View All Jobs 14146

Sr Staff Product Security Architect (ssdl)

Build secure, scalable software solutions with threat modeling and security champion mentorship
Bangalore
Expert
2 weeks ago
ServiceNow

ServiceNow

A cloud-based platform that provides solutions for IT service management, automating business processes, and workflow optimization.

Sr Staff Product Security Architect (SSDL)

It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today — ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500®. Our intelligent cloud-based platform seamlessly connects people, systems, and processes to empower organizations to find smarter, faster, and better ways to work. But this is just the beginning of our journey. Join us as we pursue our purpose to make the world work better for everyone.

Team Product Security is shifting everywhere and holistically improving the maturity of the security program. The Secure Software Development Lifecycle (SSDL) team helps the organization measure and improve security activities. The team leads product threat modeling, helps to improve security behaviors, and manages a highly visible security champions program. The team is both highly technical and strategic.

Role As a Senior Staff Product Security Architect on the ServiceNow SSDL team, you will collaborate with developers and software architects on highly technical solutions and help the organization build secure and resilient software. You will be threat modeling software products and services to identify potential risk and participate in architectural reviews of products in development.

A key part of this position is to ensure the continued success of a large and growing security champions program. You will help mentor security champions and assist them in secure software design. As a Senior Staff Product Security Architect, you will help security champions be successful.

What you get to do in this role:

  • Work on a wide range of technologies
  • Work on complex architectural and technical challenges
  • Participate in threat modeling activities
  • Mentor and collaborate with development teams to adopt secure coding practices
  • Work on strategic and highly visible security activities across the organization
  • Be an advocate for security and participate in a security champions program

To be successful in this role you have:

  • Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving.
  • 10+ years of experience in software security (AppSec)
  • 6+ years of experience in threat modeling software applications and services
  • Expert-level knowledge in threat modeling methodologies such as STRIDE or PASTA and their applied use in fast-moving, iterative development lifecycles
  • Expert-level knowledge of common web application vulnerabilities (OWASP Top 10)
  • Developer-level proficiency in one or more languages - Python, Java, JavaScript, and Golang preferred
  • In-depth knowledge of software design patterns and their security considerations
  • Expertise in authentication and authorization standards including OAuth, OIDC, SAML, JWT, and PASETO
  • Knowledge of symmetric and asymmetric cryptography, digital signatures, PKI, TLS, and cryptographic hash functions
  • Knowledge of cloud native technologies including containers, Kubernetes, and services provided by AWS, GCP, and Azure
  • Knowledge of static analysis (SAST), dynamic analysis (DAST), and software composition analysis (SCA) security tools
  • Knowledge of OWASP ASVS, SCVS, and related verification standards
  • Ability to work collaboratively in a highly distributed team
  • Ability to communicate technical concepts to business stakeholders
  • A passion for security
+ Show Original Job Post
























Sr Staff Product Security Architect (ssdl)
Bangalore
Product
About ServiceNow
A cloud-based platform that provides solutions for IT service management, automating business processes, and workflow optimization.