Jobs / United States / Adobe INC

Senior Product Security Engineer

Adobe INC · 🇺🇸 San Jose

Sponsorship verdict

Sponsorship possible

One solid signal, not two — worth applying, and worth asking about sponsorship early.

  • Employer is on a government sponsor recordThe US Department of Labor certified 1,036 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 221 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
  • The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
  • No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
  • What Adobe INC paid sponsored hires in similar roles2 certified filings for “Product Security Engineer (118.3010.14)” (Information Security Analysts) in VA: $100k–$123k, median $111k. Most were filed at wage level I (50%) — 1 lottery entry, ≈15% projected selection odds for cap-subject employers. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
  • Confirmed live todayWhen a source last listed this job as open.

US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).

A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.

Start free →

Or apply yourself on the official page →

Sponsor Radar — Adobe INC

1,036 H-1B filings certified since Oct 2025

The US Department of Labor certified 1,036 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 221 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).

Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Adobe INC →

About the role

Job Description: Senior Product Security Engineer The Opportunity Are you passionate about product security testing and vulnerability management? Adobe Product and Software Security is seeking a dynamic candidate with strong security testing expertise to join our expanding team. In this role, you will be the frontline responder for external vulnerability reports submitted through the Bug Bounty program, working closely with internal engineering and security teams to ensure timely, accurate triage and resolution, managing automation workflows, supporting live hacking events, campaigns, challenges. This is a great opportunity to contribute to innovative work that will elevate Adobe Security to new heights! What You'll Do • Triage, validate and reproduce incoming vulnerability reports submitted via the bug bounty platform, assessing validity, impact, and scope, including AI related reports. • Assign CVSS scores and severity ratings accurately, following Adobe’s internal severity guidelines and industry standards. • Reproduce proof-of-concept (PoC) exploits to validate reported vulnerabilities across web, API, and mobile surfaces. • Communicate clearly and professionally with external researchers: request clarifications, provide status updates, and manage expectations. • Coordinate with product engineering teams to route confirmed vulnerabilities for remediation. • Identify duplicate, out-of-scope, or informational reports and close them with clear, respectful explanations. • Contribute to internal documentation, triage runbooks, and severity calibration guidelines. • Flag systemic or critical findings to Bug Bounty team for partner concern as needed. • Develop dashboards in PowerBI to support data-driven analysis and remediation efforts. What You Need to Succeed • Bachelor’s degree or equivalent experience in Computer Science, Engineering, or a related field, with 5+ years of practical experience. • In-depth knowledge of application security vulnerabilities (OWASP Top 10) and mitigation techniques. • Strong understanding of CVSS v3.1 scoring and hands-on experience applying it to real-world vulnerabilities. • Proficiency in common web vulnerability classes: XSS, SQL injection, SSRF, IDOR, authentication flaws, and business logic issues. • Ability to reproduce and validate PoC exploits using tools such as Burp Suite, browser DevTools, curl, and custom scripts. • Familiarity with bug bounty platforms and responsible disclosure processes. • Solid written communication skills — able to write clear, constructive responses to researchers of all skill levels. • Familiarity with attacker techniques used by external researchers against LLM systems and generative AI products. • Proficiency with JIRA and PowerBI. • Strong knowledge of LLM (Large Language Model) testing methodologies. • Hands-on experience in penetration testing of AI/ML and LLM-powered products, including chat interfaces, agentic workflows, and inference APIs. • Ability to design and complete AI-specific test cases. • Experience with attacker techniques used by external researchers against LLM systems and generative AI products. • Experience with a SOAR/orchestration platform (building or extending app connectors and playbooks, understanding action-based automation models) • API integration literacy (can read a vendor's REST API docs or an OpenAPI/Swagger spec and correctly implement authentication (OAuth2, bearer tokens, API keys), pagination, and error handling) • Scripting proficiency in Python (comfortable writing and maintaining small, production-quality integration code) • Event-driven automation (hands-on experience with webhooks, AWS Lambda, and API Gateway, turning real-time platform events into automated downstream actions) • Dependability:

View the official posting →

Source: Employer career site (Workday) First seen: 2026-09-04 Last confirmed: 2026-10-02 How our data works → Report this job

Similar opportunities