
Staff Product Security Engineer, PSIRT
ServiceNow7 hours ago
Hyderābād, IndiaStaff+
Responsibilities
- Lead technical and organizational response during significant product security incidents.
- Coordinate vulnerability remediation across engineering, product, release, test, incident-command, and customer-facing teams.
- Investigate vulnerabilities across design, code, configuration, and operational layers, distinguishing practical exploitability from theoretical risk.
- Verify mitigation completeness and move fixes through affected releases without stalling.
- Contribute to CVE assignment, scoring, advisory review, coordinated disclosure, and publication timing.
- Develop proof-of-concept exploits for web application vulnerabilities.
- Author root cause analyses, lead retrospectives, and drive lessons learned and process improvements to closure.
- Contribute to product security risk tracking, SDLC improvements, and secure development practices.
- Participate in on-call coverage for significant security events.
Requirements
- Bachelor’s degree with at least 8 years of related experience, or a master’s degree with at least 6 years, or a PhD with at least 3 years, or equivalent experience.
- At least 4 years of auditing source code for security vulnerabilities.
- Demonstrated leadership during significant security events or major incidents.
- Ability to read and comprehend Java and JavaScript code and strong knowledge of common vulnerabilities in both.
- Proficiency scripting in Python and JavaScript for data gathering, processing, and visualization.
- Experience developing proof-of-concept exploits for web application vulnerabilities.
- Ability to communicate complex security risks clearly to technical teams and leadership.
- Experience leading fix implementation and release coordination across engineering, product, and test/release teams.
- Proficiency in deep-dive product security investigations and root-cause analysis.
- Familiarity with SDLC integration, CI/CD pipelines, SaaS threat models, and secure development practices.
- Experience integrating AI into work processes, decision-making, or problem-solving.
- Preferred experience in PSIRT or a similar function for a major software or SaaS platform.
- Preferred expertise in product security incident response, vulnerability research, or application security.
- Preferred experience conducting vulnerability assessments on the ServiceNow platform.
- Preferred experience with AI-specific attack vectors, software supply chain security, SDLC tooling security, cloud infrastructure, and containerized environments.
- Relevant security certifications such as OSWE or equivalent demonstrated expertise are preferred.
Benefits
- Regular employee position with a flexible work persona in the APAC region.
- ServiceNow supports flexible, remote, or office-based work arrangements depending on role and location.
- Participation in on-call coverage is part of the role.
- Equal opportunity and reasonable accommodation support are provided.
Categories
About ServiceNow
ServiceNow builds a cloud platform for enterprise digital workflows, covering IT service management, customer service, HR service delivery, security operations, and operations management, plus tools for custom app development. It sells subscription SaaS to large organizations and public-sector agencies to automate processes and connect data across systems. Founded in 2004 and headquartered in Santa Clara, California, ServiceNow is a public company listed on the NYSE under the ticker NOW.