SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 201,300 - 352,300 / annual
ServiceNow's Security and Risk Engineering organization is building a zero-to-one incubation for a novel exploitability engine—a new class of exposure analysis that ranks security work by exploitability (where attackers could realistically get in) rather than raw severity.
As Senior Staff Machine Learning Engineer, you own the end-to-end architecture of this security harness and its exploitability engine. You are accountable for the technical decisions that shape everything downstream: you set direction, make hard calls defensible, and multiply the engineers around you.
Key ownership areas:
- End-to-end architecture of the exploitability engine: evidence ingestion, entity resolution, attack-path probability core, choke-point ranking, and validation loops that keep predictions honest.
- Model-shaping decisions: calibrated probability vs. ordinal rank, identity as a first-class graph edge, assume-breach seeding, critical asset definition.
- Probabilistic ranking core: edge-traversal probability, guided path search with hop and likelihood limits, correlated-control-failure modeling, uncertainty bands.
- Calibration and validation loop using canaries, purple-team and incident replay, zone and vector-based calibration.
- Make-or-break metrics as first-class engineering targets (entity-resolution accuracy, calibration quality).
- Build-on strategy: extending existing portfolio, knowing what to reuse vs. what must be net-new.
You will lead zero-to-one work at production scale, turning ambiguous novel problems into reliable systems others build on. You'll drive technical direction across architecture, design, and code reviews; mentor senior engineers; partner with product, security R&D, and SecOps to translate customer problems into architecture; and establish AI safety, security, governance, and guardrails for agentic systems in production.
ServiceNow is the AI control tower for business reinvention, serving 85% of the Fortune 500. The company culture emphasizes AI-first thinking, clean architecture, intuitive experiences, and continuous learning.
REQUIREMENTS:
- 10+ years of software engineering experience, including leading design and delivery of complex production systems.
- Demonstrated experience as technical owner or lead for a major system or across teams.
- Depth building AI/ML-powered production systems; probabilistic modeling, graph analytics, calibration and evaluation strongly preferred.
- Modern AI experience: LLMs, RAG, embeddings, vector search, agentic harness and workflows, model evaluation, AI observability.
- Strong programming in Python and/or Java, Go, or similar language.
- Cloud-native technologies, distributed systems, APIs, databases, scalable architectures.
- Bachelor's or Master's degree in Computer Science, Artificial Intelligence, Machine Learning, or related technical discipline, or equivalent practical experience.
- Cybersecurity or security-product experience, or familiarity with modern security architectures and operations, strongly preferred.
- Track record of owning architecture across large systems or multiple teams with deep production-quality software experience.
- Hands-on depth in agentic and LLM systems and probabilistic/ML-driven scoring (graph modeling, calibration, search, optimization, risk and probability engineering).
- Judgment to make consequential architecture decisions under uncertainty, defensible to engineers and executives.
- Command of distributed systems, APIs, cloud-native development, data or graph systems.
- Expert-level Python and/or Java, Go, TypeScript.
- Technical leadership and mentorship that moves teams through influence.
- Applied interest in security problems (attack-path analysis, vulnerability management, identity security, threat intelligence, detection and response) strongly preferred.
- Experience with AI-assisted development tools (Claude Code, Codex, Cursor, Windsurf) is a plus.
- Experience with AI evaluation, safety, governance, or policy guardrails is a plus.