Startups

Staff Security Engineer - Application/Product Security

ServiceNow · Petah Tikva, IL · On-site

← All jobs
About ServiceNow

It all started when engineer Fred Luddy wrote code that automated a tedious task for his coworker, Phyllis. She cried tears of joy. Backed by Greylock and Sequoia.

About the role

8+ years of hands-on experience in product security, application security, penetration testing, or vulnerability research. Depth of expertise matters more than years.

What they're looking for

  • 8+ years of hands-on experience in product security, application security, penetration testing, or vulnerability research. Depth of expertise matters more than years
More about this role

ServiceNow seeks a Staff Application Security Engineer to serve as the technical core of our bug bounty program within the Product Security Incident Response Team (PSIRT). This is the senior engineer who owns bug bounty reports from intake through resolution: reproducing and validating the vulnerability, assessing its severity, and seeing it through to a verified fix.

The work is deeply technical. Reproducing a vulnerability is only the starting point. From there you read the underlying code, identify root cause, and either propose the fix or design it alongside engineering before confirming it holds. You are also the person researchers deal with directly, which makes clear, credible communication as central to the role as the technical analysis itself.

As one of the most senior engineers on the team, you will set the standard for how triage is done and mentor earlier-career engineers. Beyond the bug bounty queue, you will conduct variant hunts, perform original platform security research, lead major product security incidents, and run forensic postmortems when a significant issue reaches production.

Key Responsibilities

Triage and Resolve Bug Bounty Reports

  • Own incoming reports...

Read the full posting on ServiceNow's site ↗

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.