Senior Product Security Engineer

Adobe Adobe · Enterprise · San Francisco, CA +5

Senior Product Security Engineer to scale security capabilities across software supply chain, Kubernetes deployment environments, and cloud-native systems. Focus on securing the SDLC, strengthening supply chain integrity, and embedding security into delivery pipelines with automation-first, secure-by-default approaches. Operate as a security expert, influencing engineering organizations, designing scalable security solutions, and managing risk across complex, cloud-native systems.

What you'd actually do

  1. Develop and implement security controls across CI/CD platforms including GitHub Actions workflows, Jenkins, and other internal build systems.
  2. Establish secure-by-default pipeline standards covering build isolation, artifact integrity, secrets management, and least-privilege access.
  3. Identify systemic software supply chain risks, design scalable mitigations, and drive adoption of them to prevent entire classes of vulnerabilities.
  4. Secure Kubernetes-based deployment platforms across multi-cloud environments.
  5. Define security baselines for Kubernetes clusters, workloads, container runtimes, admission controls, and network segmentation.

Skills

Required

  • Bachelor’s degree in Computer Science, Engineering, or related field of study.
  • 6+ years of experience in Product Security, Application Security, Cloud Security, or a related field.
  • Experience threat modeling for CI/CD and cloud-native systems.
  • Deep expertise in CI/CD systems such as GitHub Actions, Jenkins, GitLab CI, or similar platforms.
  • Strong experience securing Kubernetes and containerized workloads in cloud-native environments.
  • Hands-on knowledge of software supply chain security, artifact signing, and open-source risk management.
  • Experience implementing GitOps workflows and securing infrastructure-as-code (Terraform, CloudFormation, etc.).
  • Strong programming or scripting ability (e.g., Python, Go, Bash) with experience building automation and security tooling.
  • Demonstrated ability to identify systemic risks and design scalable, automation-first mitigations.
  • Strong understanding of Secure SDLC practices and how security solutions reduce risk across large organizations.
  • Proven ability to influence engineering teams and serve as a technical leader without formal management authority.

What the JD emphasized

  • security controls
  • supply chain integrity
  • automation-first
  • secure-by-default
  • Kubernetes
  • cloud-native systems
  • systemic software supply chain risks
  • scalable mitigations
  • secure Kubernetes-based deployment platforms
  • security baselines for Kubernetes clusters
  • security architecture reviews
  • security risk
  • security solutions
  • security advisor
  • domain expert in CI/CD, supply chain, and cloud security
  • threat modeling for CI/CD and cloud-native systems
  • software supply chain security
  • open-source risk management
  • security solutions reduce risk