SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
ServiceNow is seeking a Staff Product Security Engineer to join the Product Security Incident Response Team (PSIRT), serving as a senior technical authority responsible for awareness, response, and investigation of post-release vulnerabilities in ServiceNow products and services.
In this role, you will operate as a recognized expert, working independently and collaboratively on the most significant security issues facing the platform. You will lead deep-dive investigations into vulnerabilities requiring complex technical evaluation, coordinate resolution across engineering, product, and release teams, and demonstrate calm, decisive leadership during critical security events.
Key responsibilities include:
**Lead Through Significant Security Events**: Provide technical and organizational leadership during security incidents, partnering with incident commanders, business information security leadership, engineering, and customer-facing teams to maintain clear ownership, prioritization, and handoffs.
**Reduce Exposure Window**: Drive coordinated response across affected releases, balancing risk and remediation feasibility. Leverage understanding of product development cycles and engineering/product partnerships to move fixes through the release pipeline efficiently. Verify fix completeness and guard against incomplete mitigations.
**CVE & Coordinated Disclosure**: Contribute to ServiceNow's CVE disclosure process for incidents you own, including CVE assignment, scoring, advisory content, and publication timing. Conduct technical accuracy reviews of external advisories and joint disclosure content.
**Pursue After-Action Outcomes**: Author root cause analyses and drive lessons learned to closure. Participate in retrospectives following significant security events, translating findings into concrete process and technical improvements. Contribute to tracking product security risk themes and feed incident learnings into secure development practices.
The role requires on-call participation with scheduled coverage: Sunday–Tuesday and Friday–Saturday (specific UTC/IST hours provided). Additional coverage outside stated hours may be required for significant incidents.
This position is ideal for someone who already understands product development cycles and the engineering/product relationships that drive them, and who can use that fluency to lead fixes to completion under incident pressure.
**Requirements:**
- Minimum 8 years of related experience with a Bachelor's degree; or 6 years with a Master's degree; or a PhD with 3 years of experience; or equivalent experience
- Minimum 4 years of auditing source code for security vulnerabilities
- Demonstrated leadership during significant security events or major incidents, with willingness to participate in on-call
- Ability to read and comprehend Java and JavaScript code
- Strong understanding of common Java and JavaScript vulnerabilities
- Proficiency in scripting in both Python and JavaScript for data gathering, processing, and visualization
- Development of proof-of-concept exploits for web application vulnerabilities
- Written and verbal communication of complex security risk to both technical teams and leadership
- Experience leading fix implementation and release coordination across engineering, product, and test/release teams
- Proficiency in deep-dive product security investigations and root-cause analysis spanning design, code, configuration, and operational layers
- Exploit analysis and proof-of-concept development that distinguishes real exploitability from theoretical risk
- Familiarity with SDLC integration, CI/CD pipelines, SaaS threat models, and secure development practices
- Experience leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving
**Preferred Qualifications:**
- Experience in a PSIRT or similar function for a major software or SaaS platform
- Recognized expertise in product security incident response, vulnerability research, or application security within a software or SaaS environment
- Experience conducting vulnerability assessments on the ServiceNow platform
- Experience with emerging threats: AI-specific attack vectors, software supply chain security, and SDLC tooling security
- Experience with cloud infrastructure (AWS, Azure, GCP) and containerized environments
- Relevant security certifications (e.g., OSWE) or demonstrated equivalent expertise