Sr. Product Security Engineer (Testing)
Job Title:
Sr. Product Security Engineer (Testing)
Company
Work matters. It’s where we spend a third of our lives. And the workplace of the future is going to be a great place. We’re dedicated to bringing that to life for people everywhere. That’s why we put people at the heart of everything we do.
People matter. Our people have a passion for learning, building, and innovating. Whether you’re an engineer, a sales professional, a finance professional, or anything in-between, our roles aim to provide each person with meaningful impact and plenty of space to grow.
Role
As an engineer on the ServiceNow Product Security Team, you will be responsible in identifying security vulnerabilities within customer-facing software products. You will work with internal development teams to review source code and audit custom functionality built on top of the ServiceNow platform. A key part of this position is to effectively communicate issues to the application owners, provide meaningful remediation recommendations, and validate that they have been resolved.
What you get to do in this role:
- Provide software auditing services to internal teams to discover, communicate, and recommend remediation activities for software vulnerabilities.
- Evaluate architecture design, identify threats, and document risk.
- Work with third-party vendors on security testing.
In order to be successful in this role, we need someone who has:
- 6+ years prior experience securing enterprise products.
- 2-5 years of experience of web application security auditing including code review.
- 1+ years of experience in threat modeling and threat modeling tools.
- In-depth knowledge of common web application vulnerabilities (OWASP Top Ten)
- Strong understanding of web and mobile application security assessment techniques.
- Developer level proficiency in Java and JavaScript.
- Knowledge of static and dynamic security analysis tools.
- Knowledge of the Security Development Lifecycle (SDLC).
- Ability to deliver technical reports and communicate technical concepts to both non-technical business users as well as technical stakeholders.
- A passion for security.
EEOE Statement Section
ServiceNow’s EEOE statement is automatically added to each U.S. based job description.
ServiceNow is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, age, disability, gender identity, or veteran status. If you are an individual with a disability and require a reasonable accommodation to complete any part of the application process, or are limited in the ability or unable to access or use this online application process and need an alternative method for applying, you may contact us at [email protected] for assistance.