Description Principal Security Engineer (Product Security)
Santa Clara, CA
This position reports to: Sr. Manager, Product Security
ServiceNow is changing the way people work. With a service-orientation toward the activities, tasks and processes that make up day-to-day work life, we help the modern enterprise operate faster and be more scalable than ever before.
Wedisruptive. We work hard but try not to take ourselves too seriously. We are highly adaptable and constantly evolving. We are passionate about our product, and we live for our customers. We have high expectations and a career at ServiceNow means challenging yourself to always be better.
What you get to do in this role:
As a Security Engineer you will be a member of the Product Security Team, helping managed the ServiceNow Product Secure Development lifecycle. You will work with internal development teams to review source code and perform blackbox testing of the ServiceNow platform. In this role you will be responsibile for identifying new platform vulnerabilities, managing vulnerability scanning tools, coordinating vendor testing efforts and creating automation tools to assist in vulnerability management. A key part of this position is understanding and documenting common web application vulnerabilities in addition to vulnerabilities specific to the Service Now platform.
In order to be successful in this role, we need someone who has:
- An analytical mind for problem solving, abstract thought, and offensive security tactics.
- Strong interpersonal skills (written and oral communication).
- Linux/Unix/Darwin experience
- Direct experience coding in one or more of the following languages:
- JavaScript (Preferred)
- Java
- Python (Preferred) or Ruby
- Experiencing performing source code reviews for Security issues
- Advanced knowledge and experience in pentesting:
- Custom web applications
- Complex cloud environments
- Web services (REST & SOAP)
- In-depth experience with common web application vulnerabilities, such as the OWASP Top 10, and business logic flaws.
- Experience with application vulnerability scanning products a plus
- Experience performing Threat Modeling a plus
- Ability to articulate complex issues to executives and customers.
- Ability to pass a practical examination.
- 3+ years experience working in Product Security or as an Application Security Consulting
- 2+ years experience working as a developer and writing/maintaining applications
- Bacheloregree in Computer Science/Engineering or equivalent experience.
We provide competitive compensation, generous benefits and a professional atmosphere. This is a very collaborative and inclusive work environment where individuals strong on aptitude and attitude will have an opportunity to grow their professional careers through working with some of the most advanced technology and talented developers in the business.
ServiceNow is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, age, disability, gender identity, or veteran status. If you are an individual with a disability and require a reasonable accommodation to complete any part of the application process, or are limited in the ability or unable to access or use this online application process and need an alternative method for applying, you may contact us at (408) 501-8550, or
[email protected] for assistance.