Staff Security Engineer, Security Operations - Moveworks
ServiceNow · Mountain View, CA · 1 mo ago
HybridInformation TechnologyFull-time
About the role
The Moveworks Security team at ServiceNow is seeking a Staff Agentic Security Engineer to join our mission to automate the SOC out of existence through autonomous systems. This role requires a visionary engineer with deep expertise in modern LLM agent frameworks and strong cross-functional collaboration skills.
Responsibilities
- Build and AI orchestration: Develop advanced, framework-level approaches for chaining MCP servers and AI agents, optimizing agentic networks for maximum performance.
- Proactive Threat Hunting Program: Architect and scale a proactive threat hunting program, leveraging custom agents, MCP capabilities, and security tooling to discover complex vulnerabilities and hidden threats.
- Advanced Purple Team Synergies: Forge a cutting-edge feedback loop between the Blue Team and our internally developed AI Red Team Agent, seamlessly bridging automated offense and defense.
- Cross-Functional Influence & Leadership: Act as a strategic engineering partner across IT, Security Engineering, DevOps, DevSecOps, Compliance, Cloud, and Infrastructure teams to ensure systems are natively "automation-ready."
- E2E IR Automation Architecture: Own the engineering roadmap for the end-to-end incident response lifecycle, replacing traditional SOAR workflows with resilient, agentic orchestration.
- Incident Commander Escalation: Serve as a high-tier technical escalation point for active, complex incidents, using each incident as an adversarial data point to design superior automated immune responses.
- Validate the Defense: Design, execute, and validate automated simulation testing to systematically prove that agentic workflows and detection pipelines trigger reliably against real-world attack behaviors.
Qualifications
- U.S. Citizenship Required: Must meet strict compliance/FedRAMP criteria.
- Experience: 8–10 years of experience in Security Operations, Systems Engineering, or DevSecOps (Minimum 5 years of highly relevant engineering experience required).
- Cross-Functional Mastery: 3–5 years of proven track record working closely across multidisciplinary teams including Cloud Infrastructure, DevOps, DevSecOps, Compliance, and IT.
- AI & Agentic Fluency: Deep familiarity with modern LLM agent frameworks, including active research into their application, performance trade-offs, and behavioral guardrails.
- Automation Engineering: High proficiency in Python and software engineering principles, extensive past experience with traditional workflow engines and legacy SOAR tooling.
- Cloud & Infrastructure Depth: Strong, hands-on architectural familiarity with AWS security ecosystems (IAM, CloudTrail, GuardDuty) and containerized environments (Kubernetes/EKS).
- FedRAMP & Trust Awareness: Communication skills and security compliance maturity to translate framework controls into automated, code-driven evidence generation pipelines.