SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Security Engineer - Application/Product Security

ServiceNow - Petah Tikva, Israel - Hybrid - posted 2026-09-09

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

ServiceNow is seeking a Staff Application Security Engineer to lead the technical operations of its bug bounty program within the Product Security Incident Response Team (PSIRT). This is a deeply technical role where you own vulnerability reports end-to-end: reproducing and validating issues, assessing severity, performing root cause analysis, and verifying fixes through to resolution. You will be the senior technical authority on the team, setting standards for triage quality and mentoring earlier-career engineers. Beyond bug bounty intake, you will conduct variant hunts to identify related vulnerabilities before external discovery, perform original platform security research, lead major product security incidents, and run forensic postmortems on significant issues that reach production. Key responsibilities include triaging and resolving bug bounty reports with full ownership from intake through closure; reproducing vulnerabilities and building proof-of-concept code where needed; performing code review and root cause analysis in large, unfamiliar codebases; proposing and designing remediations with engineering teams; assigning and defending severity ratings; and serving as ServiceNow's primary technical contact with external security researchers throughout the vulnerability lifecycle. You will also mentor the PSIRT team, raise triage standards, handle severity disputes with researchers, translate technical findings for internal stakeholders, and lead complex security investigations under pressure. Required qualifications include 8+ years of hands-on experience in product security, application security, penetration testing, or vulnerability research. You must have deep expertise in common web and application vulnerability classes, exploitation techniques, vulnerability reproduction, severity assessment, and coordinated vulnerability disclosure. Strong code comprehension in Java, JavaScript, and Python is essential, with the ability to trace root cause in large codebases and review pull requests. You should be able to write code and propose concrete fixes, and have working knowledge of Git, Gradle, Maven, CI/CD pipelines, and secure SDLC practices. Proficiency with Claude Code or equivalent AI coding assistants for code comprehension and security research is required. Exceptional written communication is a core requirement—you will represent ServiceNow directly to external researchers, often in disagreement, and bridge those researchers with internal engineering teams.

Similar roles