HomeSearchSecurity Engineer Jobs › Product Security Engineer 3

Product Security Engineer 3

Adobe

Bangalore
More Security Engineer jobs: Security Engineer jobsSecurity Engineer salary

About the Role Adobe's Product and Software Security Team is looking for a Security Engineer with extensive penetration testing skills and strong DevSecOps experience. This role involves hands-on adversarial testing and integrating security throughout Adobe's software development lifecycle. The position includes assessing security in web, mobile, and desktop applications, cloud setups, AI/LLM systems, and supporting infrastructure.

It also involves creating and maintaining security controls embedded in CI/CD pipelines. The chosen candidate will manage projects from start to finish, provide clear risk evaluations with actionable fixes, and collaborate with engineering teams to deliver software that is secure by default on a large scale. What You’ll Do Perform penetration testing on AI/LLM systems (timely injection, model poisoning, jailbreaks, etc.), web applications, APIs, mobile apps, cloud infrastructure, containers, and supporting infrastructure.

Identify and take advantage of vulnerabilities including authentication/authorization flaws, business logic issues, injection, SSRF, deserialization, and chained attacks. Embed security controls into CI/CD pipelines: SAST, DAST, SCA, secrets scanning, and container/image scanning as outstanding pipeline gates. Build and operate DevSecOps automation across cloud environments (AWS, Azure, GCP): policy-as-code, infrastructure-as-code scanning, and automated security guardrails.

Develop custom scripts and tooling using Python, Go, or PowerShell to automate testing, validation, and pipeline integration. Collaborate with engineering teams on threat modeling, security code review, and secure-by-default architecture. Build the feedback loop from security findings back into preventive controls so the same class of bug doesn't ship twice. Deliver clear, actionable reports and provide remediation mentorship to engineering and product teams.

Manage the full lifecycle of penetration testing engagements from prioritisation to execution and delivery. Research emerging AI/ML exploits, cloud-native attack techniques, and supply chain risks to stay ahead of threats. Improve testing methodologies and contribute to the internal knowledge base. Requirements Experience & Skills 4-6 years of combined experience in penetration testing and DevSecOps, with meaningful depth in both — not just one.

Hands-on pentest experience across web apps, APIs, mobile, and cloud environments. You can find and exploit, not just scan and report. Demonstrated experience incorporating security tools (SAST, DAST, SCA, secrets, container/image scanning) into CI/CD pipelines within live production settings. Understanding of AI/ML security, LLM vulnerabilities, and timely engineering attacks. Strong knowledge of OWASP Top 10, OWASP API Top 10, and OWASP LLM Top 10.

Programming/scripting in at least one language: Python, Bash, PowerShell, Go, JavaScript. Ability to read and understand source code, trace execution flows, and dynamically exploit vulnerabilities during live assessments. Understanding of secure coding practices and common code-level vulnerabilities. Extensive background in cloud security (AWS, Azure, GCP) and container technologies (Docker, Kubernetes).

Familiarity with infrastructure-as-code (Terraform, CloudFormation) and policy-as-code frameworks. Understanding of attack vectors, exploits, vulnerability exploitation, and chained attacks. Strong written and verbal communication skills with ability to explain findings to technical and non-technical audiences. Preferred Strong academic background (advanced degree or equivalent experience) in IT, Computer Science, or related fields.

Certifications: OSCP, OSWE, OSEP, GXPN, GPEN, GWAPT, CRTP, eJPT, CREST, CISSP, or equivalent. Published CVEs demonstrating research capability. Bug bounty or Capture The Flag (CTF) experience. Experience in AI/ML security research. Advanced exploitation experience and custom tooling development. Threat modeling and secure D

Search all live jobs — free, no account →