ServiceNow logo
ServiceNow

As the AI platform for business transformation, we're putting AI to work across organizations — freeing people for work that matters. Making old tech work with new tech. Reaching across departments, from the front office to the back office and every office in between. Our ambition? To become the AI defining enterprise software company of the 21st century (or "AI DESCO21C," as we like to call it). With more than 8,400+ customers, we serve approximately 90% of the Fortune 500®, and we're proud to be a Fortune 100 Best Companies to Work For® and World's Most Admired Companies™. Explore your future career with us, visit www.careers.servicenow.com From Fortune. ©2026 Fortune Media IP Limited. All rights reserved. Used under license.

Senior Staff Security Incident Commander

Security EngineerSecurity EngineerFull TimeRemoteLeadTeam 10,001+Since 2004H1B SponsorCompany SiteLinkedIn

Location

United States + 1 moreAll locations: United States | Canada

Posted

9 days ago

Salary

$165.5K - $289.6K / year

Seniority

Lead

Job Description

Senior Staff Security Incident Commander

ServiceNow

Role Description The ServiceNow Security Organization (SSO) delivers world-class, innovative security solutions to reduce risk and protect the company and our customers. We enable our customers to migrate their most sensitive data and workloads to the cloud, accelerating our business so that we are the most trusted SaaS provider. We create an environment where our employees are proud to work and can make a positive impact. ServiceNow’s Security Incident Command (SIC) team is seeking an experienced senior security incident commander to join our fast-growing team. This role will support the orchestration of incident response strategy and communications during critical information security-related incidents. The SIC team maintains and executes the Major Security Incidents (MSI) lifecycle within ServiceNow, including Preparation, Response, and Recovery. MSIs are our most challenging and impactful security incidents which pose active or heightened risk to the company and/or our customers. - Orchestration of response and remediation of incident response for highest criticality security events. - Take ownership and lead response to critical incidents within the company. - Establish and mature documentation surrounding protocols and procedures governing the security incident command team. - Prepare and deliver communications, including executive summaries and incident briefings, to key stakeholders during and after incident response. - Conduct rapid response, mitigation, and investigations on the highest priority cases impacting ServiceNow and user data. - Partner with the team members across multiple regions to drive response and investigations globally. - Organization and facilitation of scenario-based exercises to test and improve incident management and response strategies. - Maintenance of existing playbooks and procedures, as well as developing new ones, to further standardize SIC and its partners' responses when verifying MSIs. - Contribute to the organization and completion of Post-Incident Reviews (PIRs) and Root Cause Analyses (RCAs) following major security incidents. - Identify new ways to simplify, integrate, automate and refine the major security incident process to better support internal and external stakeholders. Qualifications - Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making or problem-solving. - 12+ years of total cybersecurity professional experience or similar experience with education. - 5–8+ years of deep domain expertise in incident response and/or incident management. - Experience leading or supporting complex security incidents to resolution end-to-end. - Excellent verbal and written communication skills (English). - Comfort communicating complex topics in a clear and concise manner to different tiers of audiences (highly technical, less technical, executives, practitioners). - Problem-solving and decision-making skills. - Ability to quickly and accurately assess a situation, identify and prioritize risks, and make sound decisions. - Familiarity with cybersecurity principles and frameworks (e.g. MITRE ATT&CK). - Knowledge across multiple security domains is a plus. - Experience planning and/or orchestrating tabletop exercises is a plus. Requirements - West Palm Beach Florida (WPB) is available for relocation. Full relocation costs are provided by ServiceNow. - For positions in this location, we offer a base pay of $165,500 - $289,600, plus equity (when applicable), variable/incentive compensation and benefits. - Sales positions generally offer a competitive On Target Earnings (OTE) incentive compensation structure. - Compensation is based on the geographic location in which the role is located and is subject to change based on work location. Benefits - Health plans, including flexible spending accounts. - 401(k) Plan with company match. - Employee Stock Purchase Plan (ESPP). - Matching donations. - Flexible time away plan. - Family leave programs.

Related Categories

Related Job Pages

More Security Engineer Jobs

Accela logo

Senior Manager, Cybersecurity and Operations

Accela

Market-leading solutions that empower governments to build thriving communities, grow businesses and protect citizens.

Full TimeRemoteTeam 201-500Since 2000H1B Sponsor

• Lead the cybersecurity operations and security engineering function across corporate, cloud, hybrid, and production environments. • Manage and develop security engineers and analysts responsible for monitoring, detection, response, infrastructure security, vulnerability management, and operational security controls. • Own monitoring, detection, and response capabilities, including SIEM, EDR/XDR, DLP, vulnerability management, firewall, WAF, email security, identity security, and cloud security tooling. • Serve as the operational control point during significant cybersecurity incidents, coordinating response across Security, IT, Engineering, Legal, Communications, GRC, and executive stakeholders. • Develop, maintain, and test incident response playbooks, escalation paths, tabletop exercises, on-call procedures, and post-incident review processes. • Lead post-incident reviews and ensure root-cause remediation, lessons learned, and control improvements are completed. • Evaluate, implement, and optimize security solutions across endpoint, identity, network, email, cloud, logging, detection, and response platforms. • Partner with IT and Engineering to strengthen cloud, hybrid, and corporate security controls, including identity, network segmentation, key management, secrets management, privileged access, endpoint hardening, and secure configuration management. • Support GovRAMP and PCI DSS control requirements related to logging, monitoring, vulnerability management, incident response, endpoint security, access control, encryption, cloud security, configuration management, and evidence collection. • Drive measurable risk reduction across infrastructure, endpoints, cloud environments, identity systems, and business-critical services. • Own operational vulnerability management processes for infrastructure, cloud, endpoint, and corporate systems. • Support business continuity, disaster recovery, and resilience planning from a cybersecurity perspective. • Manage cybersecurity operations budget inputs, including vendor evaluation, renewals, tool rationalization, and investment recommendations. • Develop operational security metrics and reporting for executive leadership, including incident trends, vulnerability risk, detection coverage, response performance, control health, and remediation progress. • Stay ahead of evolving threats, including cloud-native attacks, identity compromise, ransomware, AI-enabled threats, and emerging attacker techniques. • Participate in or manage the security on-call rotation.

United States
$170K - $190K / year
Job Closed
Solvd, Inc. logo

Security Engineering Intern

Solvd, Inc.

Get things Solvd. | Software Development & QA

InternshipRemoteTeam 501-1,000Since 2010H1B No Sponsor

• Write clean, structured scripts (primarily Python and Bash) to automate repetitive security operations, optimize incident response workflows, and eliminate manual overhead. • Build, test, and deploy custom detection rules to flag anomalous behavior, misconfigurations, and potential threats across our cloud infrastructures (AWS, GCP, or Azure). • Design, construct, and maintain security dashboards (using tools like ELK/Elasticsearch, Splunk, Datadog, or SIEM platforms) to give our team clear, real-time visibility into our risk posture.

United States
Kalles Group logo

Security Analyst Consultant - Attack Surface Management

Kalles Group

We believe that everyone deserves to be secure. This is the foundation of everything we do for our customers, our consultants, and our communities. Our consulting services span cybersecurity, cyber risk, engineering, project leadership and learning services. Our team of industry veterans helps our partners with complex security and technology problems in a human way. Our values of integrity, ownership and purposefulness ensure our team provides the best possible outcomes time and time again, while helping us build and maintain long-term healthy relationships with our customers.

Full TimeRemoteTeam 39Since 2010

Role Description As a Senior Security Analyst Consultant – Attack Surface Management, you will lead and evolve our client’s enterprise Attack Surface Management (ASM) program, helping reduce cyber risk through proactive discovery, analysis, automation, and collaboration. This is a highly visible role that combines strategic leadership with hands-on technical execution, requiring expertise across vulnerability management, cloud security, threat intelligence, and offensive security disciplines. You will be responsible for developing a comprehensive view of the organization's attack surface, identifying opportunities to reduce exposure, and driving remediation efforts in partnership with engineering, cloud, DevOps, and security teams. Leveraging data, automation, and threat intelligence, you will help prioritize risk reduction initiatives while influencing architectural decisions that strengthen the organization’s security posture. This role is ideal for someone who enjoys building programs, solving complex security challenges, and partnering across the enterprise to create meaningful security outcomes. Qualifications - 6+ years of experience in cybersecurity, including security operations, threat hunting, offensive security, red teaming, or related disciplines - Experience building, scaling, or leading Attack Surface Management (ASM) capabilities and programs - Strong understanding of vulnerability management methodologies and risk prioritization frameworks - Experience working within multi-cloud environments, including AWS, Azure, and GCP - Deep knowledge of attacker tactics, techniques, and procedures (TTPs) and frameworks such as MITRE ATT&CK - Expertise in network security, cloud security, attack path analysis, and external attack surface discovery - Experience conducting OSINT, reconnaissance, and threat intelligence activities - Proficiency with scripting and automation technologies such as Python and PowerShell - Strong understanding of enterprise infrastructure, application architectures, and data flows - Ability to evaluate and influence architectural decisions that reduce organizational risk - Experience leading cross-functional security initiatives and driving collaboration across multiple teams - Excellent written and verbal communication skills with the ability to communicate effectively with both technical and non-technical stakeholders - Strong analytical and problem-solving skills with a data-driven approach to risk management Requirements - Industry certifications such as CISSP, OSCE, GREM, or similar cybersecurity credentials - Experience applying AI and automation technologies to security operations or attack surface management programs - Experience with cloud-native security platforms and exposure management tooling - Familiarity with threat modeling, purple teaming, or advanced adversary simulation exercises - Experience working in large-scale enterprise environments with complex security requirements Benefits - The annual salary range for this role is $110,000-$140,000. - We offer Medical, Dental, Vision plans, 401K with matching, and PTO for salaried employees. - Work/life balance – we know there’s more to life than work! We encourage our team to pursue other passions, get outside, and spend time with family. We work with clients and consultants to set expectations for a manageable workload. Company Description Kalles Group is an equal-opportunity employer and does not discriminate on the basis of creed, nationality, race, ethnicity, disability, gender, or other protected class.

United States
$110K - $140K / year

Role Description We are looking for an Application Security Engineer to embed security throughout the software development lifecycle, partnering with engineering teams to design secure systems, identify vulnerabilities, and reduce risk across our application portfolio. The role blends hands-on offensive and defensive skills with strong communication and collaboration, helping development teams build secure software efficiently rather than slowing them down. The ideal candidate brings deep technical security expertise, strong software engineering fundamentals, and a track record of shipping security improvements that meaningfully reduce risk in production. Key Responsibilities - Conduct threat modeling and security architecture reviews for new and existing applications and services. - Perform manual code reviews, secure design consultations, and pair with engineering teams on hardening critical components. - Operate and tune SAST, DAST, IAST, SCA, and secret-scanning tools across CI/CD pipelines. - Drive vulnerability management workflows including triage, prioritization, owner assignment, and SLA tracking. - Build paved-road libraries and frameworks that make secure patterns the default for engineering teams. - Lead red-team and purple-team exercises against internal applications and drive remediation of identified weaknesses. - Implement and operate runtime protections including WAF, RASP, bot protection, and abuse-detection mechanisms. - Design and enforce secure authentication, authorization, session management, and cryptographic patterns. - Partner with infrastructure and platform teams to harden container, Kubernetes, and cloud environments. - Develop and deliver application security training, lunch-and-learns, and onboarding content for engineering staff. - Respond to security incidents involving application vulnerabilities or active exploitation. - Track and apply emerging threats and CVEs that may affect the application portfolio. - Maintain comprehensive, current technical documentation — including architecture diagrams, design decisions, configuration references, runbooks, and operational procedures. - Stay current with application security research and emerging defensive tooling. Qualifications - Bachelor’s degree in Computer Science, Cybersecurity, or a related field. - Five or more years of application security or security engineering experience. - Strong understanding of OWASP Top 10, common vulnerability classes, and modern exploit patterns. - Hands-on experience performing code review across at least two major languages. - Deep familiarity with SAST, DAST, SCA, and CI/CD-integrated security tooling. - Strong understanding of authentication, authorization, and cryptographic primitives. - Experience with cloud security and modern infrastructure controls. - Strong communication skills with technical and non-technical audiences. - Proficiency in at least one programming language for tooling and automation. - Experience working closely with engineering teams in an Agile environment. Preferred Qualifications - Industry certifications such as OSCP, OSCE, GWAPT, or CISSP. - Experience with offensive security tooling and red-team operations. - Bug bounty experience, public CVEs, or open-source security contributions. - Familiarity with AI/LLM application security considerations. - Exposure to regulated industries with strict compliance requirements. How to Apply Would you like to know more about this opportunity? For immediate consideration, please send your resume to [email protected] . Learn more about Bright Vision Technologies at www.bvteck.com .

United States
100K - 150K / year
Job Closed