Senior Staff Product Security Engineer (AppSec) at ServiceNow
Work matters. It’s where we spend a third of our lives. And the workplace of the future is going to be a great place. We’re dedicated to bringing that to life for people everywhere. That’s why we put people at the heart of everything we do.
People matter. Our people have a passion for learning, building, and innovating. Whether you’re an engineer, a sales professional, a finance professional, or anything in-between, our roles aim to provide each person with meaningful impact and plenty of space to grow.
Product Security is working at Shifting Left, allowing engineering teams and the company to be proactive with simplified integrated security testing. This paradigm shift benefits developers and ServiceNow by codifying security activities at scale into their build pipelines ensuring toolchains are easily automated with continuous monitoring and feedback.
As a security engineer on the ServiceNow Product Security Team, you will be responsible in identifying security vulnerabilities within customer-facing software products. You will work with internal development teams to review source code and audit custom functionality built on top of the ServiceNow platform. You will have the opportunity to develop tooling, plan security projects, and be a security advocate. A key part of this position is to effectively communicate issues to the application owners, provide meaningful remediation recommendations, and validate that they have been resolved.
What you get to do in this role:
- Perform software auditing services to internal teams to discover, communicate, and recommend remediation activities for software vulnerabilities.
- Provide architecture design input, evaluate threats and document risk
- Proactively research new attack vectors that may affect ServiceNow.
- Research and implement automated code security quality gates in a CI/CD lifecycle
- Research security topics which are a risk to ServiceNow
- Be an advocate for security for development teams and participate in a security champions program
- Work with third-party vendors on security testing
In order to be successful in this role, we need someone who has:
- 10+ years prior experience securing enterprise products.
- 2-5 years of experience of web application security auditing including code review
- 1+ years of experience in threat modeling and threat modeling tools
- In-depth knowledge of common web application vulnerabilities (OWASP Top Ten)
- Strong understanding of web and mobile application security assessment techniques
- Knowledge of static and dynamic security analysis tools
- Knowledge of the Security Development Lifecycle (SDLC)
- Ability to deliver technical reports and communicate technical concepts to both non-technical business users as well as technical stakeholders.
- A passion for security
ServiceNow is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, age, disability, gender identity, or veteran status. If you are an individual with a disability and require a reasonable accommodation to complete any part of the application process, or are limited in the ability or unable to access or use this online application process and need an alternative method for applying, you may contact us at (408) 501-8550, or [email protected] for assistance.