Product Security Engineer

Adobe Adobe · Enterprise · San Jose, CA

Product Security Engineer at Adobe focused on testing AI/ML and LLM-powered products. Responsibilities include reviewing AI-related penetration testing and bug bounty submissions, defining AI testing scope, driving resolution of security issues, building Security Testing reports, and communicating with external researchers. Requires strong application security knowledge, LLM testing methodologies, and hands-on experience in penetration testing AI/ML products.

What you'd actually do

  1. Review, verify, and reproduce AI-related penetration testing and bug bounty submissions, including distinguishing genuine AI risks from false positives.
  2. Define AI testing scope for penetration testing and bug bounty programs.
  3. Drive resolution of security issues through ongoing engagement with engineering teams.
  4. Build Security Testing reports for products to provide transparency into all security testing coverage and results.
  5. Communicate directly with external researchers regarding bug bounty reports on reported vulnerabilities.

Skills

Required

  • Application security vulnerabilities (OWASP Top 10)
  • LLM (Large Language Model) testing methodologies
  • Penetration testing of AI/ML and LLM-powered products
  • Develop and complete AI-specific test cases
  • Attacker techniques used by external researchers against LLM systems and generative AI products
  • Vulnerability assessments
  • Burp Suite

Nice to have

  • Automation and scripting

What the JD emphasized

  • AI-related penetration testing
  • AI testing scope
  • AI-specific test cases
  • LLM testing methodologies
  • penetration testing of AI/ML and LLM-powered products
  • attacker techniques used by external researchers against LLM systems and generative AI products

Other signals

  • AI/ML security testing
  • LLM testing methodologies
  • penetration testing of AI/ML products
  • AI-specific test cases
  • attacker techniques against LLM systems