
Staff Product Security Engineer, PSIRT
ServiceNow7 hours ago
Hyderābād, IndiaStaff+
Responsibilities
- Lead technical and organizational response during significant product security events.
- Coordinate incident ownership, prioritization, hand-offs, remediation, and release activities across engineering, product, test, and release teams.
- Investigate vulnerabilities, distinguish real exploitability from theoretical risk, and verify the completeness of fixes and mitigations.
- Contribute to CVE assignment, scoring, advisory development, disclosure timing, and technical reviews of external and joint disclosure materials.
- Author root-cause analyses, lead retrospectives, and drive lessons learned and security process improvements to closure.
- Track product security risk themes and feed incident findings into SDLC and secure development improvements.
Requirements
- At least 8 years of related experience with a bachelor’s degree, 6 years with a master’s degree, 3 years with a PhD, or equivalent experience.
- At least 4 years auditing source code for security vulnerabilities.
- Demonstrated leadership during significant security events or major incidents and willingness to participate in on-call.
- Ability to read and comprehend Java and JavaScript and strong understanding of vulnerabilities in both languages.
- Proficiency scripting in Python and JavaScript for data gathering, processing, and visualization.
- Experience developing proof-of-concept exploits for web application vulnerabilities.
- Experience leading fix implementation and release coordination across engineering, product, and test/release teams.
- Proficiency conducting product security investigations and root-cause analysis across design, code, configuration, and operational layers.
- Familiarity with SDLC integration, CI/CD pipelines, SaaS threat models, and secure development practices.
- Experience integrating or critically evaluating AI in work processes, decision-making, or problem-solving.
- Preferred experience in PSIRT or similar functions, vulnerability research, application security, ServiceNow platform vulnerability assessments, AI-specific attack vectors, software supply chain security, SDLC tooling security, AWS, Azure, GCP, and containerized environments.
- Relevant security certifications such as OSWE or equivalent demonstrated expertise.
Benefits
- Regular employee position in the APAC region.
- Flexible work persona within ServiceNow’s distributed work model.
Categories
About ServiceNow
ServiceNow builds a cloud platform for enterprise digital workflows, covering IT service management, customer service, HR service delivery, security operations, and operations management, plus tools for custom app development. It sells subscription SaaS to large organizations and public-sector agencies to automate processes and connect data across systems. Founded in 2004 and headquartered in Santa Clara, California, ServiceNow is a public company listed on the NYSE under the ticker NOW.