Skip to main content
ServiceNow

Expert, Application Security & VIPR

RemoteSpain only
Published
Role
Security
Experience
Senior
Employment
Full-time
Salary not disclosed
Check eligibility

Open to ES only. Set where you work from to check your eligibility.

No BS summary

Эксперт по безопасности приложений с 7–10+ годами опыта в AppSec, Product Security или безопасной разработке ПО. Требуется глубокое знание SAST, DAST, SCA и инструментов управления зависимостями (Veracode, Checkmarx, Fortify, Snyk, SonarQube, OWASP Dependency-Check). Роль включает лидерство в программе AppSec, интеграцию с VIPR, автоматизацию пайплайнов и наставничество.

Core skills

SASTDASTSCA

Required skills

VeracodeCheckmarxFortifySnykSonarQubeOWASP Dependency-CheckSTRIDEDREADPASTAGitHub ActionsJenkinsBuildkiteDockerKubernetesReactNode.jsPythonJavaGoOAuth2TerraformCloudFormation

Optional skills

Prisma CloudWizOrcaOSWECSSLPGWAPTGWEBCEH

What you'll do

  • Lead the Application Security program across all Armis products, embedding security throughout the SDLC.
  • Perform secure design and architecture reviews, partnering with engineering teams to identify and mitigate risk early.
  • Conduct and lead threat modeling sessions using STRIDE, DREAD, or PASTA methodologies.
  • Own application-layer vulnerability management as part of Armis’ VIPR strategy, from detection through remediation and validation.
  • Integrate AppSec findings (SAST, DAST, SCA, API testing) into centralized vulnerability workflows, risk scoring, and prioritization models.
  • Correlate application vulnerabilities with asset context, exploit intelligence, and business criticality to drive risk-based remediation.
  • Track and report VMDR metrics such as MTTD, MTTR, exposure windows, and remediation effectiveness for application vulnerabilities.
  • Build and maintain automated AppSec pipelines for SAST, DAST, SCA, and API security testing.
  • Collaborate with DevOps to integrate security scanning into CI/CD pipelines (GitHub Actions, Jenkins, Buildkite).
  • Partner with Cloud and Infrastructure Security to secure APIs, microservices, and containerized workloads (Docker, Kubernetes).
  • Develop and maintain secure coding standards and security baselines for React, Node.js, Python, Java, and Go.
  • Mentor engineers and security champions; deliver secure coding training and threat modeling workshops.
  • Act as a trusted advisor to engineering leadership, translating vulnerabilities into clear risk and remediation guidance.
  • Support compliance and audit readiness including SOC 2, ISO 27001, FedRAMP, and HIPAA, ensuring application risks are documented and managed within VIPR /AppSec processes.

What they require

  • 7–10+ years of experience in Application Security, Product Security, or Secure Software Engineering.
  • Proven expertise in SAST, DAST, SCA, and dependency management tools (e.g., Veracode, Checkmarx, Fortify, Snyk, SonarQube, OWASP Dependency-Check).
  • Hands-on coding proficiency in at least two modern languages (Python, JavaScript/TypeScript, Java, Go).
  • Strong experience managing vulnerabilities end-to-end, including triage, prioritization, remediation tracking, and validation.
  • Deep understanding of OWASP Top 10, CWE, CVE, and exploitability concepts.
  • Strong knowledge of CI/CD pipelines, Git-based workflows, and secure build automation.
  • Experience with threat modeling, secure architecture reviews, and microservices/API security.
  • Ability to clearly communicate technical risk to both engineering teams and business stakeholders.

Benefits

  • Flexible work personas (flexible, remote, or required in office) with flexibility and trust.
  • Equal opportunity employer.
  • Accommodations for candidates with disabilities.

ServiceNow is a global market standard providing an intelligent cloud-based platform that connects people, systems, and processes; Moveworks is its Agentic AI Assistant platform for workforce automation.

🇺🇸 United StatesEnterprise SoftwareEnterpriseservicenow.com

What people say about this company

3.8/ 5

  • Employees appreciate the collaborative work environment.
  • There are opportunities for professional growth and development.
  • Some employees have raised concerns about management effectiveness.
Salary not disclosed