368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$114k – $258k per year (Estimated)
Location
In office (Petah Tikva)
Seniority
Senior · 8+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
ServiceNow is a leading cloud-based enterprise platform that connects data, workflows, and artificial intelligence to automate business operations. Originally focused on IT service management, the platform now streamlines processes across human resources, customer service, security, and supply chain management within a single digital ecosystem. Through its built-in low-code tools and AI capabilities, it helps global organizations optimize workforce productivity, eliminate manual tasks, and scale modern enterprise workflows.

It all started when engineer Fred Luddy wrote code that automated a tedious task for his coworker, Phyllis. She cried tears of joy. That moment inspired Fred to build a company that could do that for everyone-freeing people from busywork so they could focus on meaningful work. Today, ServiceNow is the AI control tower for business reinvention. Our ServiceNow AI platform brings together any AI, any data, and any workflow- helping 85% of the Fortune 500® work smarter, faster, and better. We're building an AI-native culture where technology and talent are unstoppable together. And we're just getting started.

Join us to put AI to work for people.

ServiceNow seeks a Senior Application Security Engineer to serve as the technical core of our bug bounty program within the Product Security Incident Response Team (PSIRT). This is the senior engineer who owns bug bounty reports from intake through resolution: reproducing and validating the vulnerability, assessing its severity, and seeing it through to a verified fix.

The work is deeply technical. Reproducing a vulnerability is only the starting point. From there you read the underlying code, identify root cause, and either propose the fix or design it alongside engineering before confirming it holds. You are also the person researchers deal with directly, which makes clear, credible communication as central to the role as the technical analysis itself.

As one of the most senior engineers on the team, you will set the standard for how triage is done and mentor earlier-career engineers. Beyond the bug bounty queue, you will conduct variant hunts, perform original platform security research, lead major product security incidents, and run forensic postmortems when a significant issue reaches production.

Key Responsibilities

Triage and Resolve Bug Bounty Reports

  • Own incoming reports end-to-end: intake, reproduction, severity scoring, root cause analysis, fix verification, and final disposition.
  • Reproduce and validate reported vulnerabilities, building out incomplete proof-of-concept code where needed.
  • Serve as the technical escalation point for the most complex and highest-severity reports, including multi-step exploit chains and cross-system issues.
  • Perform code review and root cause analysis to identify the underlying defect rather than the reported symptom.
  • Propose remediations, or design them with engineering, and verify the fix resolves the issue.
  • Assign and defend severity ratings using the program's severity framework.
  • Route issues to owning teams, file and track defects, and keep vulnerability records accurate through closure.

Own Researcher and Stakeholder Communication

  • Act as ServiceNow's primary technical point of contact for bug bounty researchers across the full lifecycle of a report.
  • Handle severity and validity disputes directly, keeping every exchange clear, timely, respectful, and technically credible.
  • Translate technical findings for internal stakeholders and keep engineering and leadership current on status and risk.

Mentor the Team and Raise Triage Standards

  • Provide technical mentorship to earlier-career PSIRT engineers, developing depth in reproduction, code analysis, severity judgment, and communication.
  • Set and maintain the bar for triage quality and strengthen program practices over time.

Lead Advanced Security Work Beyond Triage

  • Conduct variant hunts to find related instances of reported vulnerabilities before they are discovered externally.
  • Perform original platform security research to surface issues ahead of external researchers.
  • Lead major product security incidents on the PSIRT side, coordinating response across teams under pressure.
  • Run forensic postmortems after significant incidents to determine how the issue reached production, including how design-level flaws bypassed release processes, and confirm that remediations hold.

To be successful in this role, you have:

  • 8+ years of hands-on experience in product security, application security, penetration testing, or vulnerability research. Depth of expertise matters more than years.

Expertise in:

  • Common web and application vulnerability classes and exploitation techniques.
  • Vulnerability reproduction, severity assessment, and defensible risk scoring under ambiguity.
  • Coordinated vulnerability disclosure.

Code and development fluency:

  • Strong code comprehension in Java, JavaScript, and Python, with the ability to trace root cause in large, unfamiliar codebases and review pull requests.
  • Ability to write code and propose concrete fixes. This is not an application-building role, but you reason fluently in code.
  • Working knowledge of Git, Gradle, Maven, CI/CD pipelines, and secure SDLC.
  • Proficiency with Claude Code or equivalent AI coding assistant for code comprehension and security research.
  • Exceptional written communication. You will represent ServiceNow directly to external researchers, frequently in disagreement, and bridge those researchers and internal engineering. This is a core requirement of the role, not a supporting skill.

Work Personas

We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here. To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.

Equal Opportunity Employer

ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, age, disability, gender identity, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.

Accommodations

We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact [email protected] for assistance.

Export Control Regulations

For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.

From Fortune. ©2026 Fortune Media IP Limited. All rights reserved. Used under license.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Petah Tikva
up to $48k per year (net) • Remote/Hybrid • Moscow
Node JS
Python
TypeScript
JavaScript
Node JS
Nest.JS
Python
Django
FastAPI
Databases
Apache Kafka
pgvector
Pinecone
PostgreSQL
Qdrant
RabbitMQ
Redis
AI/ML
Chain-of-Thought
Claude
Claude Code
Copilot
Cursor
LangChain
LlamaIndex
LLM
Prompt Engineering
RAG
Anthropic
Function Calling
OpenAI
Structured Outputs
Frontend
GraphQL
Next.js
React.js
Redux
Redux Toolkit
Zustand
Mobile
State Management
DevOps
AWS
CI/CD
Docker
GCP
GitHub Actions
GitLab CI
Grafana
Kubernetes
Prometheus
Yandex Cloud
GitHub
GitLab
Apply
$42k – $104k per year (Estimated) • In office • Internship • 5+ years exp
Bash
PowerShell
Python
DevOps
Amazon EC2
Amazon EKS
Ansible
AWS
AWS Lambda
Azure
CentOS Stream
Chef
CI/CD
CloudFormation
Configuration Management
Datadog
FinOps
GCP
Git
GitHub Actions
GitLab CI
Grafana
Hyper-V
Istio
Jenkins
Kubernetes
KVM
Linkerd
Platform Engineering
Prometheus
Puppet
Service Mesh
Splunk
Terraform
Ubuntu
VMWare
Windows Server
Amazon CloudWatch
Amazon ECS
Amazon S3
API Gateway
AWS Step Functions
GitHub
GitLab
IAM
Cybersecurity
GDPR
ISO 27001
SOC 2
Apply
$11k – $24k per year (Estimated) • Remote/Hybrid • Saint Petersburg
Bash
PowerShell
DevOps
CI/CD
Docker
Git
GitLab CI
Hyper-V
kubectl
Kubernetes
Proxmox VE
VMWare
GitLab
Apply
$61k – $143k per year (Estimated) • Remote/Hybrid • Full-Time • 4+ years exp • Cambridge
Go
Node JS
Python
TypeScript
JavaScript
Databases
ElasticSearch
MySQL
Frontend
GraphQL
Next.js
React.js
DevOps
CI/CD
Kubernetes
Apply
$23k – $62k per year (Estimated) • In office • Full-Time • 10+ years exp • Gurgaon
C#
SQL
Databases
Apache Kafka
Redis
DevOps
Azure
CI/CD
Docker
gRPC
Kubernetes
Apply
$40k – $91k per year (Estimated) • In office • Full-Time • 6+ years exp • Chiyoda
JavaScript
SQL
Management
ServiceNow
Apply
$172k – $301k per year • Equity • In office • Full-Time • 8+ years exp • Minneapolis
C++
Go
Java
Python
AI/ML
AI Agents
Fine-tuning
Hybrid Search
LLM
Prompt Engineering
RAG
Semantic Search
Anthropic
Human-in-the-Loop
LLM Guardrails
OpenAI
Semantic Search
Structured Outputs
Function Calling
DevOps
Vector
Cybersecurity
Least Privilege
Management
ServiceNow
Apply
$181k – $317k per year • Equity • In office • Full-Time • 10+ years exp • Bachelor's Degree • San Diego
Java
Databases
Apache Iceberg
Apache Kafka
MySQL
PostgreSQL
AI/ML
Flink
Spark
Management
ServiceNow
Apply
$201k – $352k per year • Equity • In office • Full-Time • 10+ years exp • Bachelor's Degree • Santa Clara
Java
SQL
Databases
MariaDB
MS SQL
MySQL
Oracle
PostgreSQL
Trino
AI/ML
Time Series Forecasting
Mobile
Clean Architecture
JUnit
DevOps
CI/CD
Management
ServiceNow
QA
Selenium
TestNG
Apply
In office • Full-Time • 4+ years exp • San Francisco
Bash
Python
SQL
DevOps
Docker
Kubernetes
Management
ServiceNow
Apply
$85k – $242k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Petah Tikva
Perl
Python
SystemVerilog
Chips/EDA
Cadence Palladium
Cadence Protium
Cadence Xcelium
UVM
Apply
$98k – $236k per year (Estimated) • In office • Full-Time • 7+ years exp • Bachelor's Degree • Petah Tikva
Perl
Python
SystemVerilog
Verilog
Apply
Remote/Hybrid • Full-Time • Bachelor's Degree • Petah Tikva • Haifa
Python
AI/ML
Anomaly Detection
LLM
Edge AI
Apply
$138k – $330k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Petah Tikva
Java
Python
AI/ML
LangChain
LangGraph
LLM
RAG
A2A
LLM Guardrails
AI Agents
Model Context Protocol
Cybersecurity
Threat Modeling
Management
ServiceNow
Apply
$168k – $349k per year (Estimated) • In office • 12+ years exp • Bachelor's Degree • Petah Tikva
Java
Python
AI/ML
AI Agents
LLM
DevOps
CI/CD
Kubernetes
Service Mesh
Management
ServiceNow
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.