
Staff Product Security Engineer, PSIRT
ServiceNow12 hours ago
Hyderābād, IndiaStaff+
Responsibilities
- Lead technical and organizational response during significant product security events.
- Coordinate vulnerability remediation across affected releases and engineering, product, test, and release teams.
- Verify fix completeness and prevent incomplete mitigations from reaching release.
- Support CVE assignment, scoring, advisory preparation, and coordinated disclosure publication.
- Review external advisories, researcher write-ups, and joint disclosure content for technical accuracy.
- Develop proof-of-concept exploits and distinguish real exploitability from theoretical risk.
- Author root cause analyses, lead retrospectives, and drive lessons learned to completion.
- Contribute incident-driven improvements to SDLC practices, security processes, and product security risk tracking.
- Provide scheduled coverage and participate in on-call response, including additional coverage during significant incidents.
Requirements
- At least 8 years of related experience with a bachelor's degree, 6 years with a master's degree, 3 years with a PhD, or equivalent experience.
- At least 4 years of auditing source code for security vulnerabilities.
- Experience leading significant security events or major incidents and willingness to participate in on-call coverage.
- Ability to read and understand Java and JavaScript code and common vulnerabilities in both languages.
- Proficiency scripting with Python and JavaScript for data gathering, processing, and visualization.
- Experience developing proof-of-concept exploits for web application vulnerabilities.
- Ability to communicate complex security risks clearly to technical teams and leadership.
- Experience leading fix implementation and release coordination across engineering, product, and test/release teams.
- Deep-dive product security investigation and root-cause analysis experience across design, code, configuration, and operational layers.
- Familiarity with SDLC integration, CI/CD pipelines, SaaS threat models, and secure development practices.
- Experience integrating or critically evaluating AI in work processes, decision-making, or problem-solving.
- Preferred: PSIRT or comparable experience for a major software or SaaS platform.
- Preferred: recognized expertise in product security incident response, vulnerability research, or application security.
- Preferred: vulnerability assessment experience on the ServiceNow platform.
- Preferred: experience with AI-specific attack vectors, software supply chain security, and SDLC tooling security.
- Preferred: experience with AWS, Azure, GCP, and containerized environments.
- Preferred: relevant security certification such as OSWE or equivalent expertise.
Benefits
- Regular employee position in the APAC region.
- Flexible work persona with distributed-work flexibility; eligibility depends on assigned work location.
- Scheduled coverage includes Sunday, Monday, Tuesday, Friday, and Saturday shifts, with additional coverage potentially required during significant incidents.
Categories
About ServiceNow
ServiceNow builds a cloud platform for enterprise digital workflows, covering IT service management, customer service, HR service delivery, security operations, and operations management, plus tools for custom app development. It sells subscription SaaS to large organizations and public-sector agencies to automate processes and connect data across systems. Founded in 2004 and headquartered in Santa Clara, California, ServiceNow is a public company listed on the NYSE under the ticker NOW.