Staff Product Security Engineer

2 days ago


San Diego, California, United States ServiceNow Full time $155,800 - $272,700
Company Description

It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today — ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500. Our intelligent cloud-based platform seamlessly connects people, systems, and processes to empower organizations to find smarter, faster, and better ways to work. But this is just the beginning of our journey. Join us as we pursue our purpose to make the world work better for everyone.

Job Description

**PLEASE NOTE**:  This role requires a minimum of 2 days per week in our San Diego, CA ServiceNow Office.  Please do not apply if you cannot meet this requirement.  Thank you 

The ServiceNow Security Organization (SSO):  

The ServiceNow Security Organization (SSO) delivers world-class, innovative security solutions to reduce risk and protect the company and our customers. We enable our customers to migrate their most sensitive data and workloads to the cloud, accelerating our business so that we are the most trusted SaaS provider. We create an environment where our employees are proud to work and can make a positive impact  

Team:

Product Security is Shifting Everywhere and holistically improving the maturity of the security program. The Secure Software Development Lifecycle (SSDL) team helps the organization measure and improve security activities. The team leads product threat modeling, helps to improve security behaviors, and manages a highly visible security champions program. The team is both highly technical and strategic.   

Role:

As a Staff Product Security Engineer on the ServiceNow SSDL team, you will collaborate with developers and software architects on highly technical solutions and help the organization build secure and resilient software. You will be threat modeling software products and services to identify potential risk and participate in architectural reviews of products in development.    

A key part of this position is to ensure the continued success of a large and growing security champions program. You will help mentor security champions and assist them in secure software design. As a Staff Product Security Engineer, you will help security champions be successful.   

What you get to do in this role:

  • Work on a wide range of technologies 
  • Work on complex architectural and technical challenges 
  • Participate in threat modeling activities 
  • Mentor and collaborate with development teams to adopt secure coding practices 
  • Work on strategic and highly visible security activities across the organization 
  • Be an advocate for security and participate in a security champions program 
Qualifications

To be successful in this role, we need someone who has: 

  • Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving. This may include using AI-powered tools, automating workflows, analyzing AI-driven insights, or exploring AI's potential impact on the function or industry. 
  • 2+ years of experience in software development
  • 8+ years of experience in software security (AppSec)
  • 2+ years of experience in threat modeling software applications and services
  • Proficient in threat modeling methodologies such as STRIDE or PASTA and their applied use in fast-moving, iterative development lifecycles 
  • In-depth knowledge of common web application vulnerabilities (OWASP Top 10) 
  • Developer-level proficiency in one or more languages - Python, Java, JavaScript, and Golang preferred 
  • Working knowledge of Machine Learning and taxonomies such as BIML that categorize known attacks on machine learning models 
  • In-depth knowledge of software design patterns and their security considerations 
  • In-depth knowledge of authentication and authorization standards including OAuth, OIDC, SAML, JWT, and PASETO 
  • Knowledge of symmetric and asymmetric cryptography, digital signatures, PKI, TLS, and cryptographic hash functions 
  • Knowledge of cloud native technologies including containers, Kubernetes, and services provided by AWS, GCP, and Azure 
  • Knowledge of static analysis (SAST), dynamic analysis (DAST), and software composition analysis (SCA) security tools 
  • Knowledge of OWASP ASVS, SCVS, and related verification standards 
  • Ability to work collaboratively in a highly distributed team 
  • Ability to communicate technical concepts to business stakeholders 
  • A passion for security 

#SecurityJobs 

For positions in this location, we offer a base pay of: $155,800 to $272,700 plus equity (when applicable), variable/incentive compensation and benefits. Sales positions generally offer a competitive On Target Earnings (OTE) incentive compensation structure. Please note that the base pay shown is a guideline, and individual total compensation will vary based on factors such as qualifications, skill level, competencies, and work location. We also offer health plans, including flexible spending accounts, a 401(k) Plan with company match, ESPP, matching donations, a flexible time away plan and family leave programs.  Compensation is based on the geographic location in which the role is located and is subject to change based on work location. Additional Information

Work Personas

We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here. To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.

Equal Opportunity Employer

ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements. 

Accommodations

We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact [email protected] for assistance. 

Export Control Regulations

For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities. 

From Fortune. 2025 Fortune Media IP Limited. All rights reserved. Used under license. 



  • San Francisco, California, United States Material Security Full time $210,000 - $250,000 per year

    As a Staff Product Manager at Material Security, you will lead a new feature team, owning the core product experience. This includes critical elements of the platform that supports all other product areas and horizontal product experiences. Your mission is to evolve the core product concepts to support the rest of the product by applying your strong product...


  • San Diego, California, United States BioTalent Full time $120,000 - $180,000 per year

    *this is a hybrid-onsite role 3X per week in San Diego, CAJoin a mission-driven team building secure, innovative medical diagnostic technologies that improve lives every day. Our Diagnostics Software Engineering (R&D) team is seeking aLead Product Security Engineerwith strong medical device or instrument security experience to serve as the cybersecurity SME...


  • San Diego, California, United States Proven Recruiting Full time

    Lead Product Security Engineer (R&D)Hybrid in Sorrento Valley - 3 days onsiteWhat you will do:Maintain vigilance on industry security threats and manage risks according to established procedures.Define security requirements and controls based on use cases and threat models.Collaborate with cross-functional teams to integrate security into the product...


  • San Diego, California, United States Shield AI Full time

    Founded in 2015, Shield AI is a venture-backed deep-tech company with the mission of protecting service members and civilians with intelligent systems. Its products include the V-BAT and X-BAT aircraft, Hivemind Enterprise, and the Hivemind Vision product lines. With nine offices and facilities across the U.S., Europe, the Middle East, and the Asia-Pacific,...


  • San Francisco, California, United States Airtable Full time $170,000 - $215,000 per year

    Airtable is the no-code app platform that empowers people closest to the work to accelerate their most critical business processes. More than 500,000 organizations, including 80% of the Fortune 100, rely on Airtable to transform how work gets done.Join Airtable as a Product Security Engineer and play a pivotal role in shaping the security of our rapidly...


  • San Francisco, California, United States Parafin Full time $235,000 - $280,000 per year

    About Us:At Parafin, we're on a mission to grow small businesses.Small businesses are the backbone of our economy, but traditional banks often don't have their backs. We build tech that makes it simple for small businesses to access the financial tools they need through the platforms they already sell on.We partner with companies like DoorDash, Amazon,...


  • San Francisco, California, United States Block MB Full time $150,000 - $250,000 per year

    We're partnering with a cutting-edge robotics AI company backed by over $400M in funding to hire their first Product Security Engineer, a foundational hire shaping how security is built into everything they develop.You'll work hands-on across secure architecture, in-depth code reviews, and foundational infrastructure, from secrets management and key rotation...


  • San Francisco, California, United States Decagon Full time

    About DecagonDecagon is the leading conversational AI platform empowering every brand to deliver concierge customer experience. Our AI agents provide intelligent, human-like responses across chat, email, and voice, resolving millions of customer inquiries across every language and at any time.Since coming out of stealth, Decagon has experienced rapid growth....


  • San Diego, California, United States Qualcomm Full time $179,000 - $268,800 per year

    CompanyQualcomm Technologies, Inc.Job AreaOperations Group, Operations Group > Product ManagementGeneral SummaryQualcomm is looking for a Staff Product Manager - Software for its Industrial and Embedded IoT Business Unit to help define and promote Qualcomm chipsets for emerging use cases in various IoT segments. Successful candidate will define software...


  • San Francisco, California, United States Scale AI Full time $172,000 - $215,000 per year

    We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the overall security strategy. Your expertise in TypeScript, Python, Kubernetes, CI/CD, SAST,...