SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
ServiceNow is seeking a Staff AI Security Specialist to secure AI agents and agentic systems within its products and platform. As AI agents gain reasoning, context retrieval, and real-world action capabilities, they present a new and largely unmapped attack surface. This applied role sits at the intersection of AI and security, focusing on building controls that don't yet exist.
In this position, you will:
- Analyze the security of AI agent systems, including how harnesses assemble context, drive tool-calling loops, handle planning and delegation, manage memory persistence, and respond to untrusted input. Identify where adversaries can subvert these systems.
- Design and build security controls for agentic systems: static analysis of agent and tool configurations, runtime policy enforcement, behavioral detection, and mitigations for tool and goal hijacking.
- Build working prototypes end-to-end, then partner with engineering teams to harden proven solutions.
- Threat model new AI architectures and features before shipping, converting findings into concrete controls rather than risk lists.
- Red-team ServiceNow's own agents and defenses, including indirect prompt injection, tool abuse, privilege escalation across agent boundaries, and data exfiltration through model and tool channels.
- Build repeatable evaluations and benchmarks to measure control effectiveness as models and products evolve.
- Track offensive and defensive AI security research, quickly assessing what's real, what's noise, and what should influence the roadmap.
- Advise product and platform teams on secure agentic design and deepen the team's collective AI security expertise.
- Publish research, patents, and external talks on findings worth sharing.
Requirements:
- 6+ years of combined experience in security, software engineering, or applied research, including 2+ years hands-on with AI/ML or LLM-based systems.
- Strong working knowledge of agent harness security: system prompt and context construction, tool-calling loops, context window management, sub-agent delegation, sandboxing, and execution boundaries.
- Working knowledge of agent memory and retrieval systems, orchestration frameworks (e.g., MCP), and their failure modes.
- Demonstrated depth in at least one security domain (application security, offensive security, authorization/identity, or detection engineering), with attacker-centric reasoning.
- Practical understanding of AI-specific threats: prompt/tool/goal hijacking, indirect injection through retrieved content, memory poisoning, adversarial instruction persistence, insecure configurations, cross-session/cross-tenant data leakage, OWASP Top 10 for LLM Applications, and MITRE ATLAS.
- Proficiency in Python, sufficient to independently build and ship working systems.
- Ability to take ambiguous problems to working artifacts, own them end-to-end, and abandon them when evidence warrants.
- Ability to communicate technical concepts to both non-technical business users and technical stakeholders.
- Experience leveraging AI integration into work processes, decision-making, or problem-solving.
Preferred qualifications:
- Experience building systems that make and enforce security decisions at runtime.
- Experience building static or dynamic analysis tooling.
- Experience with AI red-teaming, adversarial ML, or evaluating models and guardrails at scale.
- Published security or AI research, patents, CVEs, or meaningful open-source contributions.