CybersecurityJobs.io
← Back to all jobs

Job Description

Move security operations forward with automation. In ServiceNow’s Moveworks Security team, this Staff Agentic Security Engineer role focuses on building autonomous, AI-driven defense capabilities that enhance SOC effectiveness. You will help replace traditional SOAR workflows with resilient, agentic orchestration that improves detection, response, and continuous validation.

Onsite in Mountain View, CA and designed for engineers who want to architect real outcomes: incident response lifecycle automation, proactive threat hunting, and reliable simulation testing that proves agent workflows and detection pipelines trigger against real-world attack behaviors.

What you’ll do

  • Build advanced AI orchestration: Go beyond basic tool configuration by building, coding, designing, and researching framework-level approaches for chaining MCP servers and AI agents.
  • Scale proactive threat hunting: Architect and grow a proactive threat hunting program from scratch.
  • Strengthen Blue Team and AI Red Team collaboration: Create a feedback loop between the Blue Team and ServiceNow’s internally developed AI Red Team Agent.
  • Partner across engineering and compliance: Work as a strategic engineering partner with IT, Security Engineering, DevOps, DevSecOps, Compliance, Cloud, and Infrastructure teams to ensure corporate systems are “automation-ready.”
  • Own incident response engineering: Build and maintain an end-to-end incident response roadmap across Detection, Triage, Containment, and Recovery, replacing traditional SOAR workflows with agentic orchestration.
  • Lead high-stakes escalations: Serve as a top-tier technical escalation point for active, complex incidents.
  • Validate with automated simulation testing: Design, execute, and validate automated simulation tests to systematically prove agentic workflows and detection pipelines trigger reliably against real-world attack behaviors.

What you bring

  • U.S. Citizenship required: Must meet strict compliance and FedRAMP criteria.
  • Experience: 8–10 years in Security Operations, Systems Engineering, or DevSecOps. Minimum 5 years of highly relevant engineering experience required.
  • Cross-functional mastery: 3–5 years of proven collaboration track record across multidisciplinary teams including Cloud Infrastructure, DevOps, DevSecOps, Compliance, and IT.
  • AI and agentic fluency: Deep familiarity with modern LLM agent frameworks, including active research into application, performance trade-offs, and behavioral guardrails.
  • Automation engineering: Strong proficiency in Python and software engineering principles.
  • Cloud and infrastructure depth: Hands-on architectural familiarity with AWS security ecosystems including IAM, CloudTrail, and GuardDuty, plus containerized environments such as Kubernetes and EKS.
  • FedRAMP and trust awareness: Ability to communicate and translate framework controls into automated, code-driven evidence generation pipelines.
  • Collaboration mindset: High-autonomy and high-collaboration approach.

Technologies you’ll work with

  • Python
  • Model Context Protocol (MCP)
  • LLM agent frameworks
  • MCP servers
  • AWS security ecosystems: IAM, CloudTrail, GuardDuty
  • Kubernetes, EKS
  • SOAR

Work persona and office eligibility

ServiceNow assigns work personas (flexible, remote, or required in office) based on the nature of work and assigned work location. To determine eligibility, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.

Similar Jobs