Job Tank India
AD

Product Security Engineer 3

Adobe · Bangalore

experiencedBangalorePosted 10 Sept 2026

This listing is from the archive and may be closed. Browse the latest experienced jobs for current openings.

Adobe is hiring a Product Security Engineer 3 in Bangalore.

Responsibilities

  • Perform penetration testing on AI/LLM systems (timely injection, model poisoning, jailbreaks, etc.), web applications, APIs, mobile apps, cloud infrastructure, containers, and supporting infrastructure.
  • Identify and take advantage of vulnerabilities including authentication/authorization flaws, business logic issues, injection, SSRF, deserialization, and chained attacks.
  • Embed security controls into CI/CD pipelines: SAST, DAST, SCA, secrets scanning, and container/image scanning as outstanding pipeline gates.
  • Build and operate DevSecOps automation across cloud environments (AWS, Azure, GCP): policy-as-code, infrastructure-as-code scanning, and automated security guardrails.
  • Develop custom scripts and tooling using Python, Go, or PowerShell to automate testing, validation, and pipeline integration.
  • Collaborate with engineering teams on threat modeling, security code review, and secure-by-default architecture.
  • Build the feedback loop from security findings back into preventive controls so the same class of bug doesn't ship twice.
  • Deliver clear, actionable reports and provide remediation mentorship to engineering and product teams.
  • Manage the full lifecycle of penetration testing engagements from prioritisation to execution and delivery.
  • Research emerging AI/ML exploits, cloud-native attack techniques, and supply chain risks to stay ahead of threats.
  • Improve testing methodologies and contribute to the internal knowledge base.

Requirements

Experience & Skills

  • 4-6 years of combined experience in penetration testing and DevSecOps, with meaningful depth in both — not just one.
  • Hands-on pentest experience across web apps, APIs, mobile, and cloud environments. You can find and exploit, not just scan and report.
  • Demonstrated experience incorporating security tools (SAST, DAST, SCA, secrets, container/image scanning) into CI/CD pipelines within live production settings.
  • Understanding of AI/ML security, LLM vulnerabilities, and timely engineering attacks.
  • Strong knowledge of OWASP Top 10, OWASP API Top 10, and OWASP LLM Top 10.
  • Programming/scripting in at least one language: Python, Bash, PowerShell, Go, JavaScript.
  • Ability to read and understand source code, trace execution flows, and dynamically exploit vulnerabilities during live assessments.
  • Understanding of secure coding practices and common code-level vulnerabilities.
  • Extensive background in cloud security (AWS, Azure, GCP) and container technologies (Docker, Kubernetes).
  • Familiarity with infrastructure-as-code (Terraform, CloudFormation) and policy-as-code frameworks.
  • Understanding of attack vectors, exploits, vulnerability exploitation, and chained attacks.
  • Strong written and verbal communication skills with ability to explain findings to technical and non-technical audiences.

Preferred qualifications

  • Strong academic background (advanced degree or equivalent experience) in IT, Computer Science, or related fields.
  • Certifications: OSCP, OSWE, OSEP, GXPN, GPEN, GWAPT, CRTP, eJPT, CREST, CISSP, or equivalent.
  • Published CVEs demonstrating research capability.
  • Bug bounty or Capture The Flag (CTF) experience.
  • Experience in AI/ML security research.
  • Advanced exploitation experience and custom tooling development.
  • Threat modeling and secure DevOps knowledge at enterprise scale.
  • Experience with AI-assisted security tooling (LLM pipelines, RAG, agentic workflows) for vulnerability discovery or triage.
  • Open-source contributions or technical writing on offensive security, DevSecOps, or AI security.

About Adobe

Adobe's Product and Software Security Team is looking for a Security Engineer with extensive penetration testing skills and strong DevSecOps experience. This role involves hands-on adversarial testing and integrating security throughout Adobe's software development lifecycle. The position includes assessing security in web, mobile, and desktop applications, cloud setups, AI/LLM systems, and supporting infrastructure. It also involves creating and maintaining security controls embedded in CI/CD p

View original posting