Jobs and Careers
SE

Senior Application Security Engineer

ServiceNow
United Statesfull_timeVerifiedPosted 10 Feb 2025

About the role

Company Description

It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today — ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500®. Our intelligent cloud-based platform seamlessly connects people, systems, and processes to empower organizations to find smarter, faster, and better ways to work. But this is just the beginning of our journey. Join us as we pursue our purpose to make the world work better for everyone.

Job Description

The ServiceNow Security Organization delivers world-class, innovative security solutions to reduce risk and protect the company and our customers. We enable our customers to migrate their most sensitive data and workloads to the cloud, accelerating our business so that we are the most trusted SaaS provider. We create an environment where our employees are proud to work and can make a positive impact. 

This critical position values integrity, quality, expertise, precision, communication, and efficiency and is looking for security professionals with developing to established security backgrounds and excellent communications.

As a Senior Application Security Engineer on the Global Security Support Center Application Security team, you will be responsible for investigating reported application security vulnerabilities. In this role you will work with customers, external security researchers, and developers to understand & document reported vulnerabilities. Success in this role requires web application security knowledge, analytical debugging skills, strong communication skills, and strong programming language proficiency.

What you get to do in this role:

  • Investigate ServiceNow's products to discover, communicate, and recommend remediation activities for software vulnerabilities.
  • Help customers improve the security posture of their environments, prepare to pentest their environment, and deal with respective regulatory requirements.
  • Review, test, and confirm security findings reported by customers and ensure they fully understand the finding outcomes.
  • Report problems based on confirmed security findings.
  • Contribute to architecting roadmaps for ServiceNow's Customer Penetration Testing & Security Finding program
  • Aide in development efforts by testing the proposed solutions for confirmed vulnerabilities within the ServiceNow platform.

Qualifications

This position requires passing a ServiceNow background screening, USFedPASS (US Federal Personnel Authorization Screening Standards). This includes a credit check, criminal/misdemeanor check and taking a drug test. Any employment is contingent upon passing the screening. Due to Federal requirements, only US citizens, US naturalized citizens or US Permanent Residents, holding a green card, will be considered. 

To be successful in this role you have:

  • 4+ years of working in Cyber Security or adjacent role(s)
  • 3+ years of ServiceNow experience; ServiceNow's "Certified System Administrator" certification preferred
  • In-depth knowledge of common web application vulnerabilities (OWASP Top Ten)
  • Developer level proficiency in at least one language - Python, Java, or JavaScript preferred
  • A bachelor's degree in computer Science or equivalent project/work experience
  • A strong understanding of web (or mobile) application security assessment techniques
  • Excellent communication skills and can articulate complex issues to peers, executives, and customers
  • Strong interpersonal skills
  • The ability to perform and excel with little supervision; self-motivated and driven
  • Excellent collaboration skills; the ability to foster and feed off coworkers
  • Win As a Team attitude; are a great team player
  • A passion for security
  • Offensive Security OSWE and/or OSCP certification(s) a plus

#SecurityJobs 

Not sure if you meet every qualification? We still encourage you to apply! We value inclusivity, welcoming candidates from diverse backgrounds, including non-traditional paths. Unique experiences enrich our team, and the willingness to dream big makes you an exceptional candidate!

Additional Information

Work Personas

We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work. Learn more here.

Equal O

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

ServiceNow

View company profile →