What's Happening?
ServiceNow's Product Security organization is establishing a dedicated Security R&D function, a new software engineering team focused on building security capabilities with the same engineering rigor as ServiceNow's product organization. This team, located
in Petah Tikva, Israel, and co-located with ServiceNow’s AI Security Research team, will operate in two complementary modes: open contribution to product engineering and developing its own security capabilities. The latter includes internal tooling, externally facing product features, AI-powered security automation, and third-party integrations. The team will leverage ServiceNow's platform—runtime, ACLs, data layer, and workflow engine—to create unique security capabilities. This initiative aims to build production security capabilities and contribute code directly into ServiceNow product engineering codebases, embedding security where it has the highest impact, and translating AI Security Research insights into production-grade engineering.
Why It's Important?
The formation of ServiceNow's new Security R&D team is a significant development for the U.S. enterprise software market, particularly given the increasing sophistication of cyber threats and the growing reliance on AI in business operations. By building security capabilities directly into its platform and leveraging AI for automation, ServiceNow aims to provide a more robust and resilient environment for its clients. This proactive approach to security, which integrates security expertise directly into product development, is crucial for protecting sensitive data, maintaining operational continuity, and ensuring compliance for businesses across various sectors. The team's focus on AI-powered security automation also highlights the evolving landscape of cybersecurity, where AI is becoming an indispensable tool for threat detection, prevention, and response, ultimately enhancing the trustworthiness and reliability of ServiceNow's offerings for its U.S. customer base.
What's Next?
The new Security R&D team will immediately focus on designing and developing security tooling, automation, and platform services that operate at ServiceNow’s enterprise scale. This will involve contributing code directly into ServiceNow product engineering codebases to embed security capabilities where they have the highest impact. A key area will be building AI-powered security automation by integrating in-house models and third-party services into production workflows. The team will also collaborate closely with the AI Security Research team to translate research insights into production-grade engineering. As a founding team, they will help define engineering best practices, contribute to hiring and onboarding, and stay current on emerging AI/ML technologies and security threats to bring new ideas into the team’s roadmap.
Beyond the Headlines
The establishment of a dedicated Security R&D team co-located with AI Security Research signifies a profound shift in how leading technology companies are approaching cybersecurity. It moves beyond traditional perimeter defense to an integrated, 'security-by-design' philosophy, where security is an inherent part of the product's architecture and development from the outset. This approach, particularly with the emphasis on AI-powered security automation, suggests a future where security systems are not only reactive but predictive and self-optimizing. This has significant ethical and societal implications, as it raises questions about the autonomy of AI in security decisions, the potential for AI-driven vulnerabilities, and the need for robust oversight. The long-term impact could be a more secure digital ecosystem, but also a continuous arms race between AI-powered defenses and AI-powered threats, necessitating ongoing innovation and collaboration within the cybersecurity community.













