
Staff Product Security Engineer, PSIRT
ServiceNow12 hours ago
Hyderābād, IndiaStaff+
Responsibilities
- Lead technical and organizational response during significant product security events.
- Coordinate incident ownership, prioritization, workstreams, and hand-offs with incident commanders, security leadership, engineering, product, release, and customer-facing teams.
- Drive vulnerability remediation across affected releases and verify that fixes and mitigations are complete before release.
- Contribute to CVE assignment, severity scoring, advisory content, and publication timing.
- Review external advisories, researcher write-ups, and coordinated disclosure materials for technical accuracy.
- Conduct deep-dive product security investigations, exploit analysis, and proof-of-concept exploit development.
- Author root-cause analyses, lead retrospectives, and drive lessons learned and corrective actions to closure.
- Identify product security risk themes and trends and feed incident learnings into SDLC and secure development improvements.
- Participate in on-call coverage and provide additional coverage during significant incidents.
Requirements
- At least 8 years of related experience with a bachelor’s degree, 6 years with a master’s degree, 3 years with a PhD, or equivalent experience.
- At least 4 years auditing source code for security vulnerabilities.
- Demonstrated leadership during significant security events or major incidents and willingness to participate in on-call coverage.
- Ability to read and understand Java and JavaScript code and common vulnerabilities in those languages.
- Proficiency in Python and JavaScript scripting for data gathering, processing, and visualization.
- Experience developing proof-of-concept exploits for web application vulnerabilities.
- Ability to communicate complex security risks clearly to technical teams and leadership.
- Experience leading fix implementation and release coordination across engineering, product, and test/release teams.
- Proficiency in product security investigations and root-cause analysis across design, code, configuration, and operational layers.
- Familiarity with SDLC integration, CI/CD pipelines, SaaS threat models, and secure development practices.
- Experience using or critically evaluating AI in work processes, decision-making, or problem-solving.
- Preferred experience in PSIRT or a similar function for a major software or SaaS platform.
- Preferred expertise in product security incident response, vulnerability research, or application security.
- Preferred experience conducting vulnerability assessments on the ServiceNow platform.
- Preferred experience with AI-specific attack vectors, software supply chain security, SDLC tooling security, cloud infrastructure, and containerized environments.
- Relevant security certification such as OSWE or equivalent demonstrated expertise.
Benefits
- Flexible work persona with remote, flexible, or required-in-office arrangements determined by role and location.
- Regular employee position in the APAC region.
- Scheduled coverage includes Sunday, Monday, Tuesday, Friday, and Saturday hours, with additional coverage potentially required during significant incidents.
- Equal opportunity and reasonable accommodation support are provided.
Categories
About ServiceNow
ServiceNow builds a cloud platform for enterprise digital workflows, covering IT service management, customer service, HR service delivery, security operations, and operations management, plus tools for custom app development. It sells subscription SaaS to large organizations and public-sector agencies to automate processes and connect data across systems. Founded in 2004 and headquartered in Santa Clara, California, ServiceNow is a public company listed on the NYSE under the ticker NOW.