Senior Application Security Engineer based in Mountain View, CA, onsite at ServiceNow, focused on securing AI infrastructure, platform, and features.
Responsibilities
- Lead security design reviews and data-handling assessments to ensure security is integrated at every stage of the product lifecycle.
- Perform targeted penetration testing as part of security reviews for critical features; identify vulnerabilities and propose risk-mitigating strategies; develop and refine testing methodologies to uncover security risks.
- Develop and maintain AppSec processes and CI/CD scanning tools to reliably identify and remediate vulnerabilities.
- Drive ongoing enhancements to the AppSec program to achieve effective security outcomes.
- Collaborate with machine learning, search, product, infrastructure, data, and frontend teams to design secure solutions.
- Empower teams to make informed security decisions.
Requirements
- 5+ years in Application Security, identifying risks, building mitigation plans, and delivering security features.
- 3+ years of hands-on Penetration Testing experience.
- 2+ years using SAST, DAST, dependency scanning, and vulnerability management tools such as Snyk, GitHub Dependabot, Burp Suite.
- 2+ years programming with Python or Go, or equivalent.
- Hands-on experience with cloud-native security best practices across AWS, GCP, and/or Azure.
- Strong knowledge across application and network security, authentication, authorization, identity systems, encryption, AI/LLM security, and secure coding practices.
- BS or higher in computer science or a related field, or equivalent relevant experience.
Technologies
- Python
- Golang
- Snyk
- GitHub Dependabot
- Burp Suite
- AWS
- GCP
- Azure
- SAST
- DAST
Work Personas
We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here. To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.
Equal Opportunity Employer
ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.
Accommodations
We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact globaltalentss@servicenow.com for assistance.
Export Control Regulations
For positions requiring access to controlled technology subject to export control regulations, including the U S Export Administration Regulations EAR, ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.