ServiceNow

Staff Product Security Engineer, PSIRT

ServiceNow
Apply
7 hours ago
Hyderābād, IndiaStaff+

Responsibilities

  • Lead technical and organizational response during significant product security incidents.
  • Coordinate vulnerability remediation across affected releases, engineering, product, test, release, and customer-facing teams.
  • Verify fix completeness and prevent incomplete mitigations before release.
  • Manage CVE assignment, scoring, advisory content, and coordinated disclosure activities.
  • Review external advisories, researcher write-ups, and joint disclosure content for technical accuracy.
  • Conduct exploit analysis, proof-of-concept development, deep-dive investigations, and root-cause analyses.
  • Author incident postmortems and drive lessons learned, process improvements, and secure development improvements to completion.
  • Track product security risk themes and trends across the portfolio.

Requirements

  • At least 8 years of related experience with a bachelor’s degree, 6 years with a master’s degree, 3 years with a PhD, or equivalent experience.
  • At least 4 years of auditing source code for security vulnerabilities.
  • Demonstrated leadership during significant security events or major incidents and willingness to participate in on-call coverage.
  • Ability to read and understand Java and JavaScript code and common vulnerabilities in both languages.
  • Proficiency scripting in Python and JavaScript for data gathering, processing, and visualization.
  • Experience developing proof-of-concept exploits for web application vulnerabilities.
  • Ability to communicate complex security risks clearly to technical teams and leadership.
  • Experience leading fix implementation and release coordination across engineering, product, and test/release teams.
  • Proficiency conducting product security investigations and root-cause analysis across design, code, configuration, and operational layers.
  • Familiarity with SDLC integration, CI/CD pipelines, SaaS threat models, and secure development practices.
  • Preferred experience in PSIRT or a similar function for a major software or SaaS platform.
  • Preferred expertise in product security incident response, vulnerability research, or application security.
  • Preferred experience conducting vulnerability assessments on the ServiceNow platform.
  • Preferred experience with AI-specific attack vectors, software supply chain security, SDLC tooling security, cloud infrastructure, and containerized environments.
  • Relevant security certifications such as OSWE or equivalent demonstrated expertise are preferred.

Benefits

  • Flexible work persona; the role is listed as flexible in the APAC region.
  • Regular employee position.
  • Equal opportunity and accessible application accommodations are provided.
ServiceNow

About ServiceNow

10,000+ employees

ServiceNow builds a cloud platform for enterprise digital workflows, covering IT service management, customer service, HR service delivery, security operations, and operations management, plus tools for custom app development. It sells subscription SaaS to large organizations and public-sector agencies to automate processes and connect data across systems. Founded in 2004 and headquartered in Santa Clara, California, ServiceNow is a public company listed on the NYSE under the ticker NOW.

Contact me