Senior Staff Information Security Engineer

ServiceNow
Summary
Join ServiceNow's Security Organization as a Senior Staff Information Security Engineer and play a key technical role in securing our core enterprise infrastructure. You will define and execute the technical strategy for infrastructure security, lead efforts to harden network and server infrastructure, and architect and implement scalable security controls. This role involves driving secure deployments, managing certificate lifecycles, and championing operational excellence through automation. You will also represent Infrastructure Security in various initiatives and mentor other engineers. The ideal candidate possesses extensive experience in operating system and server security, enterprise networking, and scripting/automation, along with a deep understanding of infrastructure security best practices.
Requirements
- Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving. This may include using AI-powered tools, automating workflows, analyzing AI-driven insights, or exploring AI's potential impact on the function or industry
- Masterβs degree in computer science; engineering, or information technology or equivalent industry experience
- 10+ years of relevant hands-on engineering experience
- Deep experience with operating system and server security (Linux, Windows)
- Advanced knowledge of enterprise networking and secure network architectures
- Proficiency in scripting and automation (Python, Bash, Go, etc.)
Responsibilities
- Define and execute the technical strategy for securing infrastructure, aligned to risk and business needs
- Lead efforts to harden network and server infrastructure against unauthorized access, misconfigurations, and malware
- Architect and implement scalable and automated security controls across authentication, system configurations, and monitoring pipelines
- Drive secure deployment and management of on-prem containerized environments (e.g., Kubernetes)
- Establish controls and visibility to manage certificate lifecycle and prevent expiration-related risks
- Champion operational excellence through automation, outage reduction, and service resilience improvements
- Represent Infrastructure Security in architecture reviews, incident response, and compliance initiatives
- Mentor and develop other engineers, influencing secure engineering practices across teams
- Stay current with industry threats, trends, and mitigation techniques related to infrastructure security
Preferred Qualifications
- Experience in working with web and database services (REST APIs, JSON, XML, SQL)
- Experience in working with Splunk and SPL (or other SIEM/Log management systems)
- Experience in working with cryptography (PKI, TLS, VPNs, secure credential management, disk encryption, certificate and code signing)
- Experience with infrastructure-as-code and configuration management tools such as Puppet and Ansible to automate system hardening and policy enforcement
- Experience in working with hardware virtualization (bare metal servers, storage, load balancing, virtual networking using VMware, Citrix, Hyper-V, etc.)
- Planning hardware and software system upgrades and configuration changes
- Automating operations and capacity planning
- System performance tuning and service monitoring
- System and software debugging experience with strong troubleshooting skills
- Familiarity with regulatory and industry certifications (FedRAMP, NIST 800-53, NIST CSF, SOC 2, SOX and GDPR)
- Ability to analyze and assess complex problems quickly and efficiently
- Growth mindset approach: hungry and humble with the ability to lead and train others
- Ability to thrive in a dynamic, driven, fast-paced environment