Source Job

Americas Unlimited PTO

  • Assess ServiceNow instance configurations against security baselines and identify misconfigurations.
  • Triage and validate customer-reported security findings related to instance configuration.
  • Partner with cross-functional teams to resolve complex security issues and drive systemic improvements.

Application Security ServiceNow Vulnerability Analysis Threat Modeling

20 jobs similar to Staff Application Security Engineer (ServiceNow Instance Security)

Jobs ranked by similarity.

US

  • Serve as primary point of contact for users of application security and cloud security tools, helping teams understand and remediate findings.
  • Manage security requests through ServiceNow, analyze findings, and provide hands-on support and troubleshooting.
  • Collaborate with teams to improve customer experience, develop knowledge base articles, and identify automation opportunities.

Marlabs is a global AI and Digital Solutions Consulting firm delivering intelligent solutions across AI, data, analytics, and product engineering. Since 2000, the company has partnered with large healthcare, life sciences, financial services, and government organizations, fostering an innovative and dynamic team culture.

$113,500–$121,300/yr
US

  • Design, implement, and maintain security controls for Box's enterprise applications and cloud services.
  • Partner with IT and business owners to securely deploy and operate enterprise platforms, SaaS apps, and integrations.
  • Perform security assessments, build monitoring and automation, and support vulnerability management and incident response.

Box is a leader in intelligent content management, providing a platform for collaboration, content lifecycle management, and secure workflows with enterprise AI. Founded in 2005, Box serves leading global organizations and has offices across the US, Europe, and Asia.

$120,000–$145,000/yr
US

  • Design, build, and scale application security capabilities to support secure software development across the enterprise.
  • Develop security patterns and guardrails for AI-assisted development and agentic workflows.
  • Integrate security tools with developer platforms to improve vulnerability management and automate remediation.

NBCUniversal is a leading media and entertainment company creating world-class content for film, television, streaming, and theme parks. As a subsidiary of Comcast, it fosters an inclusive culture and community engagement across a diverse global workforce of thousands.

$76,000–$130,000/yr
US

  • Deliver the full implementation life cycle to support deployment of ServiceNow modules into complex client environments.
  • Work with Agile teams in a virtual environment, understanding customer needs and coordinating with stakeholders to implement requirements.
  • Provide technical expertise and implement configurations including business rules, workflows, reports, dashboards, and user portals.

LMI is a digital solutions provider accelerating government impact with innovation and speed, serving the defense, space, healthcare, and energy sectors. Headquartered in Tysons, Virginia, the company emphasizes agility and collaboration to help agencies outpace change.

$151,200–$189,000/yr
5w PTO

  • Build and lead Attio's Product Security function, securing their AI-native SaaS platform and sensitive customer data.
  • Work with Engineering Leadership to ensure security by design, mitigating unique risks from AI-driven features and AI-assisted development.
  • Lead production security incident response, recruiting and retaining a world-class team of Security Engineers and SecOps practitioners.

Attio is the CRM for agentic revenue, designed for ambitious go-to-market teams to understand every customer and automate at scale. They have raised $116M from top investors and hire builders who thrive on complex technical challenges, holding themselves to a high bar and delighting users.

$180,000–$180,000/yr
US Unlimited PTO

  • Get involved early in new products and features, using threat modeling and security design reviews to find problems before they reach production.
  • Dig into application architecture, APIs, authentication, authorization, data flows, cloud services, and third-party integrations to understand how systems could be attacked.
  • Own and improve security tooling across the development lifecycle, including SAST, DAST, dependency scanning, and secret scanning.

YipitData is a leading market research and analytics firm for the disruptive economy, raising $475M from The Carlyle Group at a valuation over $1B. They operate globally with offices in the US, APAC, and India, and have been recognized by Inc. as a Best Workplace for three consecutive years, emphasizing transparency, ownership, and continuous mastery.

$110,000–$160,000/yr
North America

  • Own identity and access management across Later’s platform, including authentication, authorization, and secure machine-to-machine processes.
  • Design, implement, and maintain secure authentication systems for both internal tools and customer-facing experiences.
  • Partner with engineering teams to identify vulnerabilities, clearly communicate risk and impact, and drive effective remediation.

Later is the world’s most intelligent influencer marketing company, built to give brands the confidence to create unforgettable campaigns. Trusted by leading enterprise brands including Nike, Wayfair, Unilever, and Southwest Airlines, Later is a mid-to-large company with a culture of inclusion and innovation.

US Unlimited PTO

  • Perform application security testing and vulnerability assessments on web applications, APIs, and CI/CD pipelines.
  • Support DevSecOps tool integration and automation, including security scanning and policy enforcement.
  • Develop proof-of-concept secure reference implementations and utility applications to demonstrate best practices.

Ardent supports the federal government's most critical national security and defense priorities. They offer competitive pay, comprehensive benefits, and a culture that values dedication and flexibility.

US Unlimited PTO 18w maternity 18w paternity

  • Champion secure-by-default culture by embedding defense-in-depth principles into engineering frameworks and development practices.
  • Conduct hands-on source code reviews, threat modeling, and security assessments across microservice architectures.
  • Build automation and frameworks to eliminate repetitive security work and create scalable security capabilities.

Jobgether is a company that uses AI-powered matching to streamline job applications. It is a technology platform connecting candidates with hiring companies, with a focus on efficient and objective candidate review.

Global

  • Build and deploy security tooling across endpoint management, supply-chain, infrastructure, and application layers.
  • Identify and remediate security gaps across production systems and development pipelines.
  • Lead incident response end-to-end and partner with engineering on secure design reviews.

Tempo is a layer-1 blockchain built for stablecoins and real-world payments, leveraging expertise from Stripe and Paradigm. We are a team of crypto-optimists moving fast to build infrastructure for onchain economic flows.

Nigeria

  • Conduct thorough security assessments and penetration testing to identify vulnerabilities in web and mobile applications.
  • Collaborate with development teams to integrate security best practices and design secure application architectures.
  • Lead incident response and ensure compliance with security standards and regulations.

Moniepoint Inc. is an all-in-one African financial platform serving 20 million businesses with payments, banking, and tools. As Nigeria's largest merchant acquirer, it processes over $250 billion annually and fosters a culture of innovation and teamwork.

Global

  • Design and implement security controls across applications, cloud infrastructure, and development environments.
  • Conduct architecture reviews, threat modeling, and security assessments for new products.
  • Identify, prioritize, and remediate vulnerabilities across the technology stack.

SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.

$130,000–$160,000/yr
US

  • Assess and validate web application vulnerabilities across targets, confirming exploitability and scope.
  • Reproduce findings hands-on using tools like Burp Suite and rate severity with CVSS/OWASP.
  • Write clear, accurate customer-facing finding descriptions and remediation guidance.

RunSybil builds Sybil, an AI-driven pentester that automates hacker intuition to discover vulnerabilities before exploitation. Founded in 2023, the company is backed by strong investor support and includes experts from OpenAI, Meta, Mandiant, Palantir, Cruise, Trail of Bits, and Aptiv.

$130,100–$187,000/yr
US

  • Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions.
  • Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
  • Design and deploy automated security testing to identify vulnerabilities early in the development process.

Abnormal Security protects the humans behind the world's most critical organizations from AI-powered cybercrime. More than 4,500 enterprises trust its behavioral AI platform.

US

  • Support the implementation and operationalization of the ServiceNow platform for a mission-critical Department of Veterans Affairs program.
  • Perform platform administration, governance, security controls, and integration management across development, test, staging, and production environments.
  • Collaborate with cross-functional teams to ensure platform reliability, compliance with federal cybersecurity standards, and continuous improvement.

LTS is a technology services company supporting high-visibility federal missions in IT and healthcare. The company values innovation, growth, collaboration, and quality, and offers a career path that rewards ambition and performance.

US

  • Lead the development and implementation of security strategies, policies, and procedures.
  • Architect secure systems and collaborate with engineering teams to integrate security throughout the software development lifecycle.
  • Conduct risk assessments, incident response, and mentor junior engineers to promote security awareness.

Gemini is a global crypto and Web3 platform founded in 2014, offering secure crypto products and services to individuals and institutions in over 70 countries. The company is publicly traded with a mission to bridge traditional finance with the emerging cryptoeconomy, fostering a diverse team that prioritizes trust and security.

$170,000–$230,000/yr
US

  • Build secure-by-default infrastructure and automation to eliminate entire vulnerability classes across money-moving systems.
  • Own application security, threat modeling, and vulnerability disclosure from design review to production.
  • Partner with engineering to set security standards, make risk-based decisions, and ship fast without compromising safety.

Flex is building the AI-native private bank for business owners, re-architecting the entire financial system for entrepreneurs. Since launching in 2023, Flex has scaled to nine-figure annualized revenue, raised $100M+ in equity and $300M+ in debt, and operates with a high-bar, low-ego culture focused on speed and execution.

North America Unlimited PTO

  • Architect internal AI security strategy for ServiceNow's adoption of agentic tools, LLMs, and copilots.
  • Drive execution excellence by pushing architecture through to production-grade outcomes across security domains.
  • Lead AI threat modeling and partner with product AI security research to apply frontier research internally.

ServiceNow is the AI control tower for business reinvention, empowering 85% of the Fortune 500 with its AI platform. Founded on the idea of freeing people from busywork, it fosters an AI-native culture where technology and talent are unstoppable.

Global

  • Handle daily incidents, service requests and user questions on the ServiceNow platform, working to agreed SLAs and priority rules.
  • Administer users, roles, groups and access rights, including ACL configuration and periodic access reviews.
  • Configure the platform in day-to-day operation: catalogue items, forms, notifications, assignment rules and scheduled jobs.

Software Mind develops solutions that make an impact for companies around the globe. They build cross-functional engineering teams and foster a culture of openness, respect, grit, and enjoyment.

Latin America

  • Lead technical discovery and solution design with enterprise customers to address security and risk challenges.
  • Deliver compelling virtual and in-person product demonstrations and proof-of-value engagements.
  • Translate technical capabilities into business outcomes and serve as a trusted advisor to stakeholders.

ServiceNow is an AI platform company that automates workflows and helps businesses operate more efficiently. The company serves 85% of the Fortune 500 and fosters an AI-native culture with a focus on innovation.