ServiceNow logo
ServiceNow

As the AI platform for business transformation, we're putting AI to work across organizations — freeing people for work that matters. Making old tech work with new tech. Reaching across departments, from the front office to the back office and every office in between. Our ambition? To become the AI defining enterprise software company of the 21st century (or "AI DESCO21C," as we like to call it). With more than 8,400+ customers, we serve approximately 90% of the Fortune 500®, and we're proud to be a Fortune 100 Best Companies to Work For® and World's Most Admired Companies™. Explore your future career with us, visit www.careers.servicenow.com From Fortune. ©2026 Fortune Media IP Limited. All rights reserved. Used under license.

Staff Software Engineer - Product Security

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 10,001+Since 2004H1B SponsorCompany SiteLinkedIn

Location

Israel

Posted

14 days ago

Salary

0

Seniority

Senior

English

Job Description

Staff Software Engineer - Product Security

ServiceNow

Company Description It all started when engineer Fred Luddy wrote code that automated a tedious task for his coworker, Phyllis. She cried tears of joy. That moment inspired Fred to build a company that could do that for everyone-freeing people from busywork so they could focus on meaningful work. Today, ServiceNow is the AI control tower for business reinvention. Our ServiceNow AI platform brings together any AI, any data, and any workflow- helping 85% of the Fortune 500® work smarter, faster, and better. We're building an AI-native culture where technology and talent are unstoppable together. And we're just getting started. Join us to put AI to work for people. Job Description ServiceNow's Product Security organisation is building a dedicated Security R&D function - a software engineering team that builds security capabilities with the same engineering rigour as ServiceNow's product organisation. We are looking for a Staff Security Engineer to be a core contributor on this team. Security R&D operates in two complementary modes: open contribution to product engineering - writing code alongside product teams where security expertise adds value - and developing its own security capabilities, including internal tooling, externally facing product features, AI-powered security automation, and third-party integrations. This is a new team being stood up in Petah Tikva, Israel, co-located with ServiceNow's AI Security Research team. You will help shape the team's engineering practices and technical foundation from day one. This role reports to the Sr. Engineering Manager, Security R&D. What You Will Do Build Security Capabilities - Design and develop security tooling, automation, and platform services that operate at ServiceNow's enterprise scale. - Contribute code directly into ServiceNow product engineering codebases, embedding security capabilities where they have the highest impact. - Build AI-powered security automation by integrating in-house models and third-party services into production workflows. - Leverage ServiceNow's platform - Agent Framework runtime, ACL enforcement, data layer, and workflow engine - to create security capabilities that external vendors cannot match. Collaborate Across Teams - Work closely with the AI Security Research team on tooling for AI agent security, translating research insights into production-grade engineering. - Partner with product engineering teams during open contribution engagements, earning trust through code quality, reliability, and delivery. - Participate in design reviews, code reviews, and architecture discussions, contributing to the team's technical standards and engineering culture. Grow with the Team - Help define engineering best practices as a founding member of the Security R&D team. - Contribute to hiring and onboarding as the team scales, helping maintain the engineering bar. - Stay current on emerging AI/ML technologies and security threats, bringing new ideas into the team's roadmap. What Makes This Role Unique - Builder-led culture: Security R&D is defined by engineering output, not advisory reviews. We build production security capabilities with the same discipline as product engineering. - Dual operating model: The team both contributes directly to product engineering and develops its own security products and services. - Platform advantage: ServiceNow owns the entire stack - runtime, ACLs, data layer, workflow engine. You will build security capabilities that no external vendor can replicate. - Founding team: This is a new team being built from scratch. You will shape its engineering culture, technical standards, and identity from day one. - AI intersection: The role sits alongside the AI Security Research team, placing you at the frontier of securing AI systems at enterprise scale. Qualifications To be successful in this role, you have: - 8+ years of professional software engineering experience building production systems at scale. - Bachelor's degree in Computer Science, Engineering, or a related technical field. - Strong hands-on proficiency in Python and Java. You write production code daily and take pride in software craftsmanship. - Solid foundation in distributed systems, cloud-native architectures, and building services that meet enterprise requirements for scalability, reliability, and performance. - Experience working in collaborative engineering environments, contributing to shared codebases with high code quality standards. - Interest in or exposure to security engineering concepts - application security, infrastructure security, identity systems, or trust & safety. A security mindset is valued; deep security expertise can be developed on the team. - Curiosity about AI/ML and next-generation AI technologies. You don't need to be an AI expert, but you should be excited about building at the intersection of security and AI. Preferred - Experience with security tooling development, SSDLC automation, or building security features into a product. - Familiarity with container/Kubernetes environments, cloud security, or infrastructure-as-code. - Exposure to AI/ML pipelines, LLM integration, or agentic frameworks. - Experience in a SaaS or platform company building multi-tenant enterprise software. - Experience working in a globally distributed engineering team. Additional Information Work Personas We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here . To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service. Equal Opportunity Employer ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements. Accommodations We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact globaltalentss@servicenow.com for assistance. Export Control Regulations For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities. From Fortune. ©2026 Fortune Media IP Limited. All rights reserved. Used under license. .

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 11-50

Role Description Dynamic Solutions Technology, LLC, a premier strategic services firm that meets IT and Service needs for commercial and government clients, is seeking a full-time IT Asset Management Program Manager. This is an exempt remote position in support of a government customer in NJ. Must Be U.S. Citizen. - Lead the planning, execution, governance, and continuous improvement of the IT Asset Management (ITAM) Program, ensuring alignment with organizational objectives, federal regulations, and industry best practices. - Develop, maintain, and manage the ITAM Program Management Plan (PMP), establishing program governance, performance measures, resource requirements, and operational priorities. - Create and maintain detailed Work Breakdown Structures (WBS), Integrated Master Schedules, and program roadmaps to effectively manage scope, schedule, deliverables, and dependencies across Hardware Asset Management (HAM) and Software Asset Management (SAM) initiatives. - Direct program planning activities, including milestone development, resource allocation, budget forecasting, cost estimation, and financial tracking to ensure efficient use of program resources. - Monitor and evaluate program performance against established goals, objectives, key performance indicators (KPIs), and service-level expectations, providing recommendations for corrective actions and continuous improvement. - Develop and maintain HAM and SAM Strategic Roadmaps that support long-term modernization efforts, operational efficiency, compliance objectives, and lifecycle management strategies. - Lead enterprise risk and issue management activities by developing Risk and Issue Management Plans, maintaining Risk Registers, assessing program impacts, and implementing mitigation strategies. - Prepare and deliver executive-level program status reports, briefings, dashboards, and performance analyses that communicate progress, risks, issues, accomplishments, and strategic recommendations. - Coordinate stakeholder engagement activities, including governance meetings, working groups, executive briefings, and collaborative planning sessions to ensure transparency, communication, and alignment among stakeholders. - Support audit readiness and compliance initiatives by maintaining program documentation, preparing audit evidence, and ensuring adherence to federal regulations, VA policies, and ITAM governance requirements. - Manage program documentation repositories, action item trackers, meeting minutes, lessons learned, and knowledge management activities to promote organizational continuity and effective decision-making. - Collaborate with government leadership, technical teams, financial managers, acquisition personnel, and external oversight organizations, including GAO and Congressional stakeholders, to address inquiries, support reporting requirements, and advance strategic ITAM program objectives. Qualifications - BA in IT Management or Program/Project Management - 8+ years of IT program management - Minimum 5 years with Agile methodologies and project management - Public Trust Level Requirements - Serving as the Contractor's main point of contact and overall performance - Responsible for all aspects of the development and implementation of assigned projects and provides a single point of contact for those projects - Takes projects from original concept through final implementation. - Interfaces with all areas affected by the project including end users, computer services, and client services. - Defines project scope and objectives. Develops detailed work plans, schedules, project estimates, resource plans, and status reports. - Conducts project meetings and is responsible for project tracking and analysis. - Ensures adherence to quality standards and reviews project deliverables. - Manages the integration of vendor tasks and tracks and reviews vendor deliverables. - Provides strategic, technical and analytical guidance to project team. - Recommends and takes action to direct the analysis and solutions of problems from experience advising senior leadership on IT strategic work. Desired Qualifications - PMP/PMI certification - Excellent communication - Solid relationship builder - Quality Certification (ITIL, or other)

United States
LED FastStart logo

AWS Cloud Security and ICAM Specialist

LED FastStart

We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.

Full TimeRemoteTeam 51-200

Role Description The AWS Cloud Security and ICAM Specialist supports the Case Management Modernization (CMM) Program for the Administrative Office of the U.S. Courts (AO) by designing, implementing, and managing secure authentication and authorization frameworks across modernized cloud-based applications. This role ensures compliance with federal identity governance, FedRAMP, and Zero Trust Architecture (ZTA) principles within an AWS environment. The ICAM Specialist collaborates with architecture, security, and DevSecOps teams to ensure access control, identity federation, and credential management are integrated seamlessly across all layers of the CMM application ecosystem. - Design and maintain the ICAM architecture for identity, access, and authentication management across AWS-hosted CMM applications and other legacy ICAM. - Implement federated identity and single sign-on (SSO) solutions using modern protocols (SAML, OAuth2.0, OIDC). - Collaborate with Cloud and Security Architects to enforce Zero Trust Architecture (ZTA) across microservices and APIs. - Configure and maintain directory services and identity providers (e.g., AWS Cognito, AWS IAM Identity Center, Azure AD, IBM Verify, Key Cloak). - Deep experience integrating KeyCloak as a broker IdP federating upstream enterprise IdPs while issuing downstream OIDC token to application. - Design ICAM brokerage solutions and support compliance assessments, ensuring adherence to FISMA, NIST 800-63, and FedRAMP security controls. - Develop and document identity lifecycle management processes — provisioning, deprovisioning, and access reviews. - Design and implement least privileged roles, groups, functionalities based on ZTA for both privileged and non-privileged users for a FedRAMP High system. - Experience defining workflow, rules, policies within ICAM tools particularly IBM Verify and Key Cloak. - Conduct access audits, user entitlement reviews, and anomaly detection to ensure least-privilege compliance. - Provide subject matter expertise in identity federation, PKI, certificate management, and secure API authorization. - Design strategies for logging, monitoring and auditing authentication and authorization related events in combination with other AWS event logs. - Design and implement storage level, microservice level Authentication and Authorization. - Support ATO process by providing solutions to all security controls, document implementation plan, maintain Visio diagrams. - Participate in design sessions and work closely with the security lead. - Collaborate with DevSecOps teams to embed ICAM policies within CI/CD pipelines and Infrastructure-as-Code (IaC) templates. - Direct and lead Pen testing, Review architecture diagrams produced by different teams. - Independently lead design and implement of vulnerability management. - Heavily participate in ATO activity. - Lead and direct engineering team. Deliverable Alignment & Performance Outcomes - Architecture Diagrams: Depicting identity flow, federation, and integration points with AWS and CMM systems. - Access Control Documentation: Policies, RBAC models, and credential management workflows. - Compliance Verification Reports: Audit results aligned to NIST 800-63, FedRAMP, and FISMA standards. - Zero Trust Implementation Artifacts: Documentation and verification of ZTA enforcement within system components. - Performance Outcomes: - 100% of CMM applications integrated with SSO and MFA. - Zero unauthorized access incidents attributable to configuration error. - 100% compliance with NIST and FedRAMP ICAM control requirements. - Reduced account provisioning time by ≥30% through automation. Tools & Technologies - IAM & Federation: Key Cloak, Okta. - Access & Compliance: SailPoint, CyberArk, HashiCorp Vault. - Cloud: AWS IAM, KMS, CloudTrail, Lambda. - Protocols: SAML, OAuth2.0, OIDC, SCIM. - Monitoring & Audit: Splunk. - Collaboration: Jira, Confluence, SharePoint, MS Teams. Qualifications - Bachelor’s Degree in Cybersecurity, Information Systems, or related discipline required; Master's Degree preferred. - 10+ years of experience in identity and access management, including 8+ years in cloud-based federal environments required; 12+ years of experience in information systems preferred. - Hands-on experience with Key Cloak and AWS IAM Identity Center for SSO and MFA implementations. (IBM Verify a plus). - Strong knowledge of identity federation protocols (SAML, OAuth2.0, OIDC, SCIM) and modern authentication flows. - Expertise with RBAC/ABAC frameworks, policy-based access control, and least-privilege enforcement. - Familiarity with NIST 800-63, FISMA, FedRAMP, and ZTA standards and compliance frameworks. - Experience implementing ICAM solutions in Agile and DevSecOps environments. - Working knowledge of PKI, digital certificates, and encryption technologies. - Strong analytical and troubleshooting skills with ability to resolve identity integration issues. - Experience with AWS Container Security and Network Security (preferred, not required). - Expert in designing logging and monitoring system by correlating events from several AWS and ICAM system. - Experience supporting federal digital modernization or judiciary IT programs. - Familiarity with Zero Trust Architecture and micro segmentation principles. - Exposure to API gateway authentication (Kong, Apigee, AWS API Gateway). - Experience integrating identity governance tools (SailPoint, Saviynt). - Excellent presentation and communication skills. - Consultant mindset with the ability to work with high level customer stakeholders and build excellent customer relationship. - Experience identifying and applying industry tools, solutions, methods best practices, and emerging technologies. - Strong analytical skills and problem-solving skills with the ability to formulate and communicate recommendations for improvement. - Demonstrated ability to work effectively, independently, and as part of a team. Certification(s) - Certified Information Systems Security Professional (CISSP) - preferred. - AWS Certified Security – Specialty or Azure Identity & Access Administrator – preferred. - Certified Identity and Access Manager (CIAM) or Certified Identity Professional (CIP) – beneficial. - SAFe Practitioner (SPC/SSM) – a plus. Location - Remote. Salary Information The likely salary range for this position is $153,000 - $207,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range. Benefits - Medical plan options, some with Health Savings Accounts. - Dental plan options. - Vision plan. - 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. - Full flex work weeks where possible. - Variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. - 15 days of paid leave per calendar year to be used for vacations, personal business, and illness. - 10 paid holidays per year. - GDIT Paid Family Leave program provides a total of up to 160 hours of paid leave in a rolling 12 month period for eligible employees. - Short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance.

United States
$153K - $207K / year
General Dynamics logo

Contract Security, Compliance, Access Analyst

General Dynamics

A business unit of General Dynamics, General Dynamics Information Technology (GDIT) supports some of the United States' most complex government, defense, and in

• Lead and manage program activities that ensure full compliance with Controlled Unclassified Information (CUI) standards, contract security requirements, and personnel access policies, contributing to the secure and timely deployment of the IHS EHRM initiative • Collaborate with GDIT and client security teams to coordinate security clearance processes, facility access, and onboarding workflows that enable project personnel to be mission‑ready • Drive timely and accurate resolution of security, compliance, and access challenges by ensuring regulations are properly applied, documentation is validated, and data is kept precise within security and access management systems • Utilize security and access databases, Microsoft Excel, and HR workflow systems to maintain personnel records, quality‑check clearance packets, support audits, and ensure security‑related actions meet contract and federal requirements

United States
$85.1K - $109.3K / year
Job Closed
General Dynamics logo

AWS Cloud Security, ICAM Specialist

General Dynamics

A business unit of General Dynamics, General Dynamics Information Technology (GDIT) supports some of the United States' most complex government, defense, and in

• Supports the Case Management Modernization (CMM) Program for the Administrative Office of the U.S. Courts (AO) • Designing, implementing, and managing secure authentication and authorization frameworks across cloud-based applications • Ensures compliance with federal identity governance, FedRAMP, and Zero Trust Architecture (ZTA) principles within an AWS environment • Collaborates with architecture, security, and DevSecOps teams to ensure access control, identity federation and credential management are integrated seamlessly across all layers of the CMM application ecosystem • Designs and maintains the ICAM architecture for identity, access, and authentication management across AWS-hosted CMM applications and other legacy ICAM • Implements federated identity and single sign-on (SSO) solutions using modern protocols (SAML, OAuth2.0, OIDC) • Collaborates with Cloud and Security Architects to enforce Zero Trust Architecture (ZTA) • Configures and maintains directory services and identity providers (e.g., AWS Cognito, AWS IAM Identity Center, Azure AD, IBM Verify , Key Cloak)

California
$153K - $207K / year