1

Staff Security Operations Engineer Jobs (NOW HIRING)

THE ROLE As a Security Operations Engineer in the Global Information Security Office (GISO), you will lead the mission to reduce our global attack surface across cloud, endpoint, and SaaS ...

540 is seeking a Security Operations Engineer to support our partnership with Google and the Department of Defense in advancing mission-critical capabilities for a global data processing platform.

Security Operations Engineer

Lehi, UT · On-site

$120K - $180K/yr

THE ROLE As a Security Operations Engineer in the Global Information Security Office (GISO), you will lead the mission to reduce our global attack surface across cloud, endpoint, and SaaS ...

Developing both technical and non-technical solutions in collaboration with engineering teams to address security concerns * Contributing to the development of our team's operational playbooks and ...

540 is seeking a Security Operations Engineer to support our partnership with Google and the Department of Defense in advancing mission-critical capabilities for a global data processing platform.

The Opportunity As a Security Operations Engineer, you will serve on the front lines of our security program, helping protect the organization by detecting, investigating, and containing threats ...

You will drive scanning operations across the stack, partner closely with compliance and engineering teams, and help scale our security tooling and processes as we grow. This is a strong entry point ...

Security Operations Engineer

New York, NY · On-site

$140K - $160K/yr

As a Security Operations Engineer , you'll join our small, growing security team in a hands-on, execution-focused role supporting our vulnerability management and detection programs. This is a ...

Showing results 21-40

Staff Security Operations Engineer information

See salary details

$33.5K

$137.7K

$174K

How much do staff security operations engineer jobs pay per year?

As of Aug 16, 2026, the average yearly pay for staff security operations engineer in the United States is $137,745.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,000.00 and $173,000.00 per year, depending on experience, location, and employer.

What is a staff security operations engineer?

Staff Security Operations Engineers are senior-level professionals responsible for overseeing and enhancing an organization's security operations. They design, implement, and maintain security systems, monitor for threats, and lead incident response efforts. Their role often involves mentoring junior team members, developing security policies, and collaborating with other departments to ensure comprehensive protection of company assets. Staff-level engineers typically have significant experience and play a key role in shaping the organization's overall security posture.

What are the key skills and qualifications needed to thrive as a staff security operations engineer?

To thrive as a Staff Security Operations Engineer, you need deep expertise in cybersecurity principles, incident response, and threat analysis, typically supported by a bachelor's degree in computer science or a related field and relevant certifications like CISSP or GIAC. Familiarity with security information and event management (SIEM) tools, intrusion detection systems (IDS), and scripting languages is essential. Strong analytical thinking, effective communication, and leadership skills help drive security initiatives and coordinate responses across teams. These capabilities are vital to proactively identify threats, minimize risks, and safeguard organizational assets in a constantly evolving threat landscape.

How does a staff security operations engineer typically collaborate with other IT and security teams within an organization?

As a Staff Security Operations Engineer, you'll frequently collaborate with diverse teams such as IT operations, incident response, and application development. Your role involves coordinating threat detection, response efforts, and sharing insights from security monitoring tools with these teams to strengthen overall defense. You'll often participate in cross-functional meetings, incident post-mortems, and architecture reviews to ensure security best practices are integrated into projects. This collaborative approach helps ensure that security measures are both proactive and responsive to evolving threats.

What is the difference between Staff Security Operations Engineer vs Security Analyst?

AspectStaff Security Operations EngineerSecurity Analyst
CredentialsCertifications like CISSP, CISA, Security+Certifications like Security+, CEH, CISSP (preferred)
Work EnvironmentHands-on security monitoring, incident response, system configurationMonitoring security alerts, analyzing threats, reporting
Employer & IndustryTech companies, financial institutions, large enterprisesVariety of industries including healthcare, finance, government

The Staff Security Operations Engineer focuses on implementing and maintaining security systems, responding to incidents, and ensuring infrastructure security. In contrast, a Security Analyst primarily monitors security alerts, analyzes threats, and reports findings. Both roles require relevant certifications and work in similar environments, but the Engineer role is more technical and hands-on, while the Analyst role emphasizes analysis and reporting.

More about Staff Security Operations Engineer jobs

What are the most commonly searched types of Staff Security Operations Engineer jobs?

The most popular types of Staff Security Operations Engineer jobs are:

What job categories do people searching Staff Security Operations Engineer jobs look for?

The top searched job categories for Staff Security Operations Engineer jobs are:

Infographic showing various Staff Security Operations Engineer job openings in the United States as of August 2026, with employment types broken down into 86% Full Time, 11% Part Time, 1% Temporary, and 2% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $137,745 per year, or $66.2 per hour.

Staff Security Engineer, Security Operations - Moveworks

ServiceNow, Inc.

Mountain View, CA • On-site

Other

Re-posted 8 days ago


ServiceNow rating

8.3

Company rating: 8.3 out of 10

Based on 10 frontline employees who took The Breakroom Quiz

99th of 244 rated software companies


Job description

Company Description
Who we are
Moveworks is the Agentic AI Assistant platform that empowers the entire workforce.
Our platform enables employees to converse with all of their business systems through natural language to quickly find answers and automate tasks. Powered by the world's most advanced LLMs, our proprietary models, and a sophisticated Agentic AI platform, we're transforming how work gets done by allowing AI to take initiative, streamline complex workflows, and continuously learn and adapt.
Moveworks is trusted by over 5.5 million employees at more than 350 of the world's largest companies, including 10% of the Fortune 500, to automate everyday tasks and streamline business operations. Recognized on the Forbes Cloud 100 and AI 50 lists, Moveworks was also named one of Fast Company's 2025 Most Innovative Companies and Inc's Best in Business, in the Best in Innovation category. Moveworks was also recognized at Microsoft's 2025 Partner of the Year and in 2024, received the AI Breakthrough Award.
In December 2025, Moveworks was acquired by ServiceNow, marking a pivotal milestone in our journey to create a single front door to work for all business systems. By combining ServiceNow's leading workflow automation with Moveworks' Reasoning Engine and natural language capabilities, we deliver the AI platform for every person and every workflow. Built to go beyond basic summaries to deliver meaningful business impact. Together, our AI acts across enterprise systems to turn conversations into completed work.
By joining our team, you'll be at the forefront of the AI transformation, backed by the global scale of ServiceNow and the agility of a high-growth company. We are looking for world-class talent to help us extend agentic AI to every employee across every corner of the business.
Come join us!
ServiceNow
It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today - ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500 . Our intelligent cloud-based platform seamlessly connects people, systems, and processes to empower organizations to find smarter, faster, and better ways to work. But this is just the beginning of our journey. Join us as we pursue our purpose to make the world work better for everyone.
Job Description
The Moveworks Security team at ServiceNow is not looking for a traditional SOC analyst to watch a dashboard. We are looking for a Staff Agentic Security Engineer. Our ultimate goal is to automate the SOC out of existence through autonomous systems.
At the IC4 level, you will not just execute workflows; you will define the architectural framework for our AI-driven defense. You will treat the incident response lifecycle as an advanced engineering problem-experimenting with, designing, and orchestrating complex, multi-agent frameworks and Model Context Protocol (MCP) systems that handle proactive threat hunting, triage, and remediation at machine speed. This is a role for a visionary engineer who wants to push the boundaries of what agentic AI can achieve in enterprise defense.
What you get to do in this role:
  • Building and AI Orchestration: Move beyond basic tool configuration to build, code, design and research advanced, framework-level approaches for chaining MCP servers and AI agents. You will optimize agentic networks for maximum performance, multi-step reasoning accuracy, and deterministic outcomes in high-stress security scenarios.
  • Proactive Threat Hunting Program: Architect and scale a proactive threat hunting program from scratch. You will leverage custom agents, MCP capabilities, and security tooling to proactively discover complex vulnerabilities, configuration drift, and hidden threats across the infrastructure network.
  • Advanced Purple Team Synergies: Forge a cutting-edge feedback loop between the Blue Team and our internally developed AI Red Team Agent. You will seamlessly bridge automated offense and defense, turning threat hunting insights into self-healing infrastructure.
  • Cross-Functional Influence & Leadership: Act as a strategic engineering partner across IT, Security Engineering, DevOps, DevSecOps, Compliance, Cloud, and Infrastructure teams to ensure corporate systems are natively "automation-ready."
  • E2E IR Automation Architecture: Own the overarching engineering roadmap for the end-to-end incident response lifecycle (Detection Triage Containment Recovery), replacing traditional SOAR workflows with resilient, agentic orchestration.
  • Incident Commander Escalation: Serve as a high-tier technical escalation point for active, complex incidents. Use every incident as an adversarial data point to design superior automated immune responses.
  • Validate the Defense: Design, execute, and validate automated simulation testing to systematically prove that agentic workflows and detection pipelines trigger reliably against real-world attack behaviors.

Qualifications
To be successful in this role you have:
  • U.S. Citizenship Required: (Must meet strict compliance/FedRAMP criteria).
  • Experience: 8-10 years of experience in Security Operations, Systems Engineering, or DevSecOps (Minimum 5 years of highly relevant engineering experience required).
  • Cross-Functional Mastery: 3-5 years of proven track record working closely across multidisciplinary teams including Cloud Infrastructure, DevOps, DevSecOps, Compliance, and IT. Bonus points for direct collaboration experience with Product Security or Data Security teams.
  • AI & Agentic Fluency: Deep familiarity with modern LLM agent frameworks, including active research into their application, performance trade-offs, and behavioral guardrails. You know how to deeply integrate LLMs, orchestrate custom MCP servers, and build autonomous technical workflows.
  • Automation Engineering: High proficiency in Python and software engineering principles. You have extensive past experience with traditional workflow engines and legacy SOAR tooling, giving you the context needed to successfully replace them with AI-native alternatives.
  • Cloud & Infrastructure Depth: Strong, hands-on architectural familiarity with AWS security ecosystems (IAM, CloudTrail, GuardDuty) and containerized environments (Kubernetes/EKS).
  • FedRAMP & Trust Awareness: While an engineer first, you possess the communication skills and security compliance maturity to translate framework controls into automated, code-driven evidence generation pipelines.
  • Team & Collaboration Dynamics: A high-autonomy, high-collaboration mindset. You thrive in a lean, elite, fast-moving team environment where you independently drive massive technical impact while mentoring and leveling up surrounding engineers.

Additional Information
Work Personas
We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here. To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.
Equal Opportunity Employer
ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.
Accommodations
We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact for assistance.
Export Control Regulations
For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.
From Fortune. 2025 Fortune Media IP Limited. All rights reserved. Used under license.

What ServiceNow employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


ServiceNow logo

About ServiceNow

Sourced by ZipRecruiter

At ServiceNow, our technology makes the world work for everyone, and our people make it possible. We move fast because the world can't wait, and we innovate in ways no one else can for our customers and communities. By joining ServiceNow, you are part of an ambitious team of change makers who have a restless curiosity and a drive for ingenuity. We know that your best work happens when you live your best life and share your unique talents, so we do everything we can to make that possible. We dream big together, supporting each other to make our individual and collective dreams come true. The future is ours, and it starts with you. With more than 7,400+ customers, we serve approximately 80% of the Fortune 500, and we're proud to be one of FORTUNE's 100 Best Companies to Work For® and World's Most Admired Companies® 2022.

Industry

It services

Company size

5,001 - 10,000 Employees

Headquarters location

Santa Clara, CA, US

Year founded

2004