Senior Product Security Engineer: Bug Bounty & Remediation

Socket.dev

San Jose, Northern (CA, KY)

Hybrid

USD 181,000 - 261,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Adobe seeks a Senior Product Security Engineer to triage external vulnerability reports submitted via Bug Bounty, reproduce PoCs, and assign CVSS scores. You will work with product teams to ensure timely remediation and develop dashboards to monitor progress.

You will apply OWASP Top 10 knowledge and LLM/AI security testing expertise to validate findings and communicate clearly with researchers and internal teams.

Qualifications

  • Bachelor’s degree in Computer Science, Engineering or related field, plus 5+ years relevant experience.
  • Strong knowledge of application security vulnerabilities (OWASP Top 10) and mitigation.
  • Hands-on experience with CVSS v3.1 scoring.

Responsibilities

  • Triage, validate and reproduce vulnerability reports from Bug Bounty submissions.
  • Assign CVSS scores and severity using internal guidelines.
  • Reproduce PoC exploits across web, API and mobile surfaces.
  • Communicate with external researchers and manage expectations.
  • Coordinate with engineering teams to route confirmed issues for remediation.
  • Identify duplicates, out-of-scope, or informational reports and document rationale.
  • Contribute to triage runbooks and severity calibration guidelines.
  • Flag systemic findings to Bug Bounty team as needed.
  • Develop PowerBI dashboards to support data-driven remediation.

Skills

OWASP Top 10
Vulnerability testing
PoC reproduction
Written communication
LLM testing
Python scripting
Automation experience
Security incident triage

Education

Bachelor’s degree or equivalent in CS/Engineering

Tools

Burp Suite
DevTools
curl
JIRA
PowerBI
OpenAPI/Swagger
AWS Lambda / API Gateway

Job description

Adobe seeks a Senior Product Security Engineer to triage external vulnerability reports submitted via Bug Bounty, reproduce PoCs, and assign CVSS scores. You will work with product teams to ensure timely remediation and develop dashboards to monitor progress.

You will apply OWASP Top 10 knowledge and LLM/AI security testing expertise to validate findings and communicate clearly with researchers and internal teams.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Vulnerability Operations Engineer
Senior Vulnerability Operations Engineer

Adobe • Town of Montana (WI)

On-site
USD 145,000 - 261,000
Senior Product Security Engineer - Portfolio Lead
Senior Product Security Engineer - Portfolio Lead

Adobe Inc. • New York (NY)

On-site
USD 214,000 - 310,000
Staff Product Security Engineer: Security for Key Products
Staff Product Security Engineer: Security for Key Products

Adobe • New York (NY)

On-site
USD 214,000 - 310,000
Senior Security Engineer, Web Bug Bounty Lead
Senior Security Engineer, Web Bug Bounty Lead

Mozilla Corporation • United States

Remote
USD 120,000 - 150,000
Bonus plan
Health benefits (medical/dental/vision
Retirement contributions
+7
Technical Program Manager, Bug Bounty & Security
Technical Program Manager, Bug Bounty & Security

Amazon • Seattle (WA)

On-site
USD 127,100 - 172,000
Lead Web Bug Bounty Security Engineer
Lead Web Bug Bounty Security Engineer

Mozilla • United States

On-site
USD 126,000 - 183,000
Bonus plans
Medical/dental/vision coverage
Retirement contributions
+7
Application Security Engineer II — Vulnerability Triage Expert
Application Security Engineer II — Vulnerability Triage Expert

Bugcrowd • United States

Remote
USD 110,000 - 160,000
Product Security Analyst: AI-Driven Vulnerability Expert
Product Security Analyst: AI-Driven Vulnerability Expert

DaParrot Ltd • Northern (KY)

Hybrid
USD 120,000 - 140,000
Health insurance
Equity stock options
Retirement plans
+3
Security Program Manager - Bug Bounty
Security Program Manager - Bug Bounty

Amazon • San Francisco (CA)

On-site
USD 127,000 - 172,000
Health insurance
401(k) matching
Paid time off
+1
Lead Web Bug Bounty & Security Engineer
Lead Web Bug Bounty & Security Engineer

Mozilla Corporation • United States

Remote
USD 120,000 - 180,000
Generous bonus plans
Medical, dental, vision coverage
100% vesting retirement contributions
+4