Adobe

Product Security Engineer 3

Adobe Bengaluru, Karnataka, India

Software Development · 10,001+ employees

12 h ago
security Senior (5-10 yrs) Full-time India
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

Perform hands-on penetration testing across AI/LLM systems, cloud infrastructure, and applications while integrating security controls into CI/CD pipelines. Collaborate with engineering teams to conduct threat modeling and implement preventive security measures to ensure software is secure by default.

What they look for

Penetration testing DevSecOps Cloud security Python Go PowerShell CI/CD pipelines SAST DAST SCA Container security Infrastructure-as-code Threat modeling AI/ML security Vulnerability assessment Secure coding

Requirements

Requires 4-6 years of combined experience in penetration testing and DevSecOps with deep technical expertise in cloud and container security. Candidates must be proficient in scripting languages like Python or Go and possess a strong understanding of OWASP security standards.

Full description

About the Role

Adobe's Product and Software Security Team is looking for a Security Engineer with extensive penetration testing skills and strong DevSecOps experience. This role involves hands-on adversarial testing and integrating security throughout Adobe's software development lifecycle. The position includes assessing security in web, mobile, and desktop applications, cloud setups, AI/LLM systems, and supporting infrastructure. It also involves creating and maintaining security controls embedded in CI/CD pipelines. The chosen candidate will manage projects from start to finish, provide clear risk evaluations with actionable fixes, and collaborate with engineering teams to deliver software that is secure by default on a large scale.

What You’ll Do

  • Perform penetration testing on AI/LLM systems (timely injection, model poisoning, jailbreaks, etc.), web applications, APIs, mobile apps, cloud infrastructure, containers, and supporting infrastructure.
  • Identify and take advantage of vulnerabilities including authentication/authorization flaws, business logic issues, injection, SSRF, deserialization, and chained attacks.
  • Embed security controls into CI/CD pipelines: SAST, DAST, SCA, secrets scanning, and container/image scanning as outstanding pipeline gates.
  • Build and operate DevSecOps automation across cloud environments (AWS, Azure, GCP): policy-as-code, infrastructure-as-code scanning, and automated security guardrails.
  • Develop custom scripts and tooling using Python, Go, or PowerShell to automate testing, validation, and pipeline integration.
  • Collaborate with engineering teams on threat modeling, security code review, and secure-by-default architecture.
  • Build the feedback loop from security findings back into preventive controls so the same class of bug doesn't ship twice.
  • Deliver clear, actionable reports and provide remediation mentorship to engineering and product teams.
  • Manage the full lifecycle of penetration testing engagements from prioritisation to execution and delivery.
  • Research emerging AI/ML exploits, cloud-native attack techniques, and supply chain risks to stay ahead of threats.
  • Improve testing methodologies and contribute to the internal knowledge base.

Requirements

Experience & Skills

  • 4-6 years of combined experience in penetration testing and DevSecOps, with meaningful depth in both — not just one.
  • Hands-on pentest experience across web apps, APIs, mobile, and cloud environments. You can find and exploit, not just scan and report.
  • Demonstrated experience incorporating security tools (SAST, DAST, SCA, secrets, container/image scanning) into CI/CD pipelines within live production settings.
  • Understanding of AI/ML security, LLM vulnerabilities, and timely engineering attacks.
  • Strong knowledge of OWASP Top 10, OWASP API Top 10, and OWASP LLM Top 10.
  • Programming/scripting in at least one language: Python, Bash, PowerShell, Go, JavaScript.
  • Ability to read and understand source code, trace execution flows, and dynamically exploit vulnerabilities during live assessments.
  • Understanding of secure coding practices and common code-level vulnerabilities.
  • Extensive background in cloud security (AWS, Azure, GCP) and container technologies (Docker, Kubernetes).
  • Familiarity with infrastructure-as-code (Terraform, CloudFormation) and policy-as-code frameworks.
  • Understanding of attack vectors, exploits, vulnerability exploitation, and chained attacks.
  • Strong written and verbal communication skills with ability to explain findings to technical and non-technical audiences.

Preferred

  • Strong academic background (advanced degree or equivalent experience) in IT, Computer Science, or related fields.
  • Certifications: OSCP, OSWE, OSEP, GXPN, GPEN, GWAPT, CRTP, eJPT, CREST, CISSP, or equivalent.
  • Published CVEs demonstrating research capability.
  • Bug bounty or Capture The Flag (CTF) experience.
  • Experience in AI/ML security research.
  • Advanced exploitation experience and custom tooling development.
  • Threat modeling and secure DevOps knowledge at enterprise scale.
  • Experience with AI-assisted security tooling (LLM pipelines, RAG, agentic workflows) for vulnerability discovery or triage.
  • Open-source contributions or technical writing on offensive security, DevSecOps, or AI security.

About Adobe

Adobe empowers everyone to create through innovative platforms and tools that unleash creativity, productivity and personalized customer experiences. Adobe’s industry-leading offerings including Adobe Acrobat Studio, Adobe Express, Adobe Firefly, Creative Cloud, Adobe Experience Platform, Adobe Experience Manager, and GenStudio enable people and businesses to turn ideas into impact, powered by AI and driven by human ingenuity.

Our 30,000+ employees worldwide are creating the future and raising the bar as we drive the next decade of growth. We’re on a mission to hire the very best and believe in creating a company culture where all employees are empowered to make an impact. At Adobe, we believe that great ideas can come from anywhere in the organization. The next big idea could be yours. 

Let’s Adobe together

At Adobe, we believe in creating a company culture where all employees are empowered to make an impact. Learn more about Adobe life, including our values and culture, focus on people, purpose and community, Adobe for All, comprehensive benefits programs, the stories we tell, the customers we serve, and how you can help us advance our mission of empowering everyone to create.

Adobe is proud to be an Equal Employment Opportunity employer. We do not discriminate based on gender, race or color, ethnicity or national origin, age, disability, religion, sexual orientation, gender identity or expression, veteran status, or any other protected characteristic. Learn more.

Adobe aims to make our Careers website and recruiting process accessible to any and all users. If you have a disability or special need that requires accommodation to navigate our website or complete the application process, email accommodations@adobe.com.

AI Use Guidelines for Interviews: Our interviews are designed to reflect your own skills and thinking. The use of AI or recording tools during live interviews is not permitted unless explicitly invited by the interviewer or approved in advance as part of a reasonable accommodation. If these tools are used inappropriately or in a way that misrepresents your work, your application may not move forward in the process.

At Adobe, we empower employees to innovate with AI — and we look for candidates eager to do the same. As part of the hiring experience, we provide clear guidance on where AI is encouraged during the process and where it’s restricted during live interviews. See how we think about AI in the hiring experience.

Similar roles