Product Security Engineer
Job Description
Adobe, in partnership with NextDeavor, offers a contract Product Security Engineer role on-site in Lehi, Utah. This position centers on triaging and validating external vulnerability reports, coordinating remediation with engineering teams, and contributing to the ongoing maturation of the bug bounty program. You will join a security-focused environment that values thorough analysis, clear communication, and cross-functional collaboration, with a competitive hourly rate of $67.61 to $84.51.
Responsibilities
- Review vulnerability submissions from the bug bounty platform, determining validity, potential impact, and scope.
- Apply CVSS v3.1 scores and severity levels according to internal guidelines and industry standards.
- Reproduce proof-of-concept exploits across web, API, and mobile surfaces to validate findings.
- Engage with external researchers to seek clarifications, share status updates, and manage expectations.
- Coordinate remediation with product engineering teams for confirmed vulnerabilities.
- Identify duplicates, out-of-scope, or informational reports and close them with clear explanations.
- Contribute to internal documentation, triage runbooks, and severity calibration guidelines.
- Flag systemic or critical findings to the Bug Bounty team for escalation.
Requirements
- At least three years of experience in application security, penetration testing, or a bug bounty/vulnerability disclosure role.
- Strong understanding of CVSS v3.1 and experience applying it to real-world vulnerabilities.
- Proficiency with common web vulnerability classes such as XSS, SQL injection, SSRF, IDOR, authentication flaws, and business logic issues.
- Ability to reproduce and validate PoC exploits using Burp Suite, browser DevTools, curl, and custom scripts.
- Familiarity with bug bounty platforms like HackerOne and Bugcrowd and with responsible disclosure processes.
- Solid written communication skills for clear, constructive responses to external researchers.
- Familiarity with attacker techniques targeting LLM systems and generative AI products.
- Knowledge of OWASP Top 10 vulnerabilities and mitigation techniques.
Technologies
- Burp Suite
- Browser DevTools
- curl
- HackerOne
- Bugcrowd
- AWS
- Azure
- GCP
Benefits
- Health insurance
- Vision insurance
- Dental insurance
- 401(k)
- Paid sick leave
To be considered, please submit your resume.