Nitesh Bhatter

AI Researcher

Sunnyvale, California, United States16 yrs 8 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Led security strategy for Adobe Document Cloud.
  • Managed successful bug bounty programs on HackerOne and Bugcrowd.
  • Developed AI-powered security tooling for proactive threat monitoring.
Stackforce AI infers this person is a SaaS Security Engineer with expertise in compliance and AI-driven security automation.

Contact

Skills

Core Skills

Security Architecture DesignCyber-security

Other Skills

Mobile SecurityPayment Card Industry Data Security Standard (PCI DSS)Web Application Security AssessmentNetwork SecurityGovernance, Risk Management, and Compliance (GRC)Red TeamCloud SecurityWeb Application SecurityDevSecOpsApplication SecurityComplianceThreat ModelingBug Bounty ManagementCollaborationApplication Security Architecture

About

I'm a Security Engineer at Adobe focused on Document Cloud — covering Acrobat Web, PDF Services, PDF Spaces, and GenAI features. My work spans the full security lifecycle: threat modeling , PSIRT ticket reviews, vulnerability remediation, and shift-left security enforcement across product teams. I collaborate with GRC stakeholders to maintain compliance alignment with PCI, HIPAA, ISO, and other regulatory frameworks — and work with executive leadership to communicate risk posture and support data-driven security decisions. Outside of Adobe, I build AI-powered security tooling — including an automated recon framework (built with Claude AI) that continuously monitors external attack surfaces and has surfaced confirmed production findings. I also run a CVE hunting pipeline that led to a confirmed vulnerability submission to open source projects. I'm active on Bugcrowd and HackerOne, with findings including SQL injection, subdomain takeover, and DNS misconfiguration vulnerabilities. My goal is simple: keep Document Cloud a secure, resilient, and trusted platform — and push the boundaries of what security engineering can do with AI-driven automation.

Experience

16 yrs 8 mos
Total Experience
5 yrs 6 mos
Average Tenure
11 yrs 7 mos
Current Experience

Adobe

3 roles

Senior Staff Security Researcher / Lead Security Researcher - Adobe Document Cloud

Promoted

Jan 2022Present · 4 yrs 3 mos

  • As a technical Head of Security for Adobe Document Cloud, I lead end-to-end security strategy and execution across application and infrastructure layers, while ensuring compliance and supporting customer assurance at scale. My role bridges deep technical expertise with cross-functional leadership to drive secure innovation across web and mobile platforms (iOS and Android).
  • Security Architecture & Threat Modeling:
  • I oversee threat modeling and security architecture reviews for core Document Cloud applications, embedding security into the development lifecycle and mitigating design-level risks early.
  • Compliance & Regulatory Alignment:
  • Partnering with internal governance, risk, and compliance (GRC) teams as well as external auditors, I support certifications such as PCI, HIPAA, and FedRAMP, providing the evidence and controls needed to meet rigorous regulatory requirements.
  • Customer Assurance & Trust:
  • I serve as a trusted advisor to customers, articulating our security posture, explaining control implementations, and addressing concerns to support enterprise adoption and maintain customer confidence.
  • Application & Cloud Security Testing:
  • Hands-on experience leading and executing both static and dynamic penetration tests across web and mobile applications, including secure DevOps reviews for AWS and Azure environments.
  • Red Teaming & Offensive Testing:
  • Drive red teaming initiatives across Document Cloud and broader Adobe services to simulate real-world attack scenarios and harden defenses through continuous adversarial testing.
  • Security Research Collaboration:
  • Actively engage with external researchers and Adobe’s PSIRT team to triage and remediate vulnerabilities in accordance with Adobe’s security standards.
  • Bug Bounty Leadership:
  • Lead the Document Cloud bug bounty program on HackerOne and Bugcrowd, managing researcher relations, triage, and secure remediation processes in collaboration with engineering teams.
Mobile SecurityPayment Card Industry Data Security Standard (PCI DSS)Security Architecture DesignWeb Application Security AssessmentNetwork SecurityGovernance, Risk Management, and Compliance (GRC)+6

Staff Security Researcher - Product Security Lead - Document Cloud

Promoted

Feb 2019Dec 2021 · 2 yrs 10 mos

  • Work as a product security lead for one or more product teams providing expertise in:
  • Customer Relation - Working with customers to answer their security questions and help them understand security controls are in place for Document Cloud services.
  • Compliance / Legal and Privacy - Working with internal GRC team (Governance Risk and compliance), and external auditors to provide necessary information needed for compliance certifications PCI, HIPAA, FedRamp etc.
  • Hands on Web and Mobile automated and manual pentest for various Adobe services.
  • AWS and Azure - network security review and pentest (DevSecOps role)
  • Red Teaming exercise for Document Cloud and Adobe services .
  • Performing threat modeling for web and mobile (iOS and Android) applications. Working with Google and Apple to make sure Adobe applications are in compliance with Google Play store and Apple store policies.
  • Working with external security researchers and PSIRT team to triage the findings and making sure to get remediate in a timely manner based on Adobe standards.
  • Running bug bounty program on HackerOne and Bugcrowd for Document Cloud services and working with external security researchers to provide all necessary information, triage the findings etc.
Cyber-security

Information Security Engineer

Jul 2014Jan 2019 · 4 yrs 6 mos

  • Work as a security engineer / security researcher for one or more product teams, providing expertise in threat modeling, manual pentest, red teaming, network scan, vulnerability assessments, iOS/Android mobile apps review/pentest and conformance with good security practices and corporate governance.
Cyber-security

Cigital, inc

4 roles

Senior Security Consultant

Promoted

Jul 2013Jul 2014 · 1 yr

  • Worked in Cigital Inc.( http://www.cigital.com/ ) as a senior security consultant.
  • Specialties: web application security, network penetration testing, mobile assessment, threat modeling, wireless assessment.
Cyber-security

Security Consultant

Oct 2011Jun 2013 · 1 yr 8 mos

  • Worked in Cigital Inc.( http://www.cigital.com/ ) as a security consultant. I got an experience in the manual and automated web application penetration testing, Mobile penetration testing( Android and iPhone) and source code review.
Cyber-security

Associate Security Consultant

Jan 2011Oct 2011 · 9 mos

  • Hands on experience with various source code review tools IBM Appscan source edition, Fortify SCA, CAT.NET 2.0 and Fxcop 10.0 etc. Got security training on software security assessment, reverse engineering, mobile penetration testing etc.
  • Other tools hands on experience: Burp Suite, Fiddler, WebScarab, Metasploit, w3af, Paros proxy, SQL MAP, HP WebInspect, IBM Security AppScan Standard
Cyber-security

Internship

Jun 2010Dec 2010 · 6 mos

  • It was a great learning experience. Hands on experience in various source code analysis tools: Fortify SCA, IBM Appscan, Fxcop, Cat.NET etc. Also learn to perform threat modeling for the applications. I also got an experience in the manual and automated web application penetration testing.

Sans institute

Course Facilitator

Jun 2010Jul 2010 · 1 mo

  • I got an opportunity to work with Joshua Wright to learn and explore techniques attackers use to exploit WiFi networks, including attacks against WEP, WPA/WPA2, PEAP, TTLS, and other systems. Also examined the commonly overlooked threats associated with Bluetooth, WiMAX, and proprietary wireless systems. Using the SWAT toolkit etc.
  • Joshua website: http://www.willhackforsushi.com/

Johns hopkins university

3 roles

Research Assistant

Feb 2010May 2010 · 3 mos

  • I was working as a research assistant under Gerald Masson (http://www.cs.jhu.edu/~masson/).

Teaching Assistant, Network Security Course

Jan 2010May 2010 · 4 mos

  • I got an opportunity to work as a teaching assistant in network security course. My job was to answer student doubts regarding their network security projects, grade their assignments and source code review of the projects.
  • http://courses.isi.jhu.edu/netsec/

Study consultant and Teaching assistant

Jan 2009Nov 2009 · 10 mos

  • I was working as a study consultant at Johns Hopkins University. My job was to help students regarding their academic concerns such as time management,note taking,study skills,test Anxiety,activity management,test preparation.

Education

The Johns Hopkins University

MS — Computer Science

Jan 2009Jan 2010

The Johns Hopkins University

MS — Infromation Security

Jan 2008Jan 2009

Nagpur University

Bachelor of Engineering (BE) — Electronics Engineering

Jan 2004Jan 2007

St. Joseph School

HSC

Jan 2002Jan 2004

Stackforce found 100+ more professionals with Security Architecture Design & Cyber-security

Explore similar profiles based on matching skills and experience