🎁 Before you apply, rehearse this interview. Create your free WorkMundi account and get an Interview Training on HelpsYouSpeak — no cost, no card. I want my training →
Note: The job is a remote job and is open to candidates in USA. ServiceNow is a leading provider of innovative security solutions, aimed at reducing risk and protecting both the company and its customers. They are seeking a Senior Staff Product Security Engineer to serve as a technical authority within the Product Security Incident Response Team (PSIRT), leading investigations and coordinating responses to significant security vulnerabilities.ResponsibilitiesProvide additional response coverage outside of normal working hours for significant product vulnerabilities as they emergeDemonstrate technical and organizational leadership during these eventsbringing structure and clear decision-making under pressurePartner with incident commanders, business information security leadership, engineering, and customer-facing teams to maintain clear ownership, workstream prioritization, and hand-offs during these eventsDrive coordinated response across affected releases, balancing risk and remediation feasibilityLeverage an understanding of product development cycles and engineering/product partnerships to move fixes through the release pipeline without stalling on organizational boundariesVerify fix completeness and guard against incomplete mitigations before releaseLead ServiceNow's CVE disclosure processowning CVE assignment, scoring, advisory content, and publication timingCollaborate with external security partners, vendors, and researchers on coordinated disclosures, aligning timelines and messaging across partiesConduct technical accuracy reviews of external advisories, researcher write-ups, and joint disclosure content to ensure correctness before publicationRepresent PSIRT's technical position in multi-party coordinated disclosures and researcher engagementsAuthor postmortems and drive lessons learned to closure following product security incidentsParticipate in retrospectives following significant product security events, translating findings into concrete process and technical improvementsContribute to partner teams tracking product security risk themes and trends across the portfolioContribute to SDLC improvement areas, feeding incident learnings upstream into secure development practicesSkillsMinimum 12 years of related experience with a Bachelor's degree; or 8 years with a Master's degree; or a PhD with 5 years of experience; or equivalent experienceMinimum 5 years of auditing source code for security vulnerabilitiesDemonstrated leadership during significant security events or major incidents, with willingness to participate in on-callAbility to read and comprehend Java and JavaScript codeStrong understanding of common Java and JavaScript vulnerabilitiesProficiency in scripting in both Python and JavaScript for data gathering, processing, and visualizationDevelopment of proof-of-concept exploits for web application vulnerabilitiesWritten and verbal communication of complex security risk clearly to both technical teams and leadershipExperience with leading fix implementation and release coordination across engineering, product, and test/release teamsProficiency in deep-dive product security investigations and root-cause analysis spanning design, code, configuration, and operational layersExploit analysis and proof-of-concept development that distinguishes real exploitability from theoretical riskFamiliarity with SDLC integration, CI/CD pipelines, SaaS threat models, and secure development practicesExperience leading a CVE disclosure process, including CVE assignment, scoring (CVSS), and advisory publicationExperience in a PSIRT or similar function for a major software or SaaS platformRecognized expertise in product security incident response, vulnerability research, or application security within a software or SaaS environmentExperience conducting vulnerability assessments on the ServiceNow platformExperience with emerging threats: AI-specific attack vectors, software supply chain security, and SDLC tooling securityExperience with cloud infrastructure (AWS, Azure, GCP) and containerized environmentsRelevant security certifications (e.g., OSWE) or demonstrated equivalent expertiseBenefitsEquity (when applicable)Variable/incentive compensationHealth plansFlexible spending accountsA 401(k) Plan with company matchESPPMatching donationsA flexible time away planFamily leave programsCompany OverviewServiceNow is an AI platform that delivers IT operations, field service management and app engine solutions. It was founded in 2004, and is headquartered in Santa Clara, California, USA, with a workforce of 10001+ employees. Its website is http://www.servicenow.com.Company H1B SponsorshipServiceNow has a track record of offering H1B sponsorships, with 308 in 2026, 910 in 2025, 876 in 2024, 807 in 2023, 840 in 2022, 447 in 2021, 439 in 2020. Please note that this does not guarantee sponsorship for this specific role. Apply To this Job .
Here's how to pick the right one and stand out in your application.
144.883Jobs
31.687IN
81%EN
That number is real. WorkMundi's database shows 144,883 open engineer roles across the world. India has the most with 31,687 jobs, followed by the United States with 30,084. If you just finished reading one job ad and felt paralyzed by choice, you're not alone—but this scale is actually an advantage. It means you can afford to be selective.
Start by geography and language. The majority of engineer ads—117,837 of them—have the job posting text written in English. Use that as one filter, but remember: the ad text language tells you nothing about whether the role actually requires you to speak English day-to-day. Read the job description carefully. Then check which countries have the volume you're targeting. Singapore, Poland, and Australia round out the top five after India and the US.
Next, learn who's hiring. Accenture has posted 2,801 engineer roles. andurilindustries, speechify, and jobgether are also actively recruiting. If you're applying to one of these names, research their hiring patterns and interview style before you apply. That homework pays off.
When you interview, expect the question every engineer hears: 'Tell me about a time you had to debug a problem that wasn't in your job description.' Have a specific story ready—not a general one. Name the tools, the deadline pressure, and what you learned. Hiring managers listen for whether you see problem-solving as part of the role itself, not a favour.