23 hours ago
Base Salary
$145k - $261k/yr
Responsibilities
- Triage, validate, reproduce, and assess external vulnerability reports submitted through the bug bounty platform.
- Assign CVSS scores and severity ratings according to internal guidelines and industry standards.
- Reproduce proof-of-concept exploits across web, API, mobile, AI/ML, and LLM-powered products.
- Communicate with external researchers, request clarifications, provide updates, and explain duplicate, informational, or out-of-scope decisions.
- Coordinate confirmed vulnerabilities with product engineering teams for remediation.
- Maintain triage runbooks, internal documentation, and severity calibration guidelines.
- Support live hacking events, campaigns, and challenges, and escalate systemic or critical findings.
- Develop PowerBI dashboards and build or extend security automation workflows and integrations.
Requirements
- Bachelor’s degree or equivalent experience in Computer Science, Engineering, or a related field, plus 5+ years of practical experience.
- In-depth knowledge of application security vulnerabilities, including the OWASP Top 10, and their mitigations.
- Strong understanding and hands-on application of CVSS v3.1 scoring.
- Proficiency with XSS, SQL injection, SSRF, IDOR, authentication flaws, business logic issues, and proof-of-concept validation.
- Experience using Burp Suite, browser DevTools, curl, and custom scripts to reproduce exploits.
- Familiarity with bug bounty platforms and responsible disclosure processes.
- Experience with attacker techniques and testing methodologies for LLM systems, generative AI products, agentic workflows, chat interfaces, and inference APIs.
- Hands-on penetration testing experience for AI/ML and LLM-powered products, including designing AI-specific test cases.
- Proficiency with JIRA, PowerBI, and Python.
- Experience with SOAR or orchestration platforms, including app connectors, playbooks, and action-based automation models.
- Ability to implement API integrations using REST documentation or OpenAPI/Swagger specifications, OAuth2, bearer tokens, API keys, pagination, and error handling.
- Hands-on experience with webhooks, AWS Lambda, and API Gateway for event-driven automation.
- Strong written, verbal, and professional communication skills, with the ability to work independently and remain accountable under pressure.
About Adobe
Adobe empowers everyone, everywhere to imagine, create, and bring any digital experience to life. From creators and students to small businesses, global enterprises, and nonprofit organizations — customers choose Adobe products to ideate, collaborate, be more productive, drive business growth, and build remarkable experiences.
