Performs security assessments of company products that may include vulnerability and risk assessments, threat analysis, and security code reviews to identify potential design and implementation vulnerabilities. Designs and develops security features for products including systems, applications and/or solutions. Integrates new security features and updates into existing products and ensures the security of all products is maintained throughout the product lifecycle. Provides product security engineering recommendations and resolves integration and testing issues. Builds a standardized set of security product requirements and produces metrics to report performance against those requirements. Reviews and defines security diagnostics and tools to facilitate the analysis and reporting of security events. Detects and mitigates security risks, responds to product security incidents, and works with customers regarding product security related issues. Leads or participates in security architecture and design review meetings.
The Opportunity
Are you passionate about securing global systems and mitigating risks in a fast-paced environment? Adobe Security is looking for a dynamic candidate to join its Vulnerability Operation Center (VOC). As a VOC Product Security Engineer, you will analyze and prioritize incoming identified vulnerabilities and engage with developers for all of Adobe s products and online services. In this role, you will partner directly with pave the way for measuring, prioritizing, and reducing risk across Adobes suite of product offerings. This is a great opportunity to join in ground-breaking work to influence our organizations risk posture.
What youll Do
Validate and assess severity of public and privately disclosed security vulnerabilities
Drive security issues to resolution through continuous engagement with engineering teams
Develop reporting metrics for leadership that highlight risks and trends
Champion remediation efforts to Industry Wide Vulnerabilities and reducing preventable vulnerabilities
Identify security gaps and collaborate directly with product engineering teams on improved hardening opportunities
Investigate systemic vulnerability trends to improve product risk posture and reduce preventable vulnerabilities
What you need to succeed
Bachelor s degree or equivalent experience in computer science, engineering or a related subject area with 2-3 years of practical experience
Deep knowledge of infrastructure and application security vulnerabilities (OWASP Top 10) and mitigation techniques
Strong understanding of common security concepts that support root-cause analysis to make data-driven decisions on vulnerability patterns and trends
Dependability: Meets commitments, works independently, accepts accountability, handles change, sets personal standards, stays focused under pressure
Ability to speak and communicate professionally
Job Classification
Industry: IT Services & ConsultingFunctional Area / Department: IT & Information SecurityRole Category: IT SecurityRole: Security Architect / ConsultantEmployement Type: Full time