Jobs / United States / Servicenow INC

Sr Staff Product Security Engineer - Product Security Incident Response Team (PSIRT)

Servicenow INC · 🇺🇸 Petah Tikva, IL

Sponsorship verdict

Sponsorship possible

One solid signal, not two — worth applying, and worth asking about sponsorship early.

  • Employer is on a government sponsor recordThe US Department of Labor certified 547 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 185 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
  • The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
  • No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
  • What Servicenow INC paid sponsored hires in similar roles14 certified filings for “Product Security Engineer” (Information Technology Project Managers) in CA: $115k–$186k, median $144k. Most were filed at wage level II (50%) — 2 lottery entries, ≈31% projected selection odds for cap-subject employers. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
  • Confirmed live todayWhen a source last listed this job as open.

US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).

A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.

Start free →

Or apply yourself on the official page →

Sponsor Radar — Servicenow INC

547 H-1B filings certified since Oct 2025

The US Department of Labor certified 547 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 185 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).

Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Servicenow INC →

About the role

ServiceNow seeks a senior staff-level product security engineer to serve as a senior technical authority within the Product Security Incident Response Team (PSIRT). PSIRT is ServiceNow's awareness, response, and investigation capability for post-release vulnerabilities in ServiceNow-developed products and service offerings.  This role is for a recognised expert who can operate independently and as part of a team on the most significant security issues facing the platform—vulnerabilities that require evaluating intangibles. You will lead deep-dive investigations, coordinate resolution across engineering, product, and release teams, and demonstrate calm, decisive leadership during significant security events.  This is a role for someone who already understands product development cycles and the engineering and product relationships that drive them—and will use that fluency to lead fixes to completion under incident pressure. You will help shape how ServiceNow responds to product security vulnerabilities at scale and the technical rigour of the entire response capability.  The coverage provided by this role is:  • Sunday: 10:00 - 18:00 UTC.  • Monday: 08:00 - 16:00 UTC.  • Tuesday: 08:00 - 16:00 UTC.  • Wednesday: 08:00 - 16:00 UTC.  • Thursday: 08:00 - 16:00 UTC.  Due to the nature of incident response and the needs of the business, coverage may change. Additional coverage outside of stated hours may be required in response to significant incidents.  Key Responsibilities  Lead Through Significant Security Events  • Demonstrate technical and organisational leadership during these events—bringing structure and clear decision-making under pressure.  • Partner with incident commanders, business information security leadership, engineering, and customer-facing teams to maintain clear ownership, workstream prioritization, and hand-offs during these events.  Reduce Exposure Window  • Drive coordinated response across affected releases, balancing risk and remediation feasibility.  • Leverage an understanding of product development cycles and engineering/product partnerships to move fixes through the release pipeline without stalling on organisational boundaries.  • Verify fix completeness and guard against incomplete mitigations before release.  Drive the CVE & Coordinated Disclosure Process  • Collaborate with external security partners, vendors, and researchers on coordinated disclosures, aligning timelines and messaging across parties.  • Conduct technical accuracy reviews of external advisories, researcher write-ups, and joint disclosure content to ensure correctness before publication.  • Represent PSIRT's technical position in multi-party coordinated disclosures and researcher engagements.  Pursue After-Action Outcomes & Continuous Improvement  • Author postmortems and drive lessons learned to closure following product security incidents.  • Participate in retrospectives following significant product security events, translating findings into concrete process and technical improvements.  • Contribute to partner teams tracking product security risk themes and trends across the portfolio.  • Contribute to SDLC improvement areas, feeding incident learnings upstream into secure development practices.  To be successful in this role, you have:   Qualifications  • Minimum 12 years of related experience with a Bachelor's degree; or 8 years with a Master's degree; or a PhD with 5 years of experience; or equivalent experience.  • Minimum of 5 years of auditing source code for security vulnerabilities.  • Demonstrated leadership during significant security events or major incidents, with willingness to participate in on-call.  • Ability to read and comprehend Java and JavaScript code.   • Strong understanding of common

View the official posting →

Source: smartrecruiters First seen: 2026-10-05 Last confirmed: 2026-10-05 How our data works → Report this job

Similar opportunities