EngineerJobs.io
← Back to all jobs

Job Description

Senior Staff Product Security Engineer based in Kirkland, WA (onsite) leads PSIRT investigations and coordinates post-release vulnerability responses while shaping secure development and coordinated disclosure practices.

Responsibilities

  • Offer after-hours incident response coverage for critical product vulnerabilities as they surface.
  • Provide technical and organizational leadership during security events, delivering structured processes and decisive actions under pressure.
  • Collaborate with incident command, business information security leadership, engineering, and customer-facing teams to maintain clear ownership, prioritize workstreams, and manage hand-offs during incidents.
  • Steer coordinated responses across affected releases, balancing risk with feasible remediation.
  • Apply knowledge of product development cycles and engineering partnerships to push fixes through the release pipeline without bureaucratic delays.
  • Validate fix completeness and prevent partial mitigations before deployment.
  • Own the CVE disclosure workflow, including assignment, scoring (CVSS), advisory content, and publication timing.
  • Coordinate with external security partners, vendors, and researchers on disclosures, aligning timelines and messaging.
  • Perform technical accuracy reviews of advisories, researcher analyses, and joint disclosure material prior to publication.
  • Present PSIRT's technical stance during multi-party disclosures and researcher engagements.
  • Draft postmortems and drive closure of lessons learned after security incidents.
  • Participate in retrospectives and translate findings into actionable process and technical improvements.
  • Monitor and support partner teams in tracking security risk themes and portfolio-wide trends.
  • Contribute to SDLC improvements by feeding incident learnings into secure development practices.

Requirements

  • Typically 12+ years of relevant experience with a Bachelor's degree, or 8+ years with a Master's, or 5+ years with a PhD, or equivalent experience.
  • At least 5 years auditing source code for security vulnerabilities.
  • Proven leadership during major security incidents with readiness to participate on call.
  • Ability to read and understand Java and JavaScript code.
  • Solid understanding of common Java and JavaScript vulnerability patterns.
  • Proficiency with Python and JavaScript scripting for data gathering, processing, and visualization.
  • Experience developing proof-of-concept exploits for web application vulnerabilities.
  • Clear written and verbal communication of complex security risk to technical teams and leadership.
  • Experience leading fix implementation and coordinating releases across engineering, product, and QA/release teams.
  • Deep-dive product security investigations and root-cause analysis spanning design, code, configuration, and operational layers.
  • Exploit analysis and PoC development that distinguishes real exploitability from theoretical risk.
  • Familiarity with SDLC integration, CI/CD pipelines, SaaS threat models, and secure development practices.
  • Experience leading a CVE disclosure process, including CVE assignment, CVSS scoring, and advisory publication.

Technologies

  • Java
  • JavaScript
  • Python
  • AWS
  • Azure
  • GCP
  • Containerization

Compensation

  • Base pay range: USD 201,300 - 352,300 annually

Benefits

  • Health plans
  • Flexible spending accounts
  • 401(k) Plan with company match
  • ESPP
  • Matching donations
  • Flexible time away plan
  • Family leave programs
  • Equity (when applicable)

Work Personas

  • ServiceNow supports a flexible work model with defined work personas (flexible, remote, or in-office) based on role and location. Eligibility may depend on the distance to the nearest ServiceNow office.

Equal Opportunity Employer

ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, age, disability, gender identity, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.

Accommodations

We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact [email protected] for assistance.

Export Control Regulations

For positions requiring access to controlled technology subject to export control regulations, including EAR, ServiceNow may need to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.

Similar Jobs