Product Security Engineer
Description
Job Title: Product Security Engineer
Location: Chicago, IL (1201 West)
Company
Work matters. It’s where we spend a third of our lives. And the workplace of the future is going to be a great place. We’re dedicated to bringing that to life for people everywhere. That’s why we put people at the heart of everything we do.
People matter. Our people have a passion for learning, building, and innovating. Whether you’re an engineer, a sales professional, a finance professional, or anything in-between, our roles aim to provide each person with meaningful impact and plenty of space to grow.
Team
Product Security is working at Shifting Left, allowing engineering teams and the company to be proactive with simplified integrated security testing. This paradigm shift benefits developers and ServiceNow by codifying security activities at scale into their build pipelines ensuring tool chains are easily automated with continuous monitoring and feedback.
Role
As a security engineer on the ServiceNow Product Security Team, you will be responsible in identifying security vulnerabilities within customer facing software products. You will work with internal development teams to review source code and audit custom functionality built on top of the ServiceNow platform. You will have the opportunity to develop tooling, plan security projects, and be a security advocate. A key part of this position is to effectively communicate issues to the application owners, provide meaningful remediation recommendations, and validate that they have been resolved.
What you get to do in this role:
- Perform software auditing services to internal teams to discover, communicate, and recommend remediation activities for software vulnerabilities.
- Participate in the Bug Bounty and Response Disclosure Programs
- Research security topics which are a risk to ServiceNow
- Research and implement automated code security quality gates in a CI/CD lifecycle
- Work with third party vendors on security testing
In order to be successful in this role, we need someone who has:
- 2+ years of experience of web application security auditing including code review
- Experience in threat modeling and threat modeling tools a plus
- In-depth knowledge of common web application vulnerabilities (OWASP Top Ten)
- Strong understanding of web and mobile application security assessment techniques
- Some programming experience, preferable in Python, Java, or JavaScript
- Knowledge of static and dynamic security analysis tools a plus
- Ability to communicate technical concepts to both non-technical business users as well as technical stakeholders.
- A passion for security
ServiceNow is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, age, disability, gender identity, or veteran status. If you are an individual with a disability and require a reasonable accommodation to complete any part of the application process, or are limited in the ability or unable to access or use this online application process and need an alternative method for applying, you may contact us at (408) 501-8550, or [email protected] for assistance.