Skip to content

Product Security Engineer
Company | ServiceNow |
---|
Location | Santa Clara, CA, USA |
---|
Salary | $123500 – $191500 |
---|
Type | Full-Time |
---|
Degrees | Bachelor’s, Master’s |
---|
Experience Level | Mid Level |
---|
Requirements
- 2+ years of application or product security experience
- Bachelor’s or Master’s degree in Computer Science, Engineering, Information Security, or equivalent work experience
- Experience thinking critically about or integrating AI into workflows, tooling, or decision-making (e.g., AI-powered tools, automated insights, or GenAI platforms)
- Demonstrated hands-on experience with identifying and resolving OWASP Top 10 vulnerabilities
- Demonstrated hands-on experience with threat modeling in Agile environments
- Demonstrated hands-on experience with Security Verification Standards
- Demonstrated hands-on experience with authentication and authorization schemes
- Experience with automation using scripting languages (e.g., Python, JavaScript)
- Experience with data structures, algorithms, object-oriented design, design patterns, with security consideration
- Strong grasp of web and mobile application security techniques, threat modeling, and secure coding practices
- Understanding of vulnerabilities and risk in GenAI/AgenticAI platforms
- Ability to evaluate and triage results from SAST and DAST tools, perform risk assessments, and guide remediation efforts
- Strong analytical skills and ability to communicate with both technical and non-technical stakeholders
- Proactive mindset toward learning and adopting emerging technologies, tools, and frameworks to drive innovation.
Responsibilities
- Perform and support security assessments across a wide range of modern product features
- Conduct code reviews in a mixed-language codebase
- Integrate security into the software development lifecycle (SDLC) at ServiceNow
- Partner with developers and architects to design, implement, and enhance secure application solutions
- Apply expertise in authentication, authorization, secure mobile development, cryptography, and secure-by-design practices
- Champion security awareness and educate teams on secure development behaviors
- Define and implement application security best practices, standards, and guidelines
- Contribute to strategic and high-impact BSIMM activities across the company
- Support compliance efforts including audits, regulatory reviews, and security assessments
- Build and improve internal tools to make secure development easier and prevent insecure code from shipping
- Maintain and evolve automation test frameworks to improve security testing reliability and efficiency
- Collaborate with developers to design and automate targeted security testing strategies
- Work closely with engineering teams to identify, troubleshoot, and resolve security issues in development and test environments.
Preferred Qualifications
No preferred qualifications provided.