Staff Security Engineer - Application/Product Security
ServiceNow
Make my CV for this job, freeView job and applyYour CV, rewritten for this role using only your real experience. Sign in with Google and upload your CV. Nothing to install.
Skills named in this job
Read from the description itself, not inferred.
This role on the market
1,266 open application roles across 222 companies are on ApplySarthi right now, most of them in Bengaluru (101), Hyderabad (74), Delhi NCR (62).
- APAC RCSC Application SpecialistRoche
- Staff Software Engineer, Web Application ServicesMozilla
- Sr. Developer - Application Development P 4BGenpact · bengaluru
- Application Security EngineerTeliogroup
- Application Security EngineerPokemoncareers
What application roles keep asking for: Python (13%) — counted across their open postings here.
ServiceNow has 704 open roles listed here.
- Senior Staff Software Engineer - Data Platform - Kubernetes - Distributed Systems - Federal
- Senior Staff Software Engineer - Data Platform - Kubernetes - Distributed Systems - Federal
- APAC Director, Strategic Partnership for C&I
- Sr. Staff Product Designer, Mobile Experience Strategy & Systems
- Staff Software Engineerhyderabad
Counted across 14 company job boards, updated as roles open and close.
Preparing for this interview
Interviews for application roles keep coming back to Python. Practise those questions before you sit with ServiceNow.
Questions you are likely to be asked
- Why do you want to join ServiceNow?
- What is your experience with ServiceNow? Tell me one thing you learned the hard way.
- How would you cut the cloud bill of a system without hurting it?
- How do you keep secrets and access safe in your infrastructure?
- Walk me through how code gets from a commit to production where you work.
Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.
Practise the Staff Security Engineer - Application/Product Security at ServiceNow interview free →ServiceNow seeks a Staff Application Security Engineer to serve as the technical core of our bug bounty program within the Product Security Incident Response Team (PSIRT). This is the senior engineer who owns bug bounty reports from intake through resolution: reproducing and validating the vulnerability, assessing its severity, and seeing it through to a verified fix. The work is deeply technical. Reproducing a vulnerability is only the starting point. From there you read the underlying code, identify root cause, and either propose the fix or design it alongside engineering before confirming it holds. You are also the person researchers deal with directly, which makes clear, credible communication as central to the role as the technical analysis itself. As one of the most senior engineers on the team, you will set the standard for how triage is done and mentor earlier-career engineers. Beyond the bug bounty queue, you will conduct variant hunts, perform original platform security research, lead major product security incidents, and run forensic postmortems when a significant issue reaches production. Key Responsibilities Triage and Resolve Bug Bounty Reports Own incoming reports end-to-end: intake, reproduction, severity scoring, root cause analysis, fix verification, and final disposition. Reproduce and validate reported vulnerabilities, building out incomplete proof-of-concept code where needed. Serve as the technical escalation point for the most complex and highest-severity reports, including multi-step exploit chains and cross-system issues. Perform code review and root cause analysis to identify the underlying defect rather than the reported symptom. Propose remediations, or design them with engineering, and verify the fix resolves the issue. Assign and defend severity ratings using the program's severity framework. Route issues to owning teams, file and track defects, and keep vulnerability records accurate through closure. Own Researcher and Stakeholder Communication Act as ServiceNow's primary technical point of contact for bug bounty researchers across the full lifecycle of a report. Handle severity and validity disputes directly, keeping every exchange clear, timely, respectful, and technically credible. Translate technical findings for internal stakeholders and keep engineering and leadership current on status and risk. Mentor the Team and Raise Triage Standards Provide technical mentorship to earlier-career PSIRT engineers, developing depth in reproduction, code analysis, severity judgment, and communication. Set and maintain the bar for triage quality and strengthen program practices over time. Lead Advanced Security Work Beyond Triage Conduct variant hunts to find related instances of reported vulnerabilities before they are discovered externally. Perform original platform security research to surface issues ahead of external researchers. Lead major product security incidents on the PSIRT side, coordinating response across teams under pressure. Run forensic postmortems after significant incidents to determine how the issue reached production, including how design-level flaws bypassed release processes, and confirm that remediations hold. To be successful in this role, you have: 8+ years of hands-on experience in product security, application security, penetration testing, or vulnerability research. Depth of expertise matters more than years. Expertise in: Common web and application vulnerability classes and exploitation techniques. Vulnerability reproduction, severity assessment, and defensible risk scoring under ambiguity. Coordinated vulnerability disclosure. Code and development fluency: Strong code comprehension in Java, JavaScript, and Python, with the ability to trace root cause in large, unfamiliar codebases and review pull requests. Ability to write code and propose concrete fixes. This is not an application-building role, but you reason fluently in code. Working knowledge of Git, Gradle, Maven, CI/CD pipelines, and secure SDLC. Proficiency with Claude Code or equivalent AI coding assistant for code comprehension and security research. Exceptional written communication. You will represent ServiceNow directly to external researchers, frequently in disagreement, and bridge those researchers and internal engineering. This is a core requirement of the role, not a supporting skill. Work Personas We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here . To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service. Equal Opportunity Employer ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, age, disability, gender identity, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements. Accommodations We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact globaltalentss@servicenow.com for assistance. Export Control Regulations For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities. From Fortune. ©2026 Fortune Media IP Limited. All rights reserved. Used under license.
Match this job to your CV
ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.
Check my match →Similar open roles
- Manager, Product DesignServiceNow · hyderabad
- Director, UX ResearchServiceNow · hyderabad
- Principal Applications Dev EngineerServiceNow · hyderabad
- Staff Data EngineerServiceNow · hyderabad
- Staff Technical Product Manager – AI/LLM expertise + AI Evaluation ScienceServiceNow · hyderabad
- Director - India Reseller ChannelServiceNow · bengaluru
- Senior DevOps EngineerServiceNow · bengaluru
- Staff Data EngineerServiceNow · hyderabad
Need answers during your interview? Try Live Sarthi.
Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.
- Hidden from supported screen sharingThe overlay stays out of supported Windows screen captures.
- Answers start in about 1.5 secondsResponse time varies with your connection and model.
- From your own CVYour projects and your experience, not a generic script.
- 30 minutes freeThen ₹99 for a 2-day pass with unlimited calls — you pay for the days you are interviewing, not a subscription.
A Windows app, from the same team as ApplySarthi.
Listed on smartrecruiters · posted 2026-09-09. ApplySarthi collects openings and links to application pages; the role is advertised by ServiceNow, not by us.