The ServiceNow Security Organisation (SSO):
The ServiceNow Security Organisation (SSO) delivers world-class, innovative security solutions to reduce risk and protect the company and our customers. We enable our customers to migrate their most sensitive data and workloads to the cloud, accelerating our business so that we are the most trusted SaaS provider. We create an environment where our employees are proud to work and can make a positive impact
The Security Research / Offensive Security team delivers red-team-like engagements and produces investigative reports that drive a reduction in operational security risk. Paired with a toolkit of code/program and dynamic environmental analysis skills, the team provides guidance on primary security controls, best practices, and product enhancement. Exploration techniques focus on problems broadly, measuring industry trends and product insecurity across ServiceNow鈥檚 cloud environment.
As a Principal Software Security Engineer, you'll be responsible for delivering offensive security engagements against ServiceNow's public-facing and internal products. You鈥檒l also be responsible for security auditing of the ServiceNow product stack and researching nuances of securing SaaS platforms. This will require an in-depth knowledge of various approaches to application auditing, including secure code review, debugging, dynamic web application testing, analysis and threat modeling. You鈥檒l work closely with product engineering teams to provide investigative reports to improve platform resiliency and ensure best-in-class security solutions.
What you get to do in this role: