’ Reasoning Engine and natural language capabilities, we deliver the AI platform for every person and every workflow. Built to go beyond basic summaries to deliver meaningful business impact. Together, our AI acts across enterprise systems to turn conversations into completed work. By joining our team, you’ll be at the forefront of the AI transformation, backed by the global scale of ServiceNow and the agility of a high-growth company. We are looking for world-class talent to help us extend agentic AI to every employee across every corner of the business. Come join us! ServiceNow It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today — ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500®. Our intelligent cloud-based platform seamlessly connects people, systems, and processes to empower organizations to find smarter, faster, and better ways to work. But this is just the beginning of our journey. Join us as we pursue our purpose to make the world work better for everyone. Job Description The Moveworks Security team at ServiceNow is not looking for a traditional SOC analyst to watch a dashboard. We are looking for a Security Automation Disruptor. Your goal is to automate the SOC out of existence. As a member of our Blue Team, you will treat the incident response lifecycle as an engineering problem—designing, building, and deploying autonomous workflows that handle detection, triage, and remediation at machine speed. You will be at the intersection of core Security Operations and AI-driven defense. What you get to do in this role: - E2E IR Automation: Design and implement end-to-end automation for the IR lifecycle (Detection -> Triage -> Containment -> Recovery). - Detection Engineering: Build and tune high-fidelity detections in our SIEM, EDR, and AI SOC platforms - AI-Driven Ops: Leverage LLMs, Prompt Engineering, and MCP (Model Context Protocol) servers to build "Agentic" security workflows that scale our defensive capabilities. - Purple Teaming: Detect and disrupt our internal red team. You will work closely with the Red team to detect their attacks, disrupt their attack path, and close vulnerabilities. - Validate the Defense: Don’t just build it—prove it works. Design and execute automated tests to validate that our detections and playbooks actually fire when they should. - Decide with Data: Be data driven, when faced with difficult or complex decisions, you quickly gather data to make informed decisions - Incident Response: Support active incidents as an incident responder, using each event as data to build better future automation. Qualifications To be successful in this role you have: - U.S. Citizenship required - The Mindset: You hate manual work. You see a repetitive task and immediately think about how to write a script or build an Agent to do it for you. - Technical Foundation: 1–5 years of experience in Security Operations or Security Engineering. - Automation Fluency: Proficiency in Python. You should be comfortable working with APIs, webhooks, and version control systems (Git). - AI Native: You don't just use ChatGPT; you understand Prompt Engineering, how to connect MCP servers, and how to integrate LLMs into technical workflows. - Cloud Proficiency: Hands-on experience with AWS (IAM, CloudTrail, GuardDuty). Experience with Kubernetes (EKS) is a major plus. - FedRAMP Readiness: While you are an engineer first, you have the soft skills to interpret control frameworks while understanding how to generate and present evidence to ensure we are in compliance. Additional Information Work Personas We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here. To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service. Equal Opportunity Employer ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements. Accommodations We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact [email protected] for assistance. Export Control Regulations For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities. From Fortune. ©2025 Fortune Media IP Limited. All rights reserved. Used under license. - Employee Type: Regular - Region: AMS - North America and Canada - Work Persona: Flexible or Remote
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
Security Incident Response Specialist, Fluent Ukrainian
SupportYourAppSupport-as-a-Service that helps companies scale faster by taking care of their customers’ needs.
• Забезпечувати повний цикл розслідування та координації дій у відповідь на порушення безпеки або робочих процесів • Вести комунікацію з клієнтами та стейкхолдерами під час Data Breach інцидентів • Проводити Root Cause Analysis інцидентів, розробляти превентивні заходи та готувати звітність для топменеджменту • Аналізувати операційні процеси клієнтів з урахуванням інцидентів для виявлення потенційних загроз та формувати рекомендацій щодо проактивного підвищення рівня безпеки • Перевіряти безпеку постачальників, програмних платформ та сторонніх сервісів • Здійснювати аудит нових локацій для найму щодо відповідності стандартам захисту даних і впровадження інструментів безпеки • Готувати документацію та процедури управління інцидентами, а також підтримувати внутрішню базу знань.
VM Engineer - Security operations
DaviesAt Davies North America, we’re at the forefront of innovation and excellence, blending cutting-edge technology with top-tier professional services. As a vital part of the global Davies Group, we help businesses navigate risk, optimize operations, and spearhead transformation in the insurance and regulated sectors.
VM Engineer - Security operations Department: IT Employment Type: Permanent - Full Time Location: Home India Description The Vulnerability Detection and Remediation SME is responsible for leading the organization's efforts in identifying, assessing, and remediating vulnerabilities across IT infrastructure, applications, and cloud environments. This role requires deep technical expertise, strategic thinking, and the ability to collaborate across teams to ensure a robust security posture. Key Responsibilities - Lead the enterprise-wide vulnerability management program, including detection, prioritization, and remediation. - Conduct regular vulnerability scans using tools like Qualys, Tenable Nessus, Rapid7, and analyze results to identify risks. - Collaborate with IT, DevOps, and application teams to ensure timely patching and remediation of vulnerabilities. - Hands-on experience in patching using different patching tools on different OS, Applications, Cloud and Networks etc. - Develop and maintain vulnerability management policies, procedures, and playbooks. - Provide SME-level guidance on scanning signatures, detection capabilities, and remediation strategies. - Monitor threat intelligence feeds and correlate with internal vulnerability data to assess risk. - Host remediation meetings with stakeholders and track progress of corrective actions. - Ensure compliance with industry standards such as NIST, ISO 27001, PCI-DSS, HIPAA. - Generate detailed reports and dashboards for leadership on vulnerability trends and remediation status. - Support incident response teams with vulnerability exploitation insights and mitigation strategies. - Continuously improve scanning, reporting, and remediation processes through automation and orchestration tools (e.g., Service Now, MS Sentinel, Ansible, Terraform, Splunk Phantom). Skills, Knowledge & Expertise - Bachelor’s degree in computer science, Information Security, or related field. - 5+ years of experience in vulnerability management or cybersecurity. - Strong knowledge of operating systems (Windows, Linux), network protocols, and cloud platforms. - Hands-on experience with vulnerability management platforms (e.g., Qualys VMDR, Tenable.io, Rapid7 InsightVM). - Familiarity with patch management tools (e.g., Intune, Qualys, PatchmyPC, Automox WSUS, etc…). - Excellent analytical, communication, and problem-solving skills. - Experience with threat modeling techniques (e.g., STRIDE, DREAD). - Knowledge of forensic tools and incident response procedures. - Experience in scripting (e.g., Python, PowerShell) for automation. - Familiarity with SIEM platforms (e.g., Splunk, Sentinel, QRadar). - ITIL Foundation certification. - Experience with other ITSM tools and platforms. - Intune / Qulays
• Run daily, weekly, and periodic IT and security checklists • Troubleshoot issues, document fixes, and raise follow-up actions as needed • Perform health checks across infrastructure and DevOps (e.g. uptime, CI/CD, compliance, alerts) • Collaborate with DevOps and InfraOps on platform-level issues • Monitor and action items in the IT support queue with a proactive approach • Prioritize tasks effectively and align timelines with stakeholders • Deliver empathetic, solutions-oriented support across systems, hardware, and software • Identify and propose improvements as you gain business context • Work cross-functionally to implement automation, tooling, and platform enhancements • Contribute to scripts, dashboards, and operational improvements • Feed insights from day-to-day work into long-term strategic initiatives
Federal Security Operations - SkillBridge Intern
ZscalerWe make it easy to secure your cloud transformation. Get fast, secure, and direct access to apps without appliances.
About Zscaler Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise, we are constantly pushing the envelope, leveraging the world’s largest security data lake to power our cloud-native Zero Trust Exchange platform. This innovation protects our customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Here, impact in your role matters more than title and trust is built on results. We say, impact over activity. We seek innovators who actively use AI to amplify their impact and who thrive in an environment where we leverage intelligent systems to stay ahead of evolving threats. We believe in transparency and value constructive, honest debate—we’re focused on getting to the best ideas, faster. We build high-performing teams that can make an impact quickly and with high quality. To do this, we are building a culture of execution centered on customer obsession, collaboration, ownership, and accountability. We value high-impact, high-accountability with a sense of urgency where you’re enabled to do your best work and embrace your potential. If you’re driven by purpose, thrive on solving complex challenges, and want to be part of the team that’s helping to secure the AI age, we invite you to bring your talents to Zscaler and help shape the future of cybersecurity. Role We are looking for a Federal Security Operations - SkillBridge Intern to join our Enterprise Security team. This is a remote role, reporting to the Director of Federal Security Operations and Insider Threat. Our Federal Security team is a mission-focused group dedicated to defending critical infrastructure and government data through proactive detection and rapid incident response. We leverage advanced telemetry and automation to identify innovative solutions to complex threats. Together, we foster a high-integrity, security-first culture that ensures our federal customers can operate securely in a cloud-first world. What you’ll do (Role Expectations) - Establish success criteria, metrics, milestones, and timelines for deployment projects and ensure projects remain on track. - Maintain project tracking and customer issue documentation within appropriate systems and databases. - Build and maintain well-established relationships with key customer stakeholders. - Perform welcome calls with customers, describing the service, tools, and process. Who You Are (Success Profile) - You act like an owner. Your passion for the mission fuels your bias for action, and you navigate seamlessly between high-level strategy and hands-on execution. - You are a problem-solver. You seek out challenges because you are energized by finding solutions, knowing that solving the hard problems delivers the biggest impact. - You are driven by innovation. You have a deep curiosity for how things work and believe in the power of technology to accelerate transformation. - You are a pragmatic builder. You are obsessed with creating, iterating, and shipping, and you aren't afraid to roll up your sleeves to build the first version yourself. - You are data-driven. You use data and analytics to find the truth and value evidence over assumptions to drive better outcomes. What We’re Looking for (Minimum Qualifications) - Experience in a Military SOC: Prior experience operating within a Cyber Defensive Operations environment (e.g., NCDOC, CPT, or similar). - Technical Proficiency: Familiarity with SIEM/XDR platforms such as Crowdstrike Falcon Next-gen SIEM, Splunk, or Google SecOps. - Must have 180 days of service or fewer remaining prior to your date of discharge and at least 180 continuous days of active service. - Obtain approval from your unit commander. - MOU must be approved and submitted before start. What Will Make You Stand Out (Preferred Qualifications) - Professional experience or familiarity operating solutions built on Azure, AWS, and GCP. - Experience with Hypervisors such as VMware, Hyper-V, and KVM. - Working knowledge of authentication systems such as SAML, LDAP, and MS Active Directory. #LI-remote #LI-TJ1 At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure. Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including: - Various health plans - Time off plans for vacation and sick time - Parental leave options - Retirement options - Education reimbursement - In-office perks, and more! Learn more about Zscaler’s Future of Work strategy, hybrid working model, and benefits here. By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines. Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws. See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegal link. Pay Transparency Zscaler complies with all applicable federal, state, and local pay transparency rules. Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.



