Description
ServiceNow is hiring a Staff Application Security Engineer to serve as the technical core of its bug bounty program within the Product Security Incident Response Team. The role owns vulnerability reports from intake through resolution, including reproduction, severity assessment, root-cause analysis, remediation design, and fix verification. It also involves direct communication with researchers, mentoring earlier-career engineers, conducting variant hunts and original platform security research, leading major product security incidents, and running forensic postmortems. The position requires at least eight years of hands-on experience in product security, application security, penetration testing, or vulnerability research, along with strong Java, JavaScript, and Python code fluency, vulnerability research expertise, and exceptional written communication.
