Security Partnership Senior Product Engineer

Adobe Adobe · Enterprise · Bucharest, Romania

This role focuses on enhancing product security within Adobe by conducting security assessments, threat modeling, and code reviews, and by providing security recommendations and education to product engineering teams. It involves collaborating with various teams to integrate security practices into the development lifecycle and staying updated on security threats and mitigations.

What you'd actually do

  1. Analyze security risks using real-world security data and systems automation.
  2. Conduct security evaluations, encompassing vulnerability and risk assessments.
  3. Perform threat modeling, code evaluations, security examinations, and risk appraisals.
  4. Provide product security engineering recommendations and resolve integration and testing issues.
  5. Maintain up-to-date knowledge related to security threats, vulnerabilities, and mitigations; circulate this knowledge throughout the business units.

Skills

Required

  • Graduate degree in computer science, engineering, cybersecurity, or a related field, or a bachelor's degree with extensive experience in a threat modeling security role exceeding 8 years.
  • At least three years of experience working alongside corporate executives and participating in large-scale projects with previous involvement in an engineering and software development company and familiarity with the Secure Development Lifecycle.
  • Outstanding organization skills, strong planning skills, communication skills, and high attention to detail.
  • Proven track record building technical rapport and enduring relationships within diverse teams.
  • Proficient knowledge of public cloud infrastructure and architecture (AWS, Azure, GCP) along with relevant security concepts and obstacles.
  • Mastery in core security principles, techniques, and recognized standards such as authentication, permissions, documentation, standards, data oversight, and software lifecycle.
  • Proficient understanding of application and operations security vulnerabilities (such as OWASP Top 10) and methods for addressing them.
  • Ability to multitask and switch between multiple high urgency projects.
  • Experience with security issues in mobile and desktop applications.
  • Experience with emerging threats, mitigations, and industry trends.
  • Familiarity with industry standard methodologies in application & operations security.
  • Familiarity with Lean Enterprise/Agile/DevOps/SecDevOps development methodologies is required.
  • Extensive background in collaborating with SaaS/cloud-based offerings.
  • Familiarity and background using standard security tools like Kali Linux, Nessus, Qualys, BurpSuite, and more.
  • Solid knowledge and understanding of containerized applications: Docker, OpenShift, Kubernetes, etc.
  • Industry Certifications such as CISSP, CASP+, CISM, CISA, GCIH, CFCE, GCFA, and/or GCFE, or equivalent job experience.

Nice to have

  • The position requires speaking publicly to senior leadership and customers.
  • Driven and excellent at communicating with others.

What the JD emphasized

  • extensive experience in a threat modeling security role exceeding 8 years
  • familiarity with the Secure Development Lifecycle
  • Mastery in core security principles
  • Proficient understanding of application and operations security vulnerabilities
  • Familiarity with industry standard methodologies in application & operations security
  • Familiarity with Lean Enterprise/Agile/DevOps/SecDevOps development methodologies is required