Principal AI Security Engineer
ServiceNow · Petah Tikva, IL
Skills in this posting
The posting
Role
This is a hands-on architecture role: deep research, secure systems design, and prototyping, applied across product lines with minimal direction and broad latitude to set the technical agenda.
You will set platform-wide direction for securing the AI development lifecycle, define the security architecture, agents, and models operating within it, and represent ServiceNow's AI security point of view externally.
You'll be a technical authority other engineers and other teams look to on emerging AI-specific threats, working in close partnership with the AI security research team - drawing on their findings and feeding real-world attack surfaces back into their agenda.
What you'll do
Own the security strategy and architecture for our Agentic AI ecosystem, LLMs, and models across product lines
Lead threat modeling for the most complex and novel GenAI/agentic surfaces: cross-agent autonomy, multi-agent tool orchestration, and emerging attack classes not yet standardised in the industry
Set the architectural standard for securing model/RAG/data pipelines platform-wide, including access-control and data-boundary models that other teams are expected to build against
Define what "secure-by-design" means for agentic systems at ServiceNow, and drive adoption across engineering orgs
Represent ServiceNow's AI security posture externally (standards bodies, industry publications, conferences) and internally to executive stakeholders
Mentor and technically guide engineers on AI-specific security work
To succeed in this role, you’ll need
Bachelor’s / Master's degree or PhD in Computer Science or a related technical field, specialisation in Security or AI/ML or an exceptional, well-evidenced track record substituting for it
10+ years of software engineering experience, including a track record of owning the architecture of complex systems at enterprise scale
A track record of setting technical direction beyond your own team - architecture or standards other teams adopted, senior engineers you've levelled up, and comfort operating where the problem isn't yet defined
7+ years in security engineering - network and systems security, security protocols, design reviews, and threat modeling - with a focus on AI-specific work in recent years
Multiple demonstrated engagements threat modeling and/or securing LLM, GenAI, or agentic systems, with evidence of platform-level or cross-team impact
Personal ownership of prompt injection / jailbreak defense, guardrail architecture, or AI red-teaming programs - ideally having built the program/methodology, not just executed within one
Deep, applied experience securing model, RAG, or data pipelines, including having designed the access-control and data-governance model others build against
Fluency with the OWASP LLM Top 10 (or equivalent) to the point of extending, critiquing, or contributing to such frameworks - not just applying them
Deep hands-on experience with agentic AI frameworks (e.g., LangChain, LangGraph)
Clear communication, a collaborative default, and a bias toward learning fast in a field that changes constantly
Bonus
Strong command of auth protocols (OAuth 2.0, OIDC, PKCE, API Keys) and agentic protocols (MCP, A2A), including having designed identity/consent models for them
Built and open-sourced (or productized) security tooling/automation for AI systems now used beyond one team
Track record of CVEs, top-tier publications, or invited talks specifically in AI/ML or LLM security
Prior experience setting AI security strategy at a platform or company level, not just a single product
5+ years of programming experience in Java or Python
Work Personas
We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here . To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.
Equal Opportunity Employer
ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.
Accommodations
We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact globaltalentss@servicenow.com for assistance.
Export Control Regulations
For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.
From Fortune. ©2026 Fortune Media IP Limited. All rights reserved. Used under license. .
The PivotHop read
- What a security engineer actually earnsmedian, seniority, by country
- Where security engineers move nextevery measured route out
- Penetration Tester → Security Engineer47% readiness
- All open security engineer rolesthe full board
Where these skills also reach
- 36 open penetration tester roles70% readiness from security engineer
- 138 open network engineer roles70% readiness from security engineer
- 600 open systems administrator roles47% readiness from security engineer
- 600 open solutions architect roles42% readiness from security engineer
More security engineer roles
Security Engineer III - Security Operations at Primer.ioUnited KingdomTodayApply
Network Security Engineer at UvationUnited States · RemoteTodayApply
Senior Security Engineer - Manufacturing Cybersecurity at LifelancerUnited States · Remote1d agoApply
Senior Information Security Engineer - Incident Response (Remote, US) at CenturyLinkUnited States · Remote$85k–$124k1d agoApply
Senior IT Security Engineer at RelexHelsinki, Finland1d agoApply
Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.