Description
ServiceNow is hiring a Senior Application Security Engineer to serve as the technical lead for its bug bounty program within the Product Security Incident Response Team. The role owns vulnerability reports from intake through verified remediation, including reproduction, exploit validation, code review, root-cause analysis, severity scoring, fix verification, researcher communication, and issue closure. It also includes mentoring PSIRT engineers, conducting variant hunts and original platform security research, leading major product security incidents, and running forensic postmortems. Candidates need 8+ years of hands-on product or application security, penetration testing, or vulnerability research experience; strong Java, JavaScript, and Python code fluency; knowledge of Git, Gradle, Maven, CI/CD, secure SDLC, AI coding assistants, web vulnerabilities, coordinated disclosure, and exceptional written communication.
