Sr Staff Software Engineer - Product Security

ServiceNow
Petah Tikva,Posted 9 March 2026

Job Description

ServiceNow’s Product Security organisation is building a dedicated Security R&D function. This software engineering team builds security capabilities with the same rigour, CI/CD discipline, and quality standards as ServiceNow’s product engineering organisation. We are looking for a Sr. Staff Security Engineer to serve as the technical anchor on this team. Security R&D operates in two complementary modes: open contribution to product engineering — writing code alongside product teams where security expertise adds value — and developing its own security capabilities , including internal tooling, externally facing product features, AI-powered security automation, and third-party integrations. This is a new team being stood up in Petah Tikva, Israel, co-located with ServiceNow’s AI Security Research team. You will be one of the senior technical leaders shaping the team’s engineering culture, architecture decisions, and technical direction from its inception. This role reports to the Sr. Engineering Manager, Security R&D. What You Will Do Lead Technical Design and Architecture Drive architecture and design decisions for Security R&D’s capabilities, ensuring systems are built for enterprise scale, reliability, and maintainability. Lead technical design reviews and serve as the senior engineering voice on security tooling, automation, and platform services built by the team. Define technical standards, code quality expectations, and engineering best practices for the Security R&D team. Evaluate and integrate third-party security services alongside in-house AI-powered capabilities to maximise security review coverage. Build Security Capabilities at Platform Scale Design and develop security tooling, automation, and platform-native services — both for internal use and as externally facing product features. Contribute code directly into ServiceNow product engineering codebases where security domain expertise accelerates delivery and improves security outcomes. Leverage ServiceNow’s unique platform advantages — Agent Framework runtime, ACL enforcement, data layer, and workflow engine — to build capabilities that external vendors cannot replicate. Collaborate with the AI Security Research team on AI agent security tooling, bringing production engineering discipline to an emerging domain. Mentor and Elevate the Team Mentor junior and mid-level engineers, raising the technical bar across the team through code reviews, design guidance, and hands-on pairing. Represent Security R&D in cross-functional discussions with product engineering leadership, demonstrating technical credibility as an engineering peer. Contribute to hiring by helping define the technical interview bar and participating in candidate evaluations. What Makes This Role Unique Builder-led culture: Security R&D is defined by engineering output, not advisory reviews. We build production security capabilities with the same discipline as product engineering. Dual operating model: The team both contributes directly to product engineering and develops its own security products and services. Platform advantage: ServiceNow owns the entire stack — runtime, ACLs, data layer, workflow engine. You will build security capabilities that no external vendor can replicate. Founding team: This is a new team being built from scratch. You will shape its engineering culture, technical standards, and identity from day one. AI intersection: The role sits alongside the AI Security Research team, placing you at the frontier of securing AI systems at enterprise scale. To be successful in this role you have: 12+ years of progressive software engineering experience, with a track record of designing and building complex systems at enterprise scale. Bachelor’s degree in Computer Science, Engineering, or a related technical field. Strong hands-on production experience with Python and Java. You are a builder who writes code daily, not an architect who only draws diagrams. Dee ... (truncated, view full listing at source)