
PS, Solution Architect ( Armis/Veza)
ServiceNow5 hours ago
Remote, Spain or Madrid, SpainSenior / Staff+
Responsibilities
- Lead the Application Security program across all Armis products and embed security throughout the SDLC.
- Perform secure architecture reviews and lead threat modeling using STRIDE, DREAD, or PASTA.
- Own application-layer vulnerability management from detection through remediation and validation within the VIPR strategy.
- Integrate SAST, DAST, SCA, and API testing findings into centralized workflows, risk scoring, and prioritization models.
- Build and maintain automated AppSec pipelines and integrate security scanning into CI/CD pipelines using GitHub Actions, Jenkins, and Buildkite.
- Partner with cloud and infrastructure security teams to secure APIs, microservices, and containerized workloads.
- Develop secure coding standards and security baselines for React, Node.js, Python, Java, and Go.
- Mentor engineers and security champions and deliver secure coding and threat modeling training.
- Support compliance and audit readiness for SOC 2, ISO 27001, FedRAMP, and HIPAA.
Requirements
- 7–10+ years of experience in Application Security, Product Security, or Secure Software Engineering.
- Expertise with SAST, DAST, SCA, and dependency management tools such as Veracode, Checkmarx, Fortify, Snyk, SonarQube, and OWASP Dependency-Check.
- Experience in a SaaS, cloud-native, or cybersecurity product company is preferred.
- Hands-on experience integrating AppSec into vulnerability, VIPR, or exposure management programs is preferred.
- Familiarity with Prisma Cloud, Wiz, or Orca is preferred.
- Experience with Terraform or CloudFormation-based IaC security is preferred.
- Experience with API Gateway security, OAuth2, token-based authentication, and zero-trust architectures is preferred.
- Relevant certifications such as OSWE, CSSLP, GWAPT, GWEB, or CEH are preferred.
- Hands-on coding proficiency in at least two modern languages, including Python, JavaScript/TypeScript, Java, or Go.
- Strong experience managing vulnerabilities through triage, prioritization, remediation tracking, and validation.
- Deep understanding of OWASP Top 10, CWE, CVE, and exploitability concepts.
- Strong knowledge of CI/CD pipelines, Git-based workflows, secure build automation, threat modeling, secure architecture reviews, and microservices/API security.
Benefits
- The position is based in Spain and is classified as Flexible or Remote under ServiceNow’s distributed work personas.
- The employee type is regular and the role is in the EMEA region.
- ServiceNow provides reasonable accommodations during the application process.
Tech Stack
BuildkiteDockerGitGitHub ActionsGoJavaJavaScriptJenkinsKubernetesNode.jsPythonReactSonarQubeTerraformTypeScript
Categories
About ServiceNow
ServiceNow builds a cloud platform for enterprise digital workflows, covering IT service management, customer service, HR service delivery, security operations, and operations management, plus tools for custom app development. It sells subscription SaaS to large organizations and public-sector agencies to automate processes and connect data across systems. Founded in 2004 and headquartered in Santa Clara, California, ServiceNow is a public company listed on the NYSE under the ticker NOW.