Application Security Engineer
$176.1k - $308.2kServiceNow
Company Description
It all started when engineer Fred Luddy wrote code that automated a tedious task for his coworker, Phyllis. She cried tears of joy. That moment inspired Fred to build a company that could do that for everyone—freeing people from busywork so they could focus on meaningful work. Today, ServiceNow is the AI control tower for business reinvention. Our ServiceNow AI platform brings together any AI, any data, and any workflow— helping 85% of the Fortune 500® work smarter, faster, and better. We're building an AI-native culture where technology and talent are unstoppable together. And we're just getting started.
Join us to put AI to work for people.
Job Description
The ServiceNow Security Organization (SSO)
The ServiceNow Security Organization (SSO) delivers world-class, innovative security solutions to reduce risk and protect the company and our customers. We enable our customers to migrate their most sensitive data and workloads to the cloud, accelerating our business so that we are the most trusted SaaS provider. We create an environment where our employees are proud to work and can make a positive impact
About the Team
The Global Security Support Center (GSSC) plays a critical role in strengthening ServiceNow’s internal and external security posture and acts as a key interface with customers on security‑related matters.
GSSC AppSec is a globally distributed team responsible for owning the Customer Penetration Testing & Security Findings (CPT & SF) program, partnering across the Security Organization to reduce risk, handle escalations, and represent the voice of the customer.
This role is focused on ServiceNow instance security, helping customers and internal teams identify, understand, and remediate insecure configurations and instance‑level security gaps.
Role Summary
As an Staff Application Security Engineer in GSSC AppSec, you will secure ServiceNow instances by identifying configuration‑driven security risks, validating customer‑reported findings, and driving clear, actionable remediation guidance.
This is a hands‑on technical role that blends application security expertise with deep ServiceNow platform knowledge. At the senior end of the range, you will operate with minimal direction, own complex instance‑security problem spaces, and influence how GSSC AppSec scales instance security guidance and posture improvements globally.
Key Responsibilities
- ServiceNow Instance Security & Hardening
- Assess ServiceNow instance configurations against security baselines and identify misconfigurations that impact confidentiality, integrity, or availability.
- Develop and maintain prescriptive instance‑hardening guidance covering authentication, access controls, encryption, logging, monitoring, and operational security.
- Translate security requirements and risk into clear, customer‑consumable recommendations that can be implemented by teams with varying security maturity.
- Identify recurring misconfiguration patterns and drive systemic improvements (guidance, tooling, checks).
- AppSec & Customer Security Findings (CPT & SF)
- Triage, validate, and contextualize customer‑reported security findings where instance configuration or deployment patterns are a contributing factor.
- Distinguish between product vulnerabilities vs. configuration issues, documenting impact and appropriate remediation paths.
- Partner with Product Security, Engineering, and other Security teams to resolve complex or high‑impact findings.
- Support escalations and high‑visibility customer interactions as an instance‑security subject‑matter expert.
Required Qualifications
- Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving. This may include using AI-powered tools, automating workflows, analyzing AI-driven insights, or exploring AI’s potential impact on the function or industry.
- 8+ years with strong foundation in application security (vulnerability analysis, secure design principles, threat modeling mindset). Or similar experience with education
- Ability to read, write, and debug code to validate findings and understand security impact.
- Experience translating security risk into actionable remediation guidance.
- Excellent written and verbal communication skills, especially for customer‑facing or executive‑visible content.
Qualifications
Preferred Qualifications
- Hands‑on experience with the ServiceNow platform, especially platform security features, configuration, and administration.
- Familiarity with SaaS security posture management and misconfiguration risk.
- Prior experience supporting customer‑reported security findings, escalations, or external security reviews.
- Experience influencing security outcomes without direct authority (cross‑functional collaboration).
What Success Looks Like
- Customers and internal teams receive clear, accurate, and actionable guidance to secure their ServiceNow instances.
- Reduced repeat instance‑security issues through improved baselines, guidance, and detection.
- Faster, higher‑confidence triage of customer‑reported security findings tied to instance configuration.
- GSSC AppSec becomes more scalable and consistent in how it addresses instance‑level security risk.
#SecurityJobs
West Palm Beach Florida (WPB) is available to for Relocation. Full relocation costs are provided by ServiceNow
JV20
For positions in this location, we offer a base pay of $176,100 - $308,200 , plus equity (when applicable), variable/incentive compensation and benefits. Sales positions generally offer a competitive On Target Earnings (OTE) incentive compensation structure. Please note that the base pay shown is a guideline, and individual total compensation will vary based on factors such as qualifications, skill level, competencies, and work location. We also offer health plans, including flexible spending accounts, a 401(k) Plan with company match, ESPP, matching donations, a flexible time away plan and family leave programs. Compensation is based on the geographic location in which the role is located and is subject to change based on work location.
Additional Information
Work Personas
We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here. To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.
Equal Opportunity Employer
ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, age, disability, gender identity, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.
Accommodations
We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact for assistance.
Export Control Regulations
For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.
From Fortune. ©2026 Fortune Media IP Limited. All rights reserved. Used under license.
- Employee Type: Regular
- Region: AMS - North America and Canada
- Work Persona: Flexible or Remote
$100.63k - $167.79k
...your success while helping clients pursue their financial goals. Job Overview:As a member of the Information Security team, the Sr. Application Security Engineer will be responsible for helping to develop, mature, and sustain the Application Security program for the...SuggestedFull timeWork from home$99k - $225k
Application Security EngineerThe Opportunity: Everyone is trying to “harness the cloud”, but not everyone knows how. As a cloud computing infrastructure architect, you know how to take advantage of cloud capabilities. On our team of experienced professionals, you’ll use...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work$146k
...their best work. Join us and build for travelers everywhere.Security Engineer IIIOur Technology Team partners with teams across Expedia Group... ...security stakeholders to identify, assess, and remediate application security risks across the services and components you support...SuggestedFull timeShift work- ...of people and we’re just getting started.About The RoleOur Security Engineering team builds intelligent systems that protect Opendoor and our... ...where they matter, not gates where they don't.As our Application Security Engineer, you'll own how we find, prioritize, and...SuggestedWork at officeMonday to FridayShift work
$120k - $202.5k
Who We’re Looking For:The State Street Cyber Security Architecture & Engineering team is seeking an accomplished professional with proven expertise in Application Security (AppSec) and DevSecOps. The ideal candidate will have hands-on experience in application security,...SuggestedFull timeTemporary workFlexible hours$175k - $215k
...enterprise intelligence at scale by giving organizations secure, governed access to all their data, wherever it lives. Built... .... Learn more at starburst.ai.About the roleAs our Senior Application Security Engineer, you'll be the technical owner of application and product...Local areaFlexible hoursShift work- ...and support capacity planning to optimize performance Conduct security checks, recovery drills, and compliance audits, implement security... ....EEO Infosys provides equal employment opportunities to applicants and employees without regard to race; color; sex; gender identity...Full timeTemporary workRelocation
- ...increase in speed is transforming the user experience of AI applications, unlocking real-time iteration and increasing intelligence... ...inference.About the RoleWe are looking for an Application Security Engineer with a strong focus on Vulnerability Management to help secure...
$70 - $75 per hour
...Analyze global intelligence data to inform security protocols and architectural standards.... ...Skills & QualificationsCore Skills:• Application Security (AppSec)• Secure Software... ...DSPM• Vulnerability Research & Reverse Engineering• Python and C Programming• Infrastructure...Contract workTemporary workRemote work$90k - $180k
...integration, and operational health of ASPM, SSPM, and related security platforms.Partner with Application Security teams to align Product Security tooling with... ...: - StockSummaryAs a Senior Application Security Engineer at Walmart, you will provide critical security and...Full timeTemporary workPart time- Job DescriptionSenior Application Security EngineerBasic PurposeWe are seeking an experienced Senior Application Security Engineer with strong expertise in application security testing, vulnerability management, and DevSecOps advisory services. The successful candidate...
$159.3k - $202.4k
Amazon's Information Security team is looking for a security engineer well-versed in the network and system security space to join our security operations... ...to protect our networks, endpoints, servers and applications. You will get the opportunity to work on large-scale...InternshipFlexible hours- Job DescriptionSecurity Application EngineerSeattle (Bellevue, WA) Long Term ProjectNeed GC... ...Suite, Kali Linux) Job Description: Security team is seeking an enthusiastic Security... ...such as billing ops, application support, engineering ops, finance, legal, privacy, risk...
$99k - $225k
Application Security EngineerThe Opportunity:Everyone is trying to “harness the cloud,” but not everyone knows how. As a cloud computing infrastructure architect, you know how to take advantage of cloud capabilities. On our team of experienced professionals, you’ll use...Full timeContract workPart timeWork at officeLocal areaRemote work- Austin, TexasMission Control - Information Security /Employee / Full-Time /On-siteWho is... ...product, platform, and infrastructure engineering teams so that our products and cloud platforms... ...architectureExtensive experience with application and cloud architectures, predominantly...Full timeRelocation
$120k - $202.5k
Who We’re Looking For:The State Street Cyber Security Architecture & Engineering team is seeking an accomplished professional with proven expertise in Application Security (AppSec), Application Detection and Response (ADR), and DevSecOps. The ideal candidate will have hands...Full timeTemporary workFlexible hours$2,500 per month
The ApplicationSecurity Engineer is responsible for enterprise information security systems and infrastructure platforms for WellSky. The scope of this job includes... ...agent permissions (OWASP Top 10 for LLM Applications)Understanding of secure use of AI coding assistants...Full timeWork experience placement$150 per hour
A financial firm is looking for an Application Security Engineer to join their team in Iselin, NJ or NYC.Compensation: $150-200kResponsibilities:Perform Application Security scans (e.g. DAST and SCA) on applications and APIs to identify security vulnerabilities and weaknessesTriage...- ...providing critical information about the right treatments for the right patients, at the right time.Tempus is seeking a Senior Application Security Engineer with deep expertise in penetration testing to lead efforts in identifying and remediating vulnerabilities across web,...Full time
$90k - $125k
...united by our mission of creating opportunities for people where they live, learn, and work.We are seeking a highly skilled Application Security Engineer with strong experience across secure code review, penetration testing, automation, and modern SDLC practices—including...Full timeContract workTemporary workWork at officeLocal areaRemote work3 days per week$107.9k - $195.05k
The Department of Homeland Security (DHS), Customs and Border Protection (CBP) Cyber Security Directorate (CSD) Security Operations... .... Primary ResponsibilitiesLeidos is looking for an Application Security Engineer to support: Application Security Operations and...Full timeWork at officeLocal area$127k - $160.55k
...knowledge you've gained, and the personal interests that shape who you are.Position OverviewZelis is seeking an experienced Application Security Engineer with deep expertise in Software Composition Analysis (SCA) to strengthen the security of our software supply chain and...Full timeWork at officeLocal areaVisa sponsorshipFlexible hours$170k - $235k
...is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars.SR. APPLICATION SECURITY ENGINEER At SpaceX we’re leveraging our experience in building rockets and spacecraft to deploy Starlink, the world’s most...Permanent employmentTemporary workWork at officeWorldwideMonday to FridayFlexible hoursWeekend work$93.6k - $157.56k
OverviewAs someone experienced with securing a wide variety of applications, you are looking for an opportunity to use your skills in an innovative and... ...-oriented environment. As an Application Security Engineer at Esri, you will fill a critical role in helping secure...- ...or Not Required)Preferred.Role Responsibilities: (what they will be doing)Deploy and configure container scanning tools to ensure secure containerized environments.Analyze vulnerabilities identified through container scans, prioritizing remediation based on risk.Develop...
- ...organization, both internally and externallyAbility to travel as required by business and on-call availabilityThe Senior Application Security Engineer is a deeply technical, hands-on engineering and architect-level role responsible for establishing and leading the...
- Opportunity OverviewTeam Overview:The Application Security Engineer, Agentic Secure Code Harness Engineer is a hands-on role responsible for operating, monitoring, and improving an AI-enabled AppSec harness used to evaluate application and infrastructure source code for...Temporary workWork at officeHome officeFlexible hours3 days per week
- Job Role: Application Security Engineer with AWS, Cequence ,API Security(Remote)Location: RemotePrimary FocusDeployment and integration of Cequence API Security Wiz Federal Splunk and Cribl.AWS GovCloud federal government telecom or highly regulated cloud environments.Handson...Remote work
$121k - $148.9k
...our GEM awardsJob DescriptionJoin CoBank's high-performing Application Security team and help protect the applications, cloud services, and data that support our business. You will collaborate with engineering and DevOps teams to integrate security into application development...Work at officeWork visaFlexible hours- ...across the disciplines of program/project management, applications development, infrastructure, Cyber security, and enterprise content/data management services.... ...Requirements:Experience in software engineering with specialized experience in designing, developing...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Application Security Engineer. Be the first to apply!
- hydraulic application engineer United States
- application system engineer United States
- junior application support engineer United States
- application engineer United States
- application performance engineer United States
- network applications engineer United States
- project application engineer United States
- application support engineer United States
- application operations engineer United States
- senior application support engineer United States
