ServiceNow Security Organization (SSO) needs to deliver world-class, innovative security solutions to reduce risk and protect the company and its customers. The Security Research / Offensive Security team specifically needs to perform red-team like engagements, produce investigative reports, and provide guidance on security controls, best practices, and product enhancement to address operational security risks and product insecurities across ServiceNow's cloud environment.
Requirements
- Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving. This may include using AI-powered tools, automating workflows, analyzing AI-driven insights, or exploring AI’s potential impact on the function or industry.
- Background in software security auditing, computer security and the statistical methods
- 15+ years of experience performing software security auditing including code review, reverse engineering, thick app analysis, and black-box web application testing or related experience and education
- Developer level proficiency in Python, Java, and JavaScript, including modern client-side JavaScript frameworks
- Experience writing static code analysis rules a plus
- Experience with Python data science and machine learning frameworks a plus
- Network and system security engineering skills a plus
Responsibilities
- Participate in offensive security engagements including external adversarial emulation.
- Perform security audits to discover, communicate, and recommend remediation activities for vulnerabilities
- Work with engineering teams on remediation
- Deliver offensive security engagements against ServiceNow public facing and internal products.
- Responsible for security auditing of the ServiceNow product stack and researching nuance of securing SaaS platforms.
- Provide guidance on primary security controls, best practices, and product enhancement.
- Exploration techniques focus on problems broadly, measuring industry trends and product insecurity across ServiceNow’s cloud environment.
Other
- This role requires a minimum of 2 days per week in the San Diego, CA or the Santa Clara, CA ServiceNow Offices
- A passion for security and problem solving
- Familiarity with NIST 800-53 and similar controls frameworks
- 5+ years of experience with ServiceNow Platform internals
- 3+ years of experience performing threat modeling for software products