About this role
Zafran's ServiceNow application is on the ServiceNow Store and is how a large part of our enterprise customer base experiences our product day to day. It has been built and maintained by an external partner; we are bringing it in-house.
You would be the first ServiceNow engineer at Zafran and the owner of that application end to end — architecture, roadmap, code, certification, releases, and customer escalations. This is a product engineering role, not a platform administration or consulting role. You are not implementing ServiceNow for internal users; you are shipping a certified commercial application that installs into instances you do not control, at organizations whose configurations and data volumes you cannot predict.
The work is substantially independent, with real ownership over technical direction, and sits close to both our product team and our customers' security operations teams
About Zafran:
Our Mission: To stop the exploitation of vulnerabilities, everywhere.
What makes us different: Zafran de-risks 90% of critical vulnerabilities overnight across your hybrid environment and utilizes Agentic Capabilities and your existing security tools to rapidly mitigate and remediate the 10% most likely to be exploited.
Who's behind us: Zafran is backed by Menlo Ventures, Sequoia Capital, Cyberstarts, and a deep belief that cybersecurity should move as fast as attackers do. We're one of the fastest-growing companies in the industry, scaling to meet demand from the world's most advanced, security-obsessed organizations.
We're serious about our mission- so expect work that matters, teammates who challenge and inspire you, and plenty of fun along the way!
What you'll own
- Architecture, development, and maintenance of Zafran's scoped ServiceNow application
- Integration between Zafran's platform and ServiceNow — data ingestion, correlation of findings to configuration items, remediation workflows, and bidirectional sync
- Alignment with the Vulnerability Response / Unified Security Exposure Management data model, and the migration path as customers move onto USEM
- The full ServiceNow Store certification cycle: building to certification requirements, passing security and performance review, maintaining design documentation, and shepherding each submission through the review process
- Release currency — ServiceNow ships two major releases a year and requires supported apps to stay within the n-3 window. You own that calendar.
- Versioning and upgrade paths: shipping new versions without breaking existing customers, including migration logic where the data model changes
- Automated testing (ATF and beyond), source control, and release engineering for the application
- Technical escalations from customers' ServiceNow administrators, and the technical side of pre-sales conversations when a prospect's ServiceNow team has hard questions
- Transition and knowledge transfer from our current external development partner
Required
- 5+ years building on ServiceNow, with substantial scoped application development
- 5+ years of hands-on experience in backend development with languages such as Golang, Python, Java, JavaScript, or C/C++
- The ability to quickly learn and adapt to new technologies as needed
- Strong problem-solving, sense of ownership and communication skills, with the ability to work well in a team environment
- 5+ years of experience, in at least 2 positions
- Mentality of a team player, with a capability to see the big picture, and use it to focus on critical detail
- Capability and will to take responsibility and have a deep influence
- Experience shipping at least one application to the ServiceNow Store and taking it through certification — ideally including at least one recertification for a new release family
- Strong server-side JavaScript / Glide scripting; Scripted REST APIs, IntegrationHub, Flow Designer
- Solid CMDB knowledge, including CI identification and reconciliation, and familiarity with CSDM
- Experience with source control and automated testing for ServiceNow applications, not just update-set-driven development
- Comfortable owning a shipped product surface: versioning, backward compatibility, release notes, upgrade paths, and direct customer support
- Defensive engineering instincts for code that runs in environments you cannot inspect — unknown customizations, unexpected data volumes, partial failures, rate limits, and retries
- Clear written communication with customers' technical teams
Strongly preferred
- Hands-on experience with ServiceNow Vulnerability Response, Unified Security Exposure Management, or Security Operations — particularly third-party integrations built on the VR integration framework
- Prior work at an ISV or technology vendor with a listing on the ServiceNow Store
- Service Graph Connectors
- MID Server architecture, especially for customers with on-premises or network-restricted deployments
- Certified Application Developer (CAD)
- CIS–Vulnerability Response
Nice to have
- Security background more broadly — vulnerability management, exposure management, or SOC workflows
- Experience with domain-separated instances as a deployment target (MSPs and large enterprises may install our app; it needs to behave correctly there)
- Experience running a partner relationship with ServiceNow's Build Partner / Technology Partner Program
