SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Product Security Engineer, PSIRT

ServiceNow - Hyderabad, Telangana, India - In-office - posted 2026-09-15

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

ServiceNow is seeking a Staff-level Product Security Engineer to join the Product Security Incident Response Team (PSIRT). This is a senior technical authority role for a recognized expert who can operate independently and lead the organization's response to post-release vulnerabilities in ServiceNow products and services. You will lead deep-dive investigations into the most significant security issues facing the platform, coordinate resolution across engineering, product, and release teams, and demonstrate calm, decisive leadership during critical security events. This role requires fluency in product development cycles and the ability to leverage engineering and product relationships to drive fixes to completion under incident pressure. Key responsibilities include: - Leading through significant security events with technical and organizational leadership, partnering with incident commanders, business information security leadership, engineering, and customer-facing teams - Reducing exposure windows by driving coordinated response across affected releases, balancing risk and remediation feasibility - Managing CVE and coordinated disclosure processes, including CVE assignment, scoring, advisory content, and publication timing - Conducting technical accuracy reviews of external advisories and researcher write-ups - Authoring root cause analyses and driving lessons learned to closure following product security incidents - Participating in retrospectives and translating findings into concrete process and technical improvements - Contributing to SDLC improvement areas and feeding incident learnings upstream into secure development practices Requirements: - Minimum 8 years of related experience with a Bachelor's degree; or 6 years with a Master's degree; or a PhD with 3 years of experience; or equivalent experience - Minimum 4 years of auditing source code for security vulnerabilities - Demonstrated leadership during significant security events or major incidents, with willingness to participate in on-call - Ability to read and comprehend Java and JavaScript code - Strong understanding of common Java and JavaScript vulnerabilities - Proficiency in scripting in both Python and JavaScript for data gathering, processing, and visualization - Development of proof-of-concept exploits for web application vulnerabilities - Written and verbal communication of complex security risk to both technical teams and leadership - Experience with leading fix implementation and release coordination across engineering, product, and test/release teams - Proficiency in deep-dive product security investigations and root-cause analysis spanning design, code, configuration, and operational layers - Exploit analysis and proof-of-concept development that distinguishes real exploitability from theoretical risk - Familiarity with SDLC integration, CI/CD pipelines, SaaS threat models, and secure development practices - Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving Preferred Qualifications: - Experience in a PSIRT or similar function for a major software or SaaS platform - Recognized expertise in product security incident response, vulnerability research, or application security within a software or SaaS environment - Experience conducting vulnerability assessments on the ServiceNow platform - Experience with emerging threats: AI-specific attack vectors, software supply chain security, and SDLC tooling security - Experience with cloud infrastructure (AWS, Azure, GCP) and containerized environments - Relevant security certifications (e.g., OSWE) or demonstrated equivalent expertise

Similar roles