ServiceNow logo
Monthly
€10,576 - €18,512
Posted August 21, 2026 · 3 days agoLast seen August 23, 2026Est. expiry September 25, 2026

Security Incident Commander

Staff Security Incident Commander
Santa Clara, United States
Remote · Technology
Full-time · Senior
English
No People Management
8 years experience
About the role

The ServiceNow Security Organization (SSO) delivers world-class, innovative security solutions to reduce risk and protect the company and our customers. We enable our customers to migrate their most sensitive data and workloads to the cloud, accelerating our business so that we are the most trusted SaaS provider. The SIC team maintains and executes the Major Security Incidents lifecycle within ServiceNow, including Preparation, Response, and Recovery. MSIs are our most challenging and impactful security incidents which pose active or heightened risk to the company and/or our customers. Key value areas are preparing the company for MSIs through tabletop exercises, coordination of activity between many response workstream partners, maintenance and development of playbooks and procedures, tracking key MSI metrics and facts to keep everyone oriented, and communicating status, milestones, blockers, and critical decisions needed to senior management and executive stakeholders, including the CISO. What you get to do in this role: Orchestration of response and remediation of incident response for highest criticality security events; Take ownership and lead response to critical incidents within the company; Establish and mature documentation surrounding protocols and procedures governing the security incident command team; Prepare and deliver communications, including executive summaries and incident briefings, to key stakeholders during and after incident response; Conduct rapid response, mitigation, and investigations on the highest priority cases impacting ServiceNow and user data; Partner with the team members across multiple regions to drive response and investigations globally; Organization and facilitation of scenario-based exercises to test and improve incident management and response strategies; Maintenance of existing playbooks and procedures, as well as developing new ones, to further standardize SIC and its partners' responses when verifying MSIs; Contribute to the organization and completion of Post-Incident Reviews (PIRs) and Root Cause Analyses (RCAs) following major security incidents; Identify new ways to simplify, integrate, automate and refine the major security incident process to better support internal and external stakeholders.

Job Details

Skills & Technologies

MITRE ATT&CKAIincident responsetabletop exercises

Recruitment Process

  1. 1
    Application
  2. 2
    Screening
  3. 3
    Interview
  4. 4
    Offer
Seen 23 hours agoOpen ApplicationPartial Schema
ServiceNow logo
ServiceNow · 5 open roles
Top locations: Remote - Global · 2 · Washington, United States · 1 · Helsinki, Finland · 1+1 other locations
View company
Most-hired roles
Director, Product Innovation
1
Platform Architect
1
Senior Advisory Solution Consultant
1
Role-level mix
Senior (3)

Help us improve JobCrawls — sign in to sync saved jobs across devices, or send feedback anytime.