SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Product Security Engineer, PSIRT

ServiceNow - Hyderabad, Telangana, India - Hybrid - posted 2026-09-15

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

ServiceNow is seeking a Staff-level Product Security Engineer to join the Product Security Incident Response Team (PSIRT). This is a senior technical authority role for a recognized expert who can operate independently and lead the most significant security issues facing the ServiceNow platform. In this role, you will lead deep-dive investigations into post-release vulnerabilities, coordinate resolution across engineering, product, and release teams, and demonstrate decisive leadership during significant security events. You will help shape how ServiceNow responds to product security vulnerabilities at scale and drive technical rigor across the entire response capability. Key responsibilities include: - Leading through significant security events, bringing technical and organizational leadership under pressure - Partnering with incident commanders, business information security leadership, engineering, and customer-facing teams to maintain clear ownership and workstream prioritization - Driving coordinated response across affected releases, balancing risk and remediation feasibility - Leveraging understanding of product development cycles and engineering/product partnerships to move fixes through the release pipeline - Verifying fix completeness and guarding against incomplete mitigations before release - Contributing to ServiceNow's CVE disclosure process, including CVE assignment, scoring, advisory content, and publication timing - Conducting technical accuracy reviews of external advisories and joint disclosure content - Authoring root cause analyses and driving lessons learned to closure following product security incidents - Participating in retrospectives and translating findings into concrete process and technical improvements - Contributing to product security risk theme tracking and SDLC improvement initiatives This role requires someone who already understands product development cycles and the engineering/product relationships that drive them, and who can use that fluency to lead fixes to completion under incident pressure. REQUIREMENTS: - Minimum 8 years of related experience with a Bachelor's degree; or 6 years with a Master's degree; or a PhD with 3 years of experience; or equivalent experience - Minimum 4 years of auditing source code for security vulnerabilities - Demonstrated leadership during significant security events or major incidents, with willingness to participate in on-call - Ability to read and comprehend Java and JavaScript code - Strong understanding of common Java and JavaScript vulnerabilities - Proficiency in scripting in both Python and JavaScript for data gathering, processing, and visualization - Development of proof-of-concept exploits for web application vulnerabilities - Written and verbal communication of complex security risk clearly to both technical teams and leadership - Experience with leading fix implementation and release coordination across engineering, product, and test/release teams - Proficiency in deep-dive product security investigations and root-cause analysis spanning design, code, configuration, and operational layers - Exploit analysis and proof-of-concept development that distinguishes real exploitability from theoretical risk - Familiarity with SDLC integration, CI/CD pipelines, SaaS threat models, and secure development practices - Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving PREFERRED QUALIFICATIONS: - Experience in a PSIRT or similar function for a major software or SaaS platform - Recognized expertise in product security incident response, vulnerability research, or application security within a software or SaaS environment - Experience conducting vulnerability assessments on the ServiceNow platform - Experience with emerging threats: AI-specific attack vectors, software supply chain security, and SDLC tooling security - Experience with cloud infrastructure (AWS, Azure, GCP) and containerized environments - Relevant security certifications (e.g., OSWE) or demonstrated equivalent expertise

Similar roles