About the job
As Principal Engineer for AI Security Governance, you will own the technical strategy, architecture, and hands-on delivery of the program end to end. You will set direction across two governance tracks — enterprise-wide AI traffic and ServiceNow platform AI — and personally build and mature the controls that enforce it. This is a senior individual-contributor role: you will lead through technical authority, architecture, and mentorship rather than direct-report management, and you will be a driving force in ServiceNow’s internal AI transformation, moving the security function from manual effort toward AI-automated operations.
Responsibilities
Own the vision, strategy, and roadmap for the AI Security Governance Program across all five control pillars
Architect controls across both the enterprise-AI and platform-AI tracks, keeping the two governance paths distinct and defensible
Deploy, configure, and mature security controls hands-on — including AI detection and response, data security posture management (DSPM/AISPM), and data-path controls for unmanaged access
Drive the shift from manual security operations to AI-automated workflows, building automation into every control rather than staffing around it
Close the highest-severity gaps in AI data protection, agent permissions, and shadow AI
Author and sustain the risk narrative and technical materials for CISO, board, and Audit Committee audiences to a standard of precision that never overclaims
Provide technical leadership and mentorship to engineers and cross-functional partners, and bring data to every decision
Qualifications
Minimum
15+ years of relevant experience in security and software engineering, including hands-on technical leadership, or similar experience with education
Deep, current expertise in AI security — LLM and generative-AI threats, agentic-AI risk, prompt and response protection, AI/ML supply chain, and AI governance frameworks
Strong architecture and engineering skills across cloud and SaaS environments, and the ability to build and operate controls directly, not only design them
Experience with data security tooling (DSPM/AISPM, DLP, CASB) and identity/entitlement controls
A track record of translating complex technical risk into executive-, board-, and auditor-ready narratives
Strong problem-solving across security and software engineering, and the ability to apply data for diagnostics and to make the case for new solutions
Working knowledge of compliance and regulatory standards, and experience in Agile practices
Ability to build trusted relationships with security and engineering teams across the company
Eligible for adjudication to access US regulated market environments; permanent residency or citizenship required
Preferred
No preferred qualifications listed.