Senior Product Security Engineer

Adobe

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
San Jose, CA
Salary
$180,600–$261,450 / yr
Posted
7 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $181k
This role $221k
$125k most similar roles pay here $276k

This role pays more than 83% of similar roles. Most pay $151,493–$211,375 — the shaded band above. At the midpoint, this role pays about $221k versus about $181k for comparable roles.

Based on 240 similar postings.

Employer

About Adobe

Adobe Inc. is a global software company known for creative and multimedia software products including Photoshop, Illustrator, Acrobat, and its cloud-based Creative Cloud and Document Cloud suites. Industry: Creative & Digital Experience Software

Adobe currently has 218 open roles on FindRole.

Listed pay typically runs $187,100–$270,950 across 216 roles with salary data.

Most-posted roles

View all roles at Adobe

At a glance

TL;DR · Senior Product Security Engineer

Senior Product Security Engineer joins the Product and Software Security team as a frontline responder for external vulnerability reports from the bug bounty program. You will triage, validate, and reproduce proof-of-concept exploits across web, API, and mobile surfaces while assigning CVSS scores and severity ratings. The role involves managing automation workflows, coordinating with engineering teams for remediation, and developing PowerBI dashboards for data analysis. Key responsibilities include handling reports related to LLM systems and generative AI products. Required skills include expertise in OWASP Top 10, proficiency in Burp Suite, curl, and Python scripting, and experience with SOAR platforms and event-driven automation using AWS Lambda and API Gateway. You will also manage researcher communications and develop specific test cases for AI/ML powered products, including chat interfaces and inference APIs.

What you'll do

  • Triage, validate, and reproduce incoming vulnerability reports from the bug bounty platform across web, API, and mobile surfaces.
  • Assign CVSS scores and severity ratings to reported vulnerabilities based on internal guidelines and industry standards.
  • Communicate with external researchers to request clarifications, provide status updates, and manage expectations regarding their submissions.
  • Coordinate with product engineering teams to route confirmed vulnerabilities for timely remediation.
  • Develop PowerBI dashboards to support data-driven analysis and tracking of remediation efforts.
  • Create and maintain internal documentation, triage runbooks, and severity calibration guidelines.
  • Perform security testing on AI/ML and LLM-powered products, including chat interfaces and inference APIs.
  • Build and maintain automation workflows using SOAR platforms, Python scripts, and event-driven tools like AWS Lambda.

What we're looking for

  • Bachelor’s degree or equivalent experience in Computer Science, Engineering, or a related field.
  • 5+ years of practical experience in security testing and vulnerability management.
  • In-depth knowledge of OWASP Top 10 vulnerabilities and mitigation techniques.
  • Hands-on experience applying CVSS v3.1 scoring to real-world vulnerabilities.
  • Proficiency in reproducing PoC exploits using Burp Suite, browser DevTools, curl, and custom scripts.
  • Experience with penetration testing of AI/ML and LLM-powered products including chat interfaces and inference APIs.
  • Proficiency in Python for writing production-quality integration code and experience with SOAR platforms.
  • Expertise in event-driven automation using webhooks, AWS Lambda, and API Gateway.

More like this

Similar roles

Senior Product Security Engineer

Cloudflare, Inc

Austin, TX 51 days ago
Product Security Application Security AI LLM Threat Modeling STRIDE Vulnerability Management SAST Fuzzing Penetration Testing Bug Bounty JIRA Agile SaaS Distributed Systems
Hybrid

Senior Security Engineer I, Product Security

Oscar Health

Los Angeles, CA 7 days ago
Application Security SAST DAST Vulnerability Management AI Integration Model Context Protocol (MCP) Source Code Review Risk Assessment Software Development
4+ yrs exp Hybrid

Senior Security Engineer I, Product Security

Oscar Health

Tempe, AZ 7 days ago
SAST DAST SDLC Vulnerability Management Code Review AI Integration Model Context Protocol (MCP) Software Development Risk Assessment Source Code Review
4+ yrs exp Hybrid

Senior Security Engineer I, Product Security

Oscar Health

Remote (San Francisco, CA) 7 days ago
Application Security SAST DAST Vulnerability Management AI Integration Model Context Protocol (MCP) Code Review Risk Assessment Software Development
4+ yrs exp Remote

Senior Product Security Engineer I

Oscar Health

New York, NY 57 days ago
Application Security SAST DAST Vulnerability Management AI Integration Model Context Protocol (MCP) Code Review Risk Assessment Software Development
4+ yrs exp Hybrid

Product Security Engineer

Cloudflare, Inc

Austin, TX 38 days ago
Application Security LLM SAST Fuzzing Penetration Testing Threat Modeling STRIDE Bug Bounty Triage JIRA Agile Vulnerability Management SaaS
5+ yrs exp Hybrid