SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
ServiceNow is seeking a Staff AI Security Specialist to secure AI agents and agentic systems within ServiceNow's products and platform. As AI agents gain reasoning, context retrieval, and real-world action capabilities, they represent a new and largely unmapped attack surface. This role sits at the intersection of AI and security, focusing on building applied security controls.
In this position, you will:
- Analyze the security of AI agent systems, including how context is assembled, tool-calling loops operate, agent planning and delegation mechanisms, memory persistence, and responses to untrusted input, identifying adversarial subversion vectors
- Design and build security controls for agentic systems: static analysis of agent and tool configurations, runtime policy enforcement, behavioral detection, and mitigations for tool and goal hijacking
- Build working prototypes end-to-end and partner with engineering teams to harden proven controls
- Threat model new AI architectures and features before shipping, converting findings into concrete controls
- Red-team ServiceNow's own agents and defenses, including indirect prompt injection, tool abuse, privilege escalation across agent boundaries, and data exfiltration through model and tool channels
- Build repeatable evaluations and benchmarks to measure control effectiveness as models and products evolve
- Track offensive and defensive AI security research, quickly assessing relevance and roadmap impact
- Advise product and platform teams on secure agentic design and elevate organizational AI security depth
- Publish research, patents, and external talks on findings
This is a hands-on technical role requiring deep expertise in both AI systems and security. You will own problems end-to-end, from ambiguous problem statements to shipped controls.
REQUIREMENTS:
- 6+ years combined experience in security, software engineering, or applied research, including 2+ years hands-on with AI/ML or LLM-based systems (required)
- Strong working knowledge of agent harness security: system prompt and context construction, tool-calling loops, context window management, sub-agent delegation, sandboxing and execution boundaries (required)
- Working knowledge of agent memory and retrieval systems, orchestration frameworks (MCP), and their failure modes (required)
- Demonstrated depth in at least one security domain (application security, offensive security, authorization/identity, or detection engineering) with attacker-capability reasoning (required)
- Practical understanding of AI-specific threat landscape: prompt/tool/goal hijacking, indirect injection, memory poisoning, insecure configurations, cross-session/cross-tenant leakage, OWASP Top 10 for LLM Applications, MITRE ATLAS (required)
- Proficiency in Python sufficient to independently build and ship working systems (required)
- Ability to take ambiguous problems to working artifacts, own end-to-end, and abandon without ceremony when evidence warrants (required)
- Ability to communicate technical concepts to non-technical business users and technical stakeholders (required)
- Experience building systems that make and enforce security decisions at runtime (preferred)
- Experience building static or dynamic analysis tooling (preferred)
- Experience with AI red-teaming, adversarial ML, or evaluating models/guardrails at scale (preferred)
- Published security or AI research, patents, CVEs, or meaningful open-source contributions (preferred)