Commerce - Security Engineering Manager

• Minimum 3 years of engineering management or technical leadership experience, preferably in security-focused roles

• Proven track record of managing teams responsible for security initiatives, vulnerability remediation, or application security

• Experience managing complex, multi-stakeholder technical programs involving security or quality engineering

• Previous involvement in security incident response, vulnerability disclosure programs, or coordinated patch releases

• Background in e-commerce platforms, web application security, or similar complex software environments is highly desirable Technical Skills & Security Knowledge

• Strong understanding of Adobe Commerce/Magento architecture and technology stack (PHP, JavaScript, MySQL)

• Deep knowledge of application security principles relevant to web applications and e commerce platforms

• Understanding of common vulnerability classes (OWASP Top 10, SQLi, XSS, RCE, authentication bypasses, CSRF, etc.

• Familiarity with security assessment methodologies and vulnerability analysis approaches

• Knowledge of secure SDLC practices and how to integrate security into development processe

• Understanding of version control workflows, branching strategies, and release management for security patches

• Awareness of security scanning tools and their role in vulnerability detection (SAST, DAST, SCA)

• Knowledge of cryptography, authentication/authorization mechanisms, and secure architecture patterns

• Understanding of compliance frameworks relevant to e-commerce (PCI-DSS, SOC 2, etc.) Leadership & Communication

• Strong problem-solving skills and the ability to work collaboratively in a dynamic team environment

• Excellent communication skills for explaining complex security issues to both technical


We are seeking an experienced Security Engineering Manager to lead our Product Vulnerability Patching team at Adobe. This role uniquely blends security expertise with engineering leadership, requiring someone who can navigate complex vulnerability landscapes while managing the intricate orchestration of patches across multiple release lines. The ideal candidate brings a security-first mindset to team operations, technical decision-making, and cross-functional collaboration.