IMPORTANT PLEASE READ BEFORE APPLYING
- Due to Federal requirements only US citizens US naturalized citizens or US Permanent Residents holding a green card will be considered.
- This role requires a minimum of 2 days per week in the San Diego CA or Santa Clara CA ServiceNow Offices. If you cannot meet this requirement we ask that you please do not apply. Thank you.
The ServiceNow Security Organization (SSO)
The ServiceNow Security Organization (SSO) delivers world-class innovative security solutions to reduce risk and protect the company and our customers. We enable our customers to migrate their most sensitive data and workloads to the cloud accelerating our business so that we are the most trusted SaaS provider. We create an environment where our employees are proud to work and can make a positive impact
What you get to do in this role:
ServiceNow has a large and highly skilled security team located at multiple sites globally. As part of a rapidly growing organization ServiceNow is looking to expand its Global Incident Response team. This role is an opportunity to serve on the frontline of security operations supporting both ServiceNows commercial customers and its federal environment. As a rapidly growing organization ServiceNow offers strong opportunities for career growth while developing expertise across our commercial and federal environments and the ServiceNow platform itself.
As an Cybersecurity Incident Response Analyst you will be a key member of the team monitoring tools and systems that defend ServiceNows production and corporate environments defining relationships between seemingly unrelated events through deductive reasoning and continuously finding ways to do things faster better and more effectively while maintaining a laser focus on quality.
You will work on a geographically diverse team to respond to threats that may arise against our infrastructure and track cases to closure working across functional teams.
You will be required to participate in an on-call rotation including weekends to ensure that Security Operations can respond to priority incidents in a timely manner. This role requires to work weekend rotational shifts and hours (pacific time zone) outside of standard business hours if necessary.
Qualifications :
To be successful in this role you have:
- Experience in leveraging or critically thinking about how to integrate AI into work processes decision-making or problem-solving. This may include using AI-powered tools automating workflows analyzing AI-driven insights or exploring AIs potential impact on the function or industry.
- 2 years of related experience or equivalent combination of education and experience.
- Deep understanding of Security Operations Center and Security Incident Response Team protocols and procedures including incident triage and escalation workflows.
- A solid foundation in networking fundamentals with a deep understanding of TCP/IP and other core protocols.
- Experience with SIEM platforms (e.g. Splunk) for log analysis and detection tuning.
- Familiarity with EDR tools for endpoint detection and response.
- Exposure to SOAR platforms for workflow automation and incident orchestration.
- Knowledge of cloud security concepts and experience working in cloud environments (AWS Azure or GCP).
- The ability to analyze event and system logs perform forensic analysis analyze malware and process other incident response-related data as needed.
- Familiarity with intrusion detection systems.
- Understanding of Windows and Linux operating systems and command-line tools.
- Familiarity with scripting in any language.
Nice to Have
- Any cybersecurity or network related certifications (ex: CCNA CompTIA GSEC GCIH CEH certifications).
- ServiceNow platform knowledge is a plus.
#SecurityJobs
FD21
For positions in this location we offer a base pay of $108500 - $168200 plus equity (when applicable) variable/incentive compensation and benefits. Sales positions generally offer a competitive On Target Earnings (OTE) incentive compensation structure. Please note that the base pay shown is a guideline and individual total compensation will vary based on factors such as qualifications skill level competencies and work location. We also offer health plans including flexible spending accounts a 401(k) Plan with company match ESPP matching donations a flexible time away plan and family leave programs. Compensation is based on the geographic location in which the role is located and is subject to change based on work location.
Additional Information :
Work Personas
We approach our distributed world of work with flexibility and trust. Work personas (flexible remote or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here. To determine eligibility for a work persona ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.
Equal Opportunity Employer
ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race color creed religion sex sexual orientation national origin or nationality ancestry age disability gender identity or expression marital status veteran status or any other category protected by addition all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.
Accommodations
We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process or are unable to use this online application and need an alternative method to apply please contact for assistance.
Export Control Regulations
For positions requiring access to controlled technology subject to export control regulations including the U.S. Export Administration Regulations (EAR) ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.
From Fortune. 2025 Fortune Media IP Limited. All rights reserved. Used under license.
Remote Work :
No
Employment Type :
Full-time
IMPORTANT PLEASE READ BEFORE APPLYING Due to Federal requirements only US citizens US naturalized citizens or US Permanent Residents holding a green card will be considered. This role requires a minimum of 2 days per week in the San Diego CA or Santa Clara CA ServiceNow Offices. If you cannot mee...
IMPORTANT PLEASE READ BEFORE APPLYING
- Due to Federal requirements only US citizens US naturalized citizens or US Permanent Residents holding a green card will be considered.
- This role requires a minimum of 2 days per week in the San Diego CA or Santa Clara CA ServiceNow Offices. If you cannot meet this requirement we ask that you please do not apply. Thank you.
The ServiceNow Security Organization (SSO)
The ServiceNow Security Organization (SSO) delivers world-class innovative security solutions to reduce risk and protect the company and our customers. We enable our customers to migrate their most sensitive data and workloads to the cloud accelerating our business so that we are the most trusted SaaS provider. We create an environment where our employees are proud to work and can make a positive impact
What you get to do in this role:
ServiceNow has a large and highly skilled security team located at multiple sites globally. As part of a rapidly growing organization ServiceNow is looking to expand its Global Incident Response team. This role is an opportunity to serve on the frontline of security operations supporting both ServiceNows commercial customers and its federal environment. As a rapidly growing organization ServiceNow offers strong opportunities for career growth while developing expertise across our commercial and federal environments and the ServiceNow platform itself.
As an Cybersecurity Incident Response Analyst you will be a key member of the team monitoring tools and systems that defend ServiceNows production and corporate environments defining relationships between seemingly unrelated events through deductive reasoning and continuously finding ways to do things faster better and more effectively while maintaining a laser focus on quality.
You will work on a geographically diverse team to respond to threats that may arise against our infrastructure and track cases to closure working across functional teams.
You will be required to participate in an on-call rotation including weekends to ensure that Security Operations can respond to priority incidents in a timely manner. This role requires to work weekend rotational shifts and hours (pacific time zone) outside of standard business hours if necessary.
Qualifications :
To be successful in this role you have:
- Experience in leveraging or critically thinking about how to integrate AI into work processes decision-making or problem-solving. This may include using AI-powered tools automating workflows analyzing AI-driven insights or exploring AIs potential impact on the function or industry.
- 2 years of related experience or equivalent combination of education and experience.
- Deep understanding of Security Operations Center and Security Incident Response Team protocols and procedures including incident triage and escalation workflows.
- A solid foundation in networking fundamentals with a deep understanding of TCP/IP and other core protocols.
- Experience with SIEM platforms (e.g. Splunk) for log analysis and detection tuning.
- Familiarity with EDR tools for endpoint detection and response.
- Exposure to SOAR platforms for workflow automation and incident orchestration.
- Knowledge of cloud security concepts and experience working in cloud environments (AWS Azure or GCP).
- The ability to analyze event and system logs perform forensic analysis analyze malware and process other incident response-related data as needed.
- Familiarity with intrusion detection systems.
- Understanding of Windows and Linux operating systems and command-line tools.
- Familiarity with scripting in any language.
Nice to Have
- Any cybersecurity or network related certifications (ex: CCNA CompTIA GSEC GCIH CEH certifications).
- ServiceNow platform knowledge is a plus.
#SecurityJobs
FD21
For positions in this location we offer a base pay of $108500 - $168200 plus equity (when applicable) variable/incentive compensation and benefits. Sales positions generally offer a competitive On Target Earnings (OTE) incentive compensation structure. Please note that the base pay shown is a guideline and individual total compensation will vary based on factors such as qualifications skill level competencies and work location. We also offer health plans including flexible spending accounts a 401(k) Plan with company match ESPP matching donations a flexible time away plan and family leave programs. Compensation is based on the geographic location in which the role is located and is subject to change based on work location.
Additional Information :
Work Personas
We approach our distributed world of work with flexibility and trust. Work personas (flexible remote or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here. To determine eligibility for a work persona ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.
Equal Opportunity Employer
ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race color creed religion sex sexual orientation national origin or nationality ancestry age disability gender identity or expression marital status veteran status or any other category protected by addition all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.
Accommodations
We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process or are unable to use this online application and need an alternative method to apply please contact for assistance.
Export Control Regulations
For positions requiring access to controlled technology subject to export control regulations including the U.S. Export Administration Regulations (EAR) ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.
From Fortune. 2025 Fortune Media IP Limited. All rights reserved. Used under license.
Remote Work :
No
Employment Type :
Full-time
View more
View less