Principal Outbound Product Security Manager
ServiceNow
- Location
- Santa Clara, California, United States
- Employment
- Full Time
- Work model
- On-Site
- Level
- Principal
- H-1B history
- 185 approvals (FY2023)
- Posted
- 1h ago
Skills
About this role
Company Description
It all started when engineer Fred Luddy wrote code that automated a tedious task for his coworker, Phyllis. She cried tears of joy. That moment inspired Fred to build a company that could do that for everyone—freeing people from busywork so they could focus on meaningful work. Today, ServiceNow is the AI control tower for business reinvention. Our ServiceNow AI platform brings together any AI, any data, and any workflow— helping 85% of the Fortune 500® work smarter, faster, and better. We're building an AI-native culture where technology and talent are unstoppable together. And we're just getting started. Join us to put AI to work for people. Job Description **PLEASE NOTE** This role has a minimum of 2 days per week in a ServiceNow Office.
If you are unable to come into the office 2 days per week, please do not apply. Thank you. The ServiceNow Security Organization (SSO) The ServiceNow Security Organization (SSO) delivers world-class, innovative security solutions to reduce risk and protect the company and our customers. We enable our customers to migrate their most sensitive data and workloads to the cloud, accelerating our business so that we are the most trusted SaaS provider. We create an environment where our employees are proud to work and can make a positive impact The Opportunity ServiceNow's Product Security organization is undergoing a fundamental transformation—from reactive to proactive, from reporting issues to delivering solutions. This role is critical to that transformation to bridge the gap between cutting-edge AI security challenges and practical, implementable solutions that our engineering teams will actually adopt. This is not a traditional Product Security role. You'll need technical depth to earn credibility with skeptical engineers and product excellence to drive adoption without friction. The Challenge Our world-class engineering organization needs a security partner they can trust—someone who understands their constraints, speaks their language, and brings solutions, not just problems. Your technical depth must earn their trust, while your product acumen drives adoption of security solutions that enhance, rather than hinder, developer productivity.
Our Guiding Principles Protect the Brand: Reduce the impact of major security incidents. Enable the Business: Maintain and automate regulatory compliance (FedRAMP, GDPR, etc.). Secure by Default: Ship secure products with minimal friction for customers. Partner Seamlessly: Integrate security ("shift left") without slowing down engineering.
What You'll Do
Own the AI Security Product Strategy (40%) Define and drive the product roadmap for securing agentic AI across internal systems and customer offerings Balance emerging AI threats (prompt injection, model extraction, data poisoning) with implementation realities Transform Red Team findings and security research into a prioritized, data-driven backlog Shift the narrative from "security as tax" to "security as competitive advantage" Be the Technical Authority (35%) Lead architectural reviews with deep expertise in: Agentic AI frameworks (LangChain, LangGraph) and their attack surfaces Authentication patterns for distributed AI systems (OAuth 2.0, OIDC, MCP, A2A protocols LLM vulnerabilities and practical mitigations Provide hands-on guidance that minimizes friction while maximizing protection Earn engineering trust through demonstrated technical depth, not position or process Drive Cross-Functional Execution (25%) Partner with Platform and Product Engineering PMs to embed AI security into development lifecycles Define success metrics that balance security effectiveness with developer experience Coordinate with Documentation, Training, and Professional Services for smooth rollouts Engage key enterprise customers on their AI security