11 hours ago
Bengaluru, IndiaSenior
Responsibilities
- Perform penetration testing against AI/LLM systems, web applications, APIs, mobile applications, cloud infrastructure, containers, and supporting infrastructure.
- Identify and exploit authentication, authorization, business logic, injection, SSRF, deserialization, and chained vulnerabilities.
- Embed SAST, DAST, SCA, secrets scanning, and container/image scanning into CI/CD pipeline gates.
- Build and operate DevSecOps automation, policy-as-code, infrastructure-as-code scanning, and cloud security guardrails across AWS, Azure, and GCP.
- Develop scripts and security tooling with Python, Go, PowerShell, Bash, or JavaScript.
- Collaborate with engineering teams on threat modeling, security code review, and secure-by-default architecture.
- Deliver risk evaluations, actionable reports, remediation mentorship, and preventive controls for engineering and product teams.
- Manage penetration testing engagements from prioritization through execution and delivery.
- Research AI/ML exploits, cloud-native attack techniques, supply-chain risks, and improved testing methodologies.
Requirements
- 4–6 years of combined penetration testing and DevSecOps experience, with meaningful depth in both areas.
- Hands-on penetration testing experience across web applications, APIs, mobile applications, and cloud environments.
- Production experience integrating SAST, DAST, SCA, secrets scanning, and container/image scanning into CI/CD pipelines.
- Understanding of AI/ML security, LLM vulnerabilities, OWASP Top 10, OWASP API Top 10, and OWASP LLM Top 10.
- Programming or scripting experience in at least one of Python, Bash, PowerShell, Go, or JavaScript.
- Ability to read source code, trace execution flows, and dynamically exploit vulnerabilities.
- Knowledge of secure coding practices, code-level vulnerabilities, attack vectors, exploits, and chained attacks.
- Extensive cloud security experience with AWS, Azure, or GCP and container technologies such as Docker and Kubernetes.
- Familiarity with Terraform, CloudFormation, and policy-as-code frameworks.
- Preferred qualifications include an advanced degree or equivalent experience in IT, Computer Science, or a related field; relevant security certifications; published CVEs; bug bounty or CTF experience; AI/ML security research; advanced exploitation and custom tooling; enterprise-scale threat modeling and secure DevOps; AI-assisted security tooling; open-source contributions; or technical writing.
Tech Stack
Categories
About Adobe
Adobe builds software for creative work, document workflows, and customer experience used by individuals, teams, and enterprises. Its products include Creative Cloud (Photoshop, Illustrator, Premiere Pro), Acrobat/Document Cloud, and Experience Cloud for marketing and analytics, sold primarily via subscriptions. Founded in 1982 and headquartered in San Jose, California, Adobe is a public company traded on NASDAQ under the ticker ADBE.
