Staff Application Security Engineer ( Instance Security
Listed on 2026-10-08
-
IT/Tech
Cybersecurity, Security Management & Operations, Information Security & Data Protection -
Security
Cybersecurity, Security Management & Operations, Information Security & Data Protection
Location: Northern
Staff Application Security Engineer (Service Now Instance Security)
- Full-time
- Employee Type:
Regular - Region: AMS - North America and Canada
- Work Persona:
Flexible or Remote
It all started when engineer Fred Luddy wrote code that automated a tedious task for his coworker, Phyllis. She cried tears of joy. That moment inspired Fred to build a company that could do that for everyone—freeing people from busywork so they could focus on meaningful work. Today, Service Now is the AI control tower for business reinvention. Our Service Now AI platform brings together any AI, any data, and any workflow— helping 85% of the Fortune 500 work smarter, faster, and better.
We're building an AI-native culture where technology and talent are unstoppable together. And we're just getting started.
Join us to put AI to work for people.
The Service Now Security Organization (SSO)
The Service Now Security Organization (SSO) delivers world-class, innovative security solutions to reduce risk and protect the company and our customers. We enable our customers to migrate their most sensitive data and workloads to the cloud, accelerating our business so that we are the most trusted SaaS provider.
We create an environment where our employees are proud to work and can make a positive impact
About the Team
The Global Security Support Center (GSSC) plays a critical role in strengthening Service Now’s internal and external security posture and acts as a key interface with customers on security‑related matters.
GSSC App Secis a globally distributed team responsible for owning the Customer Penetration Testing & Security Findings (CPT & SF) program, partnering across the Security Organization to reduce risk, handle escalations, and represent the voice of the customer.
This role is focused onService
Now instance security, helping customers and internal teams identify, understand, and remediate insecure configurations and instance‑level security gaps.
Role Summary
As an Staff Application Security EngineerinGSSC App Sec, you will secure Service Now instances by identifying configuration‑driven security risks, validating customer‑reported findings, and driving clear, actionable remediation guidance.
This is ahands‑on technical rolethat blends application security expertise with deep Service Now platform knowledge. At the senior end of the range, you will operate with minimal direction, own complex instance‑security problem spaces, and influence how GSSC App Sec scales instance security guidance and posture improvements globally.
Key Responsibilities
- Service Now Instance Security & Hardening
- Assess Service Now instance configurations against security baselines and identify misconfigurations that impact confidentiality, integrity, or availability.
- Develop and maintainprescriptive instance‑hardening guidancecovering authentication, access controls, encryption, logging, monitoring, and operational security.
- Translate security requirements and risk intoclear, customer‑consumable recommendations that can be implemented by teams with varying security maturity.
- Identify recurring misconfiguration patterns and drive systemic improvements (guidance, tooling, checks).
- App Sec & Customer Security Findings (CPT & SF)
- Triage, validate, and contextualizecustomer‑reported security findingswhere instance configuration or deployment patterns are a contributing factor.
- Distinguish between product vulnerabilities vs. configuration issues, documenting impact and appropriate remediation paths.
- Partner with Product Security, Engineering, and other Security teams to resolve complex or high‑impact findings.
- Support escalations and high‑visibility customer interactions as an instance‑security subject‑matter expert.
Required Qualifications
- Experience in leveraging or critically…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).