Senior Product Security Engineer

Adobe Inc.

San Jose (CA)

On-site

USD 181,000 - 261,000

Full time

8 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Adobe is seeking a Senior Product Security Engineer to triage and validate external vulnerability reports from the Bug Bounty program, working with engineering and security teams to drive remediation.

You will reproduce PoCs, assign CVSS severities, and communicate clearly with researchers while developing runbooks and dashboards in PowerBI to enable data-driven security decisions.

Qualifications

  • Bachelor's degree or equivalent experience in Computer Science, Engineering, or a related field.
  • 5+ years of practical security testing experience.
  • In-depth knowledge of OWASP Top 10 vulnerabilities and mitigations.
  • Strong understanding of CVSS v3.1 scoring and applying it to real-world cases.
  • Proficiency with Burp Suite, DevTools, curl, and custom scripts.
  • Experience with bug bounty platforms and responsible disclosure processes.
  • Excellent written communication with researchers.
  • Experience with AI/LLM security testing and attacker techniques.

Responsibilities

  • Triage, validate and reproduce vulnerability reports from the bug bounty platform.
  • Assign CVSS scores and severities per internal guidelines.
  • Reproduce PoC exploits across web, API and mobile surfaces.
  • Communicate with researchers to request clarifications and provide status updates.
  • Coordinate with engineering teams to remediate confirmed vulnerabilities.
  • Develop triage runbooks and severity calibration guidelines.
  • Develop PowerBI dashboards to support data-driven remediation efforts.

Skills

Bug bounty triage
CVSS scoring
PoC reproduction
Security testing
Bug bounty platforms
Technical writing
LLM/AI security
JIRA
PowerBI
Python scripting
Automation workflows
Attacker techniques

Education

Bachelor's degree or equivalent in CS/Engineering

Tools

Burp Suite
Browser DevTools
curl
Custom scripts
JIRA
PowerBI

Job description

Job Description: Senior Product Security Engineer

The Opportunity

Are you passionate about product security testing and vulnerability management? Adobe Product and Software Security is seeking a dynamic candidate with strong security testing expertise to join our expanding team. In this role, you will be the frontline responder for external vulnerability reports submitted through the Bug Bounty program, working closely with internal engineering and security teams to ensure timely, accurate triage and resolution, managing automation workflows, supporting live hacking events, campaigns, challenges.

This is a great opportunity to contribute to innovative work that will elevate Adobe Security to new heights!

What You'll Do
  • Triage, validate and reproduce incoming vulnerability reports submitted via the bug bounty platform, assessing validity, impact, and scope, including AI related reports.
  • Assign CVSS scores and severity ratings accurately, following Adobe's internal severity guidelines and industry standards.
  • Reproduce proof-of-concept (PoC) exploits to validate reported vulnerabilities across web, API, and mobile surfaces.
  • Communicate clearly and professionally with external researchers: request clarifications, provide status updates, and manage expectations.
  • Coordinate with product engineering teams to route confirmed vulnerabilities for remediation.
  • Identify duplicate, out-of-scope, or informational reports and close them with clear, respectful explanations.
  • Contribute to internal documentation, triage runbooks, and severity calibration guidelines.
  • Flag systemic or critical findings to Bug Bounty team for partner concern as needed.
  • Develop dashboards in PowerBI to support data-driven analysis and remediation efforts.
What You Need to Succeed
  • Bachelor's degree or equivalent experience in Computer Science, Engineering, or a related field, with 5+ years of practical experience.
  • In-depth knowledge of application security vulnerabilities (OWASP Top 10) and mitigation techniques.
  • Strong understanding of CVSS v3.1 scoring and hands-on experience applying it to real-world vulnerabilities.
  • Proficiency in common web vulnerability classes: XSS, SQL injection, SSRF, IDOR, authentication flaws, and business logic issues.
  • Ability to reproduce and validate PoC exploits using tools such as Burp Suite, browser DevTools, curl, and custom scripts.
  • Familiarity with bug bounty platforms and responsible disclosure processes.
  • Solid written communication skills - able to write clear, constructive responses to researchers of all skill levels.
  • Familiarity with attacker techniques used by external researchers against LLM systems and generative AI products.
  • Proficiency with JIRA and PowerBI.
  • Strong knowledge of LLM (Large Language Model) testing methodologies.
  • Hands-on experience in penetration testing of AI/ML and LLM-powered products, including chat interfaces, agentic workflows, and inference APIs.
  • Ability to design and complete AI-specific test cases.
  • Experience with attacker techniques used by external researchers against LLM systems and generative AI products.
  • Experience with a SOAR/orchestration platform (building or extending app connectors and playbooks, understanding action-based automation models)
  • API integration literacy (can read a vendor's REST API docs or an OpenAPI/Swagger spec and correctly implement authentication (OAuth2, bearer tokens, API keys), pagination, and error handling)
  • Scripting proficiency in Python (comfortable writing and maintaining small, production-quality integration code)
  • Event-driven automation (hands-on experience with webhooks, AWS Lambda, and API Gateway, turning real-time platform events into automated downstream actions)
  • Dependability: Demonstrates commitment, works independently, accepts accountability, adapts to change, sets personal standards, and remains focused under pressure.
  • Ability to communicate professionally and effectively.
About Adobe

Adobe empowers everyone to create through innovative platforms and tools that unleash creativity, productivity and personalized customer experiences. Adobe's industry-leading offerings including Adobe Acrobat Studio, Adobe Express, Adobe Firefly, Creative Cloud, Adobe Experience Platform, Adobe Experience Manager, and GenStudio enable people and businesses to turn ideas into impact, powered by AI and driven by human ingenuity.

Our 30,000+ employees worldwide are creating the future and raising the bar as we drive the next decade of growth. We're on a mission to hire the very best and believe in creating a company culture where all employees are empowered to make an impact. At Adobe, we believe that great ideas can come from anywhere in the organization. The next big idea could be yours.

Let's Adobe together

At Adobe, we believe in creating a company culture where all employees are empowered to make an impact. Learn more about Adobe life, including our values and culture, focus on people, purpose and community, Adobe for All, comprehensive benefits programs, the stories we tell, the customers we serve, and how you can help us advance our mission of empowering everyone to create.

Adobe is proud to be an Equal Employment Opportunity employer. We do not discriminate based on gender, race or color, ethnicity or national origin, age, disability, religion, sexual orientation, gender identity or expression, veteran status, or any other protected characteristic. Learn more.

Adobe aims to make our Careers website and recruiting process accessible to any and all users. If you have a disability or special need that requires accommodation to navigate our website or complete the application process, email accommodations@adobe.com.

AI Use Guidelines for Interviews:

Our interviews are designed to reflect your own skills and thinking. The use of AI or recording tools during live interviews is not permitted unless explicitly invited by the interviewer or approved in advance as part of a reasonable accommodation. If these tools are used inappropriately or in a way that misrepresents your work, your application may not move forward in the process.

At Adobe, we empower employees to innovate with AI - and we look for candidates eager to do the same. As part of the hiring experience, we provide clear guidance on where AI is encouraged during the process and where it is restricted during live interviews. See how we think about AI in the hiring experience.

Expected Pay Range:

Our compensation reflects the cost of labor across several U.S. geographic markets, and we pay differently based on those defined markets. The U.S. pay range for this positionis $144,800 -- $261,450 annually. Paywithin this range varies by work locationand may also depend on job-related knowledge, skills,and experience. Your recruiter can share more about the specific salary range for the job location during the hiring process. In California, the pay range for this position is $180,600 - $261,450

At Adobe, for sales roles starting salaries are expressed as total target compensation (TTC = base + commission), and short-term incentives are in the form of sales commission plans. Non-sales roles starting salaries are expressed as base salary and short-term incentives are in the form of the Annual Incentive Plan (AIP).

In addition, certain roles may be eligible for long-term incentives in the form of a new hire equity award.

State-Specific Notices:
California:
Fair Chance Ordinances

Adobe will consider qualified applicants with arrest or conviction records for employment in accordance with state and local laws and \"fair chance\" ordinances.

Colorado:

If this role is open to hiring in Colorado (as listed on the job posting), the application window will remain open until at least the date and time stated above in Pacific Time, in compliance with Colorado pay transparency regulations. If this role does not have Colorado listed as a hiring location, no specific application window applies, and the posting may close at any time based on hiring needs.

Massachusetts:
Massachusetts Legal Notice

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Product Security Engineer
Senior Product Security Engineer

Socket.dev • San Jose (CA), Northern (KY)

Hybrid
USD 181,000 - 261,000
Vice President, Product and Software Security
Vice President, Product and Software Security

Adobe Inc. • San Jose (CA)

On-site
USD 335,000 - 521,000
Systems DesignArchitecture Engineer 5
Systems DesignArchitecture Engineer 5

Adobe • Seattle (WA)

On-site
USD 148,000 - 293,000
Platform Engineer 4
Platform Engineer 4

Adobe Inc. • San Jose (CA)

On-site
USD 178,000 - 258,000
Senior Security Automation Engineer
Senior Security Automation Engineer

Adobe • Lehi (UT)

On-site
USD 145,000 - 261,000
Full-Stack Engineer
Full-Stack Engineer

Adobe Inc. • San Jose (CA)

On-site
USD 177,000 - 258,000
Senior Product Manager, Data Platform - Knowledge & Retrieval
Senior Product Manager, Data Platform - Knowledge & Retrieval

Adobe Inc. • San Jose (CA)

On-site
USD 166,000 - 240,000
Group Manager, Communications Strategy & Ops
Group Manager, Communications Strategy & Ops

Adobe Inc. • San Francisco (CA)

On-site
USD 173,000 - 251,000
Senior Software Development Engineer
Senior Software Development Engineer

Adobe • California (MO)

On-site
CAD 120,000 - 165,000
Senior Marketing Program Manager
Senior Marketing Program Manager

Adobe Inc. • San Jose (CA)

On-site
USD 121,000 - 220,000