Senior Manager, Systems Engineering - Vulnerability

ServiceNow
San Diego, California$172k – $301kPosted 27 February 2026

Job Description

<p><strong>Please Note:</strong></p><p><strong>This position requires passing ServiceNow’s USFedPASS background screening (US Federal Personnel Authorization Screening Standards), which includes a credit check, criminal/misdemeanor check, and drug test. Employment is contingent upon successful completion. Due to federal requirements, candidates must be U.S. citizens, naturalized citizens, or permanent residents holding a valid green card.</strong></p><p>&#xa0;</p><p><strong>This role is ideally based in our San Diego, CA or Orlando, FL office, with the expectation of working in a hybrid environment.</strong></p><p>&#xa0;</p><p><strong>Role Overview</strong></p><p>As Senior Manager of Systems Engineering – Vulnerability Management, you will lead a team of infrastructure engineers responsible for ensuring compliance and reducing risk across ServiceNow’s Commercial and Regulated Markets environments. This role blends technical leadership with people management, requiring the ability to drive a transition from reactive operations to proactive, engineering-first practices while developing a high-performing team. Success in this role demands strong cross-functional collaboration and the ability to champion a “shift left” security mindset across the organization.</p><p><strong>What you get to do in this role:</strong></p><ul><li><strong>Team Leadership &amp; Development</strong><ul><li>Lead, coach, and grow a team of highly effective engineers, fostering a culture of continuous learning and high performance through inclusive hiring practices, goal setting, individual development plans, and performance management.</li></ul></li><li><strong>Operational Excellence &amp; SLAs</strong><ul><li>Own the end-to-end vulnerability lifecycle, ensuring the organization meets strict remediation SLAs and prioritizes risks based on actual business impact.</li><li>Oversee the resolution of vulnerabilities across hybrid-cloud environments (AWS/Azure/GCP) and traditional on-premise infrastructure.</li></ul></li><li><strong>“Shift Left” Advocacy</strong><ul><li>Partner with DevOps and Engineering teams to integrate security earlier in the SDLC, ensuring vulnerabilities are identified and remediated during the design and build phases.</li></ul></li><li><strong>Automation &amp; AI Integration</strong><ul><li>Identify opportunities to leverage AI and automation to streamline scanning, reporting, and triage, enabling the team to focus on complex risk analysis.</li></ul></li><li><strong>Process &amp; Program Improvement</strong><ul><li>Identify and execute systems and process optimization opportunities that improve reliability, performance at scale, and operational efficiency.</li></ul></li><li><strong>Stakeholder Partnership</strong><ul><li>Act as a liaison between Security, Engineering, and Business leaders, translating technical debt into business risk to drive executive buy-in for remediation priorities.</li></ul></li><li><strong>Operational Rigor</strong><ul><li>Own early intervention, triage, and escalation response to ensure targets are met, driving cross-functional resolution with urgency and transparency.</li></ul></li></ul> <p><strong>To be successful in this role you have:</strong></p><ul><li>Experience in&#xa0;leveraging&#xa0;or&#xa0;critically&#xa0;thinking about how to integrate AI into work processes, decision-making, or problem-solving. This may include using AI-powered tools, automating workflows, analyzing AI-driven insights, or exploring AI's potential impact on the function or industry. &#xa0;</li><li>12+ years of related experience with a Bachelor's degree; or 8 years and a Master's degree; or a PhD with 5 years experience; or equivalent experience.</li><li>8 years of experience in vulnerability management, information security, or related cybersecurity roles, with 3+ years of people management experience.</li><li>Deep understanding of vulnerability management tools and processes (e.g., Tenable, Trivy, Anchore), CI/CD pipelines, and clo ... (truncated, view full listing at source)