Security Engineer - Automation
Listed on 2026-01-13
-
IT/Tech
Cybersecurity, Cloud Computing
Join to apply for the Security Engineer - Automation role at eBay
At eBay, we’re more than a global ecommerce leader — we’re changing the way the world shops and sells. Our platform empowers millions of buyers and sellers in more than 190 markets around the world. We’re committed to pushing boundaries and leaving our mark as we reinvent the future of ecommerce for enthusiasts. Our customers are our compass, authenticity thrives, bold ideas are welcome, and everyone can bring their unique selves to work — every day.
We’re in this together, sustaining the future of our customers, our company, and our planet. Join a team of passionate thinkers, innovators, and dreamers — and help us connect people and build communities to create economic opportunity for all.
eBay’s Threat Management and Response (TMR) organization is responsible for protecting our global platform and users from evolving cyber threats. We build scalable tools, automate incident response, and drive continuous improvement in our detection and response capabilities.
As part of this mission, the TMR Security Engineering team is expanding its Service Now Automation implementation to enhance automation, data integration, and response efficiency across the enterprise.
AboutThe Role
We are seeking a Service Now Developer – Security Operations to design, build, and maintain Service Now‑based security workflows supporting our global Cyber Security Incident Response Team (CSIRT) and Vulnerability Management programs. This role focuses on leveraging Service Now’s Security Operations suite—including Security Incident Response (SIR), Vulnerability Response (VR), and Threat Intelligence (TI) modules—to streamline processes, automate responses, and integrate with existing enterprise security platforms.
The ideal candidate is an experienced Service Now developer with deep knowledge of security operations, automation, and enterprise integrations.
- Design, develop, and implement Service Now Sec Ops modules (SIR, VR, TI, and Event Management).
- Build and maintain automated workflows, UI policies, business rules, and script includes.
- Develop REST/SOAP integrations with tools such as Splunk, Crowd Strike, Qualys, Salesforce, and BMC Remedy.
- Develop custom dashboards and Performance Analytics to track security metrics and incident response performance.
- Implement enhancements in the Service Portal to improve usability for security teams.
- Maintain the reliability, scalability, and security of the Service Now platform through regular patching, upgrades, and configuration management.
- Partner with Security Engineering, CSIRT, and Vulnerability Management teams to align workflows with operational needs.
- Troubleshoot issues, perform root cause analysis, and ensure high availability of production environments.
- Contribute to continuous improvement initiatives for security automation and incident management.
- 5+ years of software development experience using JavaScript, Angular
JS, HTML, CSS, and AJAX. - 1+ years of experience as a Service Now Developer and Administrator.
- Hands‑on experience with Service Now Security Operations (Sec Ops) modules.
- Good understanding of Service Now scripting, integrations, and architecture (Business Rules, Script Includes, Flow Designer, Transform Maps).
- Experience developing integrations using REST/SOAP APIs and working with MID Server and Integration Hub.
- Knowledge of SQL and experience diagnosing data‑related performance issues.
- Familiarity with source control tools (GIT, Maven) and UNIX shell scripting.
- Ability to design and execute unit, integration, and regression tests.
- Strong problem‑solving skills and ability to work cross‑functionally within technical and non‑technical teams.
- Service Now Certified System Administrator (CSA)
- Service Now Certified Implementation Specialist – Sec Ops
- Service Now Certified Application Developer (CAD)
- Knowledge of cybersecurity frameworks (NIST 800‑61, MITRE ATT&CK, ISO 27001).
- Experience integrating Service Now with SIEM, SOAR, or Threat Intelligence platforms.
- Exposure to enterprise‑scale incident management or SOC environments.
$118,800 -…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).