Senior Staff Product Security Engineer
Job Description
Senior Staff Product Security Engineer at ServiceNow in Kirkland, WA, onsite, responsible for leading PSIRT investigations and coordinating post-release vulnerability responses while shaping secure development and coordinated disclosure practices.
Responsibilities
- Provide extended response coverage outside standard hours for significant product vulnerabilities as they surface.
- Demonstrate technical and organizational leadership during incidents, establishing structure and decisive action under pressure.
- Collaborate with incident commanders, business information security leadership, engineering, and customer-facing teams to maintain clear ownership, prioritize workstreams, and manage hand-offs during events.
- Drive a coordinated response across affected releases while balancing risk and remediation feasibility.
- Leverage knowledge of product development cycles and engineering partnerships to move fixes through the release pipeline without stalling across teams.
- Verify fix completeness and guard against incomplete mitigations prior to release.
- Lead ServiceNow's CVE disclosure process, including CVE assignment, scoring, advisory content, and publication timing.
- Collaborate with external security partners, vendors, and researchers on coordinated disclosures, aligning timelines and messaging.
- Conduct technical accuracy reviews of external advisories, researcher write-ups, and joint disclosure content before publication.
- Represent PSIRT's technical position in multi-party disclosures and researcher engagements.
- Author postmortems and drive closure on lessons learned following product security incidents.
- Participate in retrospectives after significant security events, translating findings into concrete process and technical improvements.
- Contribute to partner teams by tracking product security risk themes and portfolio-wide trends.
- Support SDLC improvement efforts by feeding incident learnings back into secure development practices.
Requirements
- Minimum 12 years of related experience with a Bachelor's degree; 8 years with a Master's; 5 years with a PhD; or equivalent experience.
- At least 5 years auditing source code for security vulnerabilities.
- Proven leadership during significant security events or major incidents, with willingness to participate in on-call rotations.
- Ability to read and understand Java and JavaScript code.
- Strong understanding of common Java and JavaScript vulnerabilities.
- Proficiency in Python and JavaScript scripting for data gathering, processing, and visualization.
- Experience developing proof-of-concept exploits for web application vulnerabilities.
- Clear written and verbal communication of complex security risk to technical teams and leadership.
- Experience leading fix implementation and release coordination across engineering, product, and test/release teams.
- Deep-dive product security investigations and root-cause analysis spanning design, code, configuration, and operational layers.
- Exploit analysis and PoC development that distinguishes real exploitability from theoretical risk.
- Familiarity with SDLC integration, CI/CD pipelines, SaaS threat models, and secure development practices.
- Experience leading a CVE disclosure process, including CVE assignment, CVSS scoring, and advisory publication.
Technologies
- Java
- JavaScript
- Python
- AWS
- Azure
- GCP
- Containerization
Compensation
- Base salary range: USD 201,300 to 352,300 per year
Benefits
- Health plans
- Flexible spending accounts
- 401(k) Plan with company match
- Employee stock purchase plan (ESPP)
- Matching donations
- Flexible time away plan
- Family leave programs
- Equity (when applicable)
Work Personas
We operate in a distributed world with flexibility and trust. Work personas, whether flexible, remote, or in-office, are assigned based on the role and location. Eligibility for a work persona may involve confirming the distance between your primary residence and the nearest ServiceNow office using a third-party service.
Equal Opportunity Employer
ServiceNow is an equal opportunity employer. All qualified applicants receive consideration without regard to race, color, religion, sex, sexual orientation, national origin, age, disability, gender identity, veteran status, or any other protected status. Applicants with arrest or conviction records will be considered in line with legal requirements.
Accommodations
We aim to provide an accessible and inclusive experience. If you require a reasonable accommodation to complete any part of the application process or need an alternative method to apply, contact [email protected] for assistance.
Export Control Regulations
Positions requiring access to controlled technology may be subject to export control regulations. ServiceNow may need to obtain export control approvals, and employment is contingent upon securing any necessary licenses or approvals.