AD
Product Security Engineer 3
Adobe · Bangalore
experiencedBangalorePosted 10 Sept 2026
This listing is from the archive and may be closed. Browse the latest experienced jobs for current openings.
Adobe is hiring a Product Security Engineer 3 in Bangalore.
Responsibilities
- Perform penetration testing on AI/LLM systems (timely injection, model poisoning, jailbreaks, etc.), web applications, APIs, mobile apps, cloud infrastructure, containers, and supporting infrastructure.
- Identify and take advantage of vulnerabilities including authentication/authorization flaws, business logic issues, injection, SSRF, deserialization, and chained attacks.
- Embed security controls into CI/CD pipelines: SAST, DAST, SCA, secrets scanning, and container/image scanning as outstanding pipeline gates.
- Build and operate DevSecOps automation across cloud environments (AWS, Azure, GCP): policy-as-code, infrastructure-as-code scanning, and automated security guardrails.
- Develop custom scripts and tooling using Python, Go, or PowerShell to automate testing, validation, and pipeline integration.
- Collaborate with engineering teams on threat modeling, security code review, and secure-by-default architecture.
- Build the feedback loop from security findings back into preventive controls so the same class of bug doesn't ship twice.
- Deliver clear, actionable reports and provide remediation mentorship to engineering and product teams.
- Manage the full lifecycle of penetration testing engagements from prioritisation to execution and delivery.
- Research emerging AI/ML exploits, cloud-native attack techniques, and supply chain risks to stay ahead of threats.
- Improve testing methodologies and contribute to the internal knowledge base.
Requirements
Experience & Skills
- 4-6 years of combined experience in penetration testing and DevSecOps, with meaningful depth in both — not just one.
- Hands-on pentest experience across web apps, APIs, mobile, and cloud environments. You can find and exploit, not just scan and report.
- Demonstrated experience incorporating security tools (SAST, DAST, SCA, secrets, container/image scanning) into CI/CD pipelines within live production settings.
- Understanding of AI/ML security, LLM vulnerabilities, and timely engineering attacks.
- Strong knowledge of OWASP Top 10, OWASP API Top 10, and OWASP LLM Top 10.
- Programming/scripting in at least one language: Python, Bash, PowerShell, Go, JavaScript.
- Ability to read and understand source code, trace execution flows, and dynamically exploit vulnerabilities during live assessments.
- Understanding of secure coding practices and common code-level vulnerabilities.
- Extensive background in cloud security (AWS, Azure, GCP) and container technologies (Docker, Kubernetes).
- Familiarity with infrastructure-as-code (Terraform, CloudFormation) and policy-as-code frameworks.
- Understanding of attack vectors, exploits, vulnerability exploitation, and chained attacks.
- Strong written and verbal communication skills with ability to explain findings to technical and non-technical audiences.
Preferred qualifications
- Strong academic background (advanced degree or equivalent experience) in IT, Computer Science, or related fields.
- Certifications: OSCP, OSWE, OSEP, GXPN, GPEN, GWAPT, CRTP, eJPT, CREST, CISSP, or equivalent.
- Published CVEs demonstrating research capability.
- Bug bounty or Capture The Flag (CTF) experience.
- Experience in AI/ML security research.
- Advanced exploitation experience and custom tooling development.
- Threat modeling and secure DevOps knowledge at enterprise scale.
- Experience with AI-assisted security tooling (LLM pipelines, RAG, agentic workflows) for vulnerability discovery or triage.
- Open-source contributions or technical writing on offensive security, DevSecOps, or AI security.
About Adobe
Adobe's Product and Software Security Team is looking for a Security Engineer with extensive penetration testing skills and strong DevSecOps experience. This role involves hands-on adversarial testing and integrating security throughout Adobe's software development lifecycle. The position includes assessing security in web, mobile, and desktop applications, cloud setups, AI/LLM systems, and supporting infrastructure. It also involves creating and maintaining security controls embedded in CI/CD p