About The Position

The Moveworks Security team at ServiceNow is seeking a Staff Agentic Security Engineer to automate the Security Operations Center (SOC) through autonomous systems. This role, at the IC4 level, involves defining the architectural framework for AI-driven defense, treating incident response as an advanced engineering problem. The engineer will experiment with, design, and orchestrate complex, multi-agent frameworks and Model Context Protocol (MCP) systems for proactive threat hunting, triage, and remediation at machine speed. This is an opportunity for a visionary engineer to push the boundaries of agentic AI in enterprise defense.

Requirements

  • U.S. Citizenship Required (Must meet strict compliance/FedRAMP criteria).
  • 8–10 years of experience in Security Operations, Systems Engineering, or DevSecOps (Minimum 5 years of highly relevant engineering experience required).
  • 3–5 years of proven track record working closely across multidisciplinary teams including Cloud Infrastructure, DevOps, DevSecOps, Compliance, and IT.
  • Deep familiarity with modern LLM agent frameworks, including active research into their application, performance trade-offs, and behavioral guardrails.
  • High proficiency in Python and software engineering principles.
  • Extensive past experience with traditional workflow engines and legacy SOAR tooling.
  • Strong, hands-on architectural familiarity with AWS security ecosystems (IAM, CloudTrail, GuardDuty) and containerized environments (Kubernetes/EKS).
  • Communication skills and security compliance maturity to translate framework controls into automated, code-driven evidence generation pipelines.
  • High-autonomy, high-collaboration mindset, thriving in a lean, elite, fast-moving team environment.
  • Ability to independently drive massive technical impact while mentoring and leveling up surrounding engineers.

Nice To Haves

  • Direct collaboration experience with Product Security or Data Security teams.

Responsibilities

  • Build, code, design, and research advanced, framework-level approaches for chaining MCP servers and AI agents, optimizing agentic networks for performance, reasoning accuracy, and deterministic outcomes.
  • Architect and scale a proactive threat hunting program using custom agents, MCP capabilities, and security tooling to discover vulnerabilities, configuration drift, and hidden threats.
  • Forge a feedback loop between the Blue Team and an internally developed AI Red Team Agent, bridging automated offense and defense, and turning threat hunting insights into self-healing infrastructure.
  • Act as a strategic engineering partner across IT, Security Engineering, DevOps, DevSecOps, Compliance, Cloud, and Infrastructure teams to ensure corporate systems are automation-ready.
  • Own the engineering roadmap for the end-to-end incident response lifecycle (Detection → Triage → Containment → Recovery), replacing traditional SOAR workflows with agentic orchestration.
  • Serve as a high-tier technical escalation point for active, complex incidents, using each incident as data to design superior automated immune responses.
  • Design, execute, and validate automated simulation testing to prove the reliability of agentic workflows and detection pipelines against real-world attack behaviors.

Benefits

  • Flexible work personas (flexible, remote, or required in office).
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service