Senior Staff Security Incident Commander | Security Org
$165.5k - $289.6kServiceNow
Senior Staff Security Incident Commander | Security Org
The ServiceNow Security Organization (SSO) delivers world-class, innovative security solutions to reduce risk and protect the company and our customers. We enable our customers to migrate their most sensitive data and workloads to the cloud, accelerating our business so that we are the most trusted SaaS provider. We create an environment where our employees are proud to work and can make a positive impact.
ServiceNow's Security Incident Command (SIC) team is seeking an experienced senior security incident commander to join our fast-growing team. This role will support the orchestration of incident response strategy and communications during critical information security-related incidents.
The SIC team maintains and executes the Major Security Incidents (MSI) lifecycle within ServiceNow, including Preparation, Response, and Recovery. MSIs are our most challenging and impactful security incidents which pose active or heightened risk to the company and/or our customers.
Key value areas are preparing the company for MSIs through tabletop exercises (TTX), coordination of activity between many response workstream partners, maintenance and development of playbooks and procedures, tracking key MSI metrics and facts to keep everyone oriented, and communicating status, milestones, blockers, and critical decisions needed to senior management and executive stakeholders, including the CISO.
What you get to do in this role:
- Orchestration of response and remediation of incident response for highest criticality security events.
- Take ownership and lead response to critical incidents within the company.
- Establish and mature documentation surrounding protocols and procedures governing the security incident command team.
- Prepare and deliver communications, including executive summaries and incident briefings, to key stakeholders during and after incident response.
- Conduct rapid response, mitigation, and investigations on the highest priority cases impacting ServiceNow and user data.
- Partner with the team members across multiple regions to drive response and investigations globally.
- Organization and facilitation of scenario-based exercises to test and improve incident management and response strategies.
- Maintenance of existing playbooks and procedures, as well as developing new ones, to further standardize SIC and its partners' responses when verifying MSIs.
- Contribute to the organization and completion of Post-Incident Reviews (PIRs) and Root Cause Analyses (RCAs) following major security incidents.
- Identify new ways to simplify, integrate, automate and refine the major security incident process to better support internal and external stakeholders.
Qualifications:
- Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making or problem-solving. This may include using AI-powered tools, automating workflows, analyzing AI-driven insights, or exploring AI's potential impact on the function or industry.
- 12+ years of total cybersecurity professional experience or similar experience with education
- 5–8+ years of deep domain expertise in incident response and/or incident management
- Experience leading or supporting complex security incidents to resolution end-to-end.
- Excellent verbal and written communication skills (English)
- Comfort communicating complex topics in a clear and concise manner to different tiers of audiences (highly technical, less technical, executives, practitioners)
- Problem-solving and decision-making skills
- Ability to quickly and accurately assess a situation, identify and prioritize risks, and make sound decision
- Familiarity with cybersecurity principles and frameworks (e.g. MITRE ATT&CK).
- Knowledge across multiple security domains is a plus.
- Experience planning and/or orchestrating tabletop exercises is a plus.
West Palm Beach Florida (WPB) is available for relocation. Full relocation costs are provided by ServiceNow.
For positions in this location, we offer a base pay of $165,500 - $289,600, plus equity (when applicable), variable/incentive compensation and benefits. Sales positions generally offer a competitive On Target Earnings (OTE) incentive compensation structure. Please note that the base pay shown is a guideline, and individual total compensation will vary based on factors such as qualifications, skill level, competencies, and work location. We also offer health plans, including flexible spending accounts, a 401(k) Plan with company match, ESPP, matching donations, a flexible time away plan and family leave programs. Compensation is based on the geographic location in which the role is located and is subject to change based on work location.
Work personas are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here . To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.
ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.
We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact View email address on click.appcast.io for assistance.
For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.
$100k
Playlist, based in New York, is seeking a Security Analyst III to lead complex security operations and incidents. You will mentor team members and optimize processes within a dynamic SOC environment. The ideal candidate should have over 7 years in security operations,...Senior$166k - $220k
A defense technology company is seeking a Security Operations Analyst in Washington, D.C. The role involves monitoring alerts and responding to incidents across various environments, focusing on optimization of detection signatures and threat hunting. Candidates should...Senior- A defense technology firm in Seattle is seeking a Security Operations Analyst to monitor and respond to adversarial activity. As a Senior Analyst, you will lead incident responses, conduct threat hunting, and collaborate with cross-functional teams to optimize security...Senior
- A defense technology company is seeking a Security Operations Analyst to monitor and respond to security incidents. You will manage alerts across various disciplines, develop detection automation, and lead incident response efforts. Candidates must have experience in security...SeniorFull time
$166k - $220k
A leading defense technology company is seeking a Security Operations Analyst in Costa Mesa, California. The role involves monitoring and responding to security incidents, collaborating across teams, and conducting threat hunts to ensure the security of cutting-edge military...Senior$180k
...About the Role As a Senior Security Technologist, Incident Command, you are accountable for leading Uber’s most critical, complex, and high-impact security incidents end-to-end - from escalation to containment, recovery, and systemic remediation. You operate at...SeniorFull timeWork at officeRemote work$166k - $220k
A defense technology company in Seattle is seeking a Security Operations Analyst to monitor and respond to adversarial activity. This role involves triaging alerts, optimizing detection signatures, and participating in threat modeling. Candidates should have experience...Senior- ...Leading incident management processes, the full-time remote Senior Incident Commander will facilitate resolution of major incidents, develop standard operating procedures, and ensure effective communication with stakeholders while providing daily incident management support...SeniorFull timeRemote work
$24 per hour
...Incident Commander Base hourly rate: $24.00 Schedule: Full Time (Thursday, Friday, Saturday - 12 hour shifts) Surefox North America... ...compliance requirements within the provided guidelines. Perform security patrols of designated areas on foot, while monitoring access...Hourly payFull timeImmediate startRelocationShift work- Axon Enterprise in New York is looking for a Senior Incident Response Manager to oversee the escalation lifecycle of incidents. This role requires strong operational accountability, executive-level communication, and the ability to lead cross-functional teams during critical...Senior
- Aurora is seeking a Senior Incident Commander to lead incident response for their autonomous vehicle platform and supporting systems. The ideal candidate will coordinate technical incidents, manage escalations, and contribute to continuous improvement initiatives. Qualified...Senior
- Honeywell Aerospace is seeking a Principal Incident Response Analyst in Phoenix, AZ or remote. This role focuses on leading cybersecurity... ...candidate must have at least 5 years of experience in Incident Command and a Bachelor’s Degree, along with strong skills in network...SeniorRemote job
- ...To support the orchestration of incident response strategy and communications during critical information security-related incidents, the full-time California Licensed Security Incident Commander will lead response efforts for high-priority security events, establish documentation...Full timeRemote workFlexible hours
$130k - $160k
...across cloud platformsDevelop and maintain escalation protocols, incident runbooks, and postmortem documentationCommunicate incident... ...architecture and troubleshooting)Strong understanding of networking, security, and distributed systemsProven track record in incident...SeniorFull time$46.84 - $78.06 per hour
...teams who rely on technology every minute of the day.As a Senior Major Incident Commander, you are the calm, decisive commander at the center of... ...help you and your family. We provide health and financial security options, so you can focus on being the best at what you do...SeniorWork experience placementLive inRemote workMonday to FridayShift workNight shift$115k - $204k
Senior Incident Commander We are searching for a Senior Incident Commander to lead incident response across our autonomous vehicle platform, on... ...systems, enterprise IT, and the supporting Network and Security Operations Centers (NOC/SOC). This role applies the principles...SeniorLocal areaNight shiftRotating shift$107k - $214.5k
A leading professional services firm is seeking a DFIR Manager to oversee cyber incident responses, particularly ransomware events. The role demands strong incident command experience, the ability to manage multiple engagements simultaneously, and participation in on-call...Senior$250k - $350k
Fluidstack is seeking a Staff Incident Responder in San Francisco, CA, to lead incident response efforts for their AI infrastructure. In this role, you'll coordinate across various teams, establish standards for incidents, and analyze trends to enhance the incident response...Senior$270k - $370k
Fluidstack is looking for a Principal Incident Responder in San Francisco. This senior role involves leading incident responses and defining the standards and processes for incident management, especially as it pertains to frontier AI operations. You'll be responsible...Senior- RSM US LLP in Chicago is seeking a DFIR Manager to guide organizations through critical cyber events. This role requires strong incident command authority and deep expertise in ransomware investigations and cross-functional leadership. The successful candidate will...Senior
- Fluidstack is seeking a Principal Incident Responder to lead our incident response program within cutting-edge AI infrastructure. You'll coordinate responses to material incidents, develop critical operational processes, and ensure compliance with regulatory obligations...Senior
- A security services company in St. Louis seeks an Incident Commander to act as a liaison with clients and provide emergency response. Responsibilities include monitoring security, responding to incidents, and maintaining compliance with client policies. Candidates must...Flexible hours
- Surefox North America Inc is seeking an experienced Incident Commander in St. Louis to lead emergency response efforts and act as a liaison... ...Responsibilities include developing client relationships, monitoring security, responding to emergencies, and preparing incident reports....Full time
- Surefox Consulting, LLC is looking for a Corporate Security Agent (Incident Commander) in San Francisco. This role is part-time and involves monitoring security systems, providing emergency response, and overseeing incident reports. The ideal candidate will have at least...Part time
- Surefox North America Inc seeks an Incident Commander in San Francisco, CA. This role demands expertise in physical security and emergency response, acting as a key liaison between clients and security teams. Responsibilities include monitoring security systems, conducting...
$166k - $220k
A defense technology firm in Costa Mesa is looking for a Security Operations Analyst to monitor and respond to threats in critical defense... ...signatures, optimizing response automation, and leading incident response. The ideal candidate has experience in security monitoring...Senior- ...Part-time Incident Commanders (Security Officer) Surefox North America Inc is a veteran owned company that prides itself on creating a diverse and unique culture of trained and talented individuals. We are currently seeking experienced individuals with high integrity...Temporary workPart timeFor contractorsWork at officeImmediate startRelocationMonday to FridayShift work
$112k - $200.86k
...8537 Position Overview: Want to help make a better world? As Incident Commander and Analyst at Autodesk you can do just that. How is this possible... ...facing cloud services support at Autodesk by being an elite, Senior Incident Commander, and Analyst. Your finger will be on the...SeniorFull timeFor contractors- A security services provider is seeking an experienced FIFA SRT Supervisor for the Boston... ...coordinate with public safety, and manage incident responses during events. This role... ...a preference for candidates with prior command experience and incident command training...Weekly pay
- A veteran-owned security firm in San Francisco is seeking a Security Officer - Incident Commander to provide emergency response and act as a liaison with clients. This role requires exceptional observational skills, the ability to handle emergencies, and compliance with...Flexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Staff Security Incident Commander | Security Org. Be the first to apply!
- commander United States
- senior game producer United States
- senior manager process engineering United States
- senior manufacturing engineer United States
- senior director fp&a United States
- senior manager clinical operations United States
- senior community manager United States
- senior optical engineer United States
- senior lead project manager United States
- senior manager quality engineering United States

