×
September 10, 2026
The ServiceNow Job Nobody Trained For Is The One Everybody Now Needs
Laptop screen showing glowing padlock icons on a linked network diagram, with a person using a smartphone beside it

In the last fortnight ServiceNow patched three vulnerabilities in its AI Platform that each scored a perfect 10.0, none of which required authentication to exploit. In the same window it expanded the AI Control Tower to govern AI across any system in the enterprise, whoever built it. I think those two events point at the same career opportunity, and at a profile the market is short of.

What happened

The advisory came out on 27 August. CVE-2026-18885 allowed arbitrary code execution. CVE-2026-18886 allowed privilege escalation through improper access control. CVE-2026-74820 was a SQL injection flaw against the underlying database. All three scored 10.0, none required authentication or user interaction, and all three were rated low complexity. A fourth, a sandbox escape, scored 8.7.

ServiceNow patched hosted instances directly and released hotfixes for self-hosted deployments across Xanadu, Yokohama, Zurich and Australia.

Separately, coverage in early September described the AI Control Tower being expanded to discover, observe, govern, secure and measure AI deployed across any system, not just ServiceNow’s own. I have not pinned the exact announcement date, so take the timing loosely. Alongside that, this year’s acquisitions tell a consistent story: Armis for asset visibility, Veza for identity governance, and Sweep, which ServiceNow confirmed as completed on 1 September, for a governance layer spanning ServiceNow, Salesforce and HubSpot.

Read those together

ServiceNow is becoming the place enterprises govern all their AI. Which makes the ServiceNow platform itself a very high-value target, and makes the person who secures it a very hard person to replace.

The role that is forming

There is a gap opening between two established professions and it does not yet have a settled job title.

Security teams own vulnerability management but frequently lack depth on the ServiceNow platform itself. Platform teams own the instance but sit inside IT service management, where security advisories are not the daily rhythm. Advisories land in the space between and both sides assume the other has it.

The people who can occupy that gap need three things at once: real hands-on platform knowledge, enough security literacy to read an advisory and work out what it touches in a specific configuration, and enough standing to force an out-of-cycle change when it matters. That is an unusual combination. My expectation is that scarcity of that kind gets priced eventually, though I am not going to pretend I can show you a published benchmark for a role that does not yet have a settled title.

It is also getting broader. When agents hold credentials and act autonomously inside your environment, they become identities that need governing like any other. The controls we built over two decades for human insider risk mostly have not been applied to them, because attention has been on the productivity gain. Somebody has to close that, and it will not be a pure security person or a pure platform person.

How to move towards it

1. Start with what you already have. If you are a platform person, you are closer to this than a security generalist is. Platform depth is the harder half to acquire. Security literacy on top of real ServiceNow experience is a shorter journey than the reverse.

2. Learn the machine identity side. The Zurich release documentation covers capability for securing machine-to-machine integrations, including the Vault and Machine Identity consoles. Check the release notes for what is in your version, then get hands-on. This is the concrete, learnable part of the agent governance problem, and it comes up far less often in conversations than the strategy layer does.

3. Read the advisories, properly. Not the headline. Go and understand which components each CVE touched and why. Doing that four times will teach you more about the platform’s attack surface than any course, and it costs nothing.

4. Build one governance story. How you handled access, auditability, or the decision not to automate something. Even small. Hiring managers are nervous about exactly this and hardly any candidate raises it unprompted.

5. Learn to talk about risk in business terms. The question that decides these interviews is some version of: an agent takes a wrong action against customer data at 2am on a Sunday, what happens? If you can answer that with a clear account of accountability, detection and rollback, you are ahead of nearly everyone.

A realistic word on timing

I am not going to tell you this is an easy pivot or that a certification unlocks it. It is a genuinely senior profile and it usually forms out of an architect or senior developer who has been pulled into governance work informally and then made it their identity.

What I will say, and I want to be clear this is my read rather than a measured finding, is that the demand side is visible in what ServiceNow is buying and building, while the supply side looks thin to me from where I sit. If that is right, it is a good window. If I am wrong about the supply side, the worst case is that you have gone deep on security and governance skills on a platform that is becoming the enterprise control plane for AI, which is not a bad place to be wrong.

If you are three or four years into ServiceNow and wondering where to go deep, this is the most defensible direction I can point you at.

Thinking about your next move? We speak to ServiceNow professionals across the UK, Europe and North America every day and we are happy to give you an honest read on your profile, whether or not you are actively looking. Start a conversation.


Sources: ServiceNow security advisory, 27 August 2026 · SecurityWeek, 31 August 2026 · ServiceNow newsroom

Let's get started

Talk to one of our consultants todays, if you're looking to register a vacancy and apply for a role.

Upload your CV

Submit CV

This field is for validation purposes and should be left unchanged.
Name(Required)
Max. file size: 2 GB.