Behind the Scenes with John, Staff Security AI Engineer

Adobe's Cyber Defense Center (ACDC) sits at the front line of detecting and responding to threats across the company, working through a high volume of security signals every day. As that volume grows, AI agent workflows increasingly help handle routine tasks reliably, freeing analysts to focus on the judgment calls only people can make. Building those workflows well takes someone who understands, from experience, just how much that consistency is worth. John Gillis, Staff Security AI Engineer, has turned automation and AI into an equalizer: a way to get the small things right, consistently. Rather than letting his setbacks derail him, he made them the foundation of how he builds today.

In this blog, we'll take you behind the scenes to meet John to learn how he has navigated his career journey and discovered why the way his mind works became one of his biggest advantages.

Tell us about your career journey and background. What initially got you interested in cybersecurity?

I've always had a natural curiosity for how things work. As a kid, I was constantly trying to break video games poking at the code to see what I could make them do that they weren't supposed to. I broke a lot of computers growing up, too. So when it came time to decide what to do with my life, computer programming felt like the obvious starting point.

The thing is, I've never done well in school. I loved the idea of programming, but I hated learning it the way my college professors wanted me to, so I dropped it. I switched to physics and struggled there as well. Eventually I found my way onto an IT path, and that finally clicked. It was a great introduction to the field, and along the way I got into network security and administration.

I applied for an IT help desk job several times and got rejected over and over. I didn't land the role until a spot opened unexpectedly and the team needed someone to start the next business day. That's honestly been the trend of my whole life: I'm rarely successful right out of the gate. I have to fail a lot before I get any traction.

By the time I finished my bachelor's degree I had about a year and a half of IT experience, and I applied for an internship as a cybersecurity. Somewhere in that IT chapter, I fell in love with building solutions. My manager once asked me to prep for our semi-annual sales week, when our entire sales team flooded in from across the U.S. The help desk's job was to physically touch every single computer, and that did not sit well with me. I knew there had to be a better way, so I researched and set up a deployment server that did the whole job for us. We finished in less than half the time, with just two people watching the deployments run. That was the start of my love for automation. There's an incredible sense of accomplishment in watching your work translate directly into value for other people.

As I took on more challenging roles, I learned something about myself I hadn't known: I have Attention-Deficit / Hyperactivity Disorder (ADHD). I wasn't diagnosed until well into adulthood, but once I was, everything about my childhood and my schooling suddenly made sense. Throughout my career I've never been able to operate at the same level as my peers on raw effort alone. I figured out that if I could get a computer to handle the simple, repetitive things, it would handle them the same way every time, as long as I programmed it correctly. For someone with my kind of ADHD, doing something consistently by hand can be genuinely hard. But a computer doing those small things gave me the consistent results I needed to make better decisions.

That mentality is exactly what made me effective once I moved into cybersecurity. I'd automate tasks that looked tiny on their own – but automate enough of them and the return compounds, and it's all maintainable. Eventually that path led me to Adobe as a cybersecurity analyst, where I built a Chrome extension from the ground up that cut down the time analysts spent in their workflow. That project turned into a full-time automation role for our cyber defense center.

The jump from automation to building AI workflows for security analysts felt completely natural, because I'd done the analysts' jobs myself. I brought the same mentality I'd developed all the way back in IT. As it turns out, building good AI workflows is all about helping the AI do the small things really, really well.

What do you enjoy most about your current role?

I build AI agent workflows and help direct AI efforts for the Adobe Cyber Defense Center (ACDC). Day to day, that means I'm constantly building agentic workflows myself and helping others across the team build their own. I get to experiment, discover new ways of doing things, and improve the processes we already have in place.

Really, my job boils down to a simple loop: find a problem, nail the solution, then scale it. That's it. And honestly, that's the part I enjoy most. There's nothing quite like watching something you built take a painful, manual task off someone's plate and give them that time back. The same sense of accomplishment I felt setting up that first deployment server years ago is exactly what I get to chase every day now, just with far more powerful tools.

What is your favorite part about working at Adobe?

Adobe Security is vast – there's a little bit of everything here, which means there's always something new to dig into. More than anything, though, Adobe has given me the room to be creative and to build solutions that didn't exist anywhere else. Our leadership team has consistently encouraged me to think outside the box, and that's exactly the kind of support that led to our AI-driven Security Operations Center (SOC) capabilities.

What I appreciate most is the culture behind it. Even through my mistakes, people here have cheered me on rather than counted me out. That trust is what's allowed us to take big swings and accomplish some genuinely great things together. For someone whose whole career has been about failing a few times before getting it right, that's been the perfect place to land.

What is one piece of advice you would give to someone interested in pursuing a career in cybersecurity?

With AI, there's never been more opportunity to go above and beyond what's expected of a junior analyst. You have almost no limits on what you can learn or try – build the hack labs, research hard concepts, and lean on AI as a patient, around-the-clock tutor that's eager to teach you whatever you want to know.

But the thing that really sets you apart is having actual proof of what you've done. So go do things. Make a TikTok, an Instagram reel, or a YouTube short. Write a blog. Give a free lecture at your local library. Build something and show it. Be obsessed with helping and learning, and the opportunities will find you.

Finally, what is one thing people would be surprised to know about you?

People see the AI and automation work and assume things came easily to me. The truth is the opposite. I failed a lot. By every traditional measure, I was not the “natural talent” in the room.

What people might be surprised to know is that I've come to see all my failures as my biggest advantage. Somewhere along the way I stopped believing that ability is something you're simply born with – a fixed amount you either have, or you don't. I'm a firm believer in a growth mindset: that skill is built through effort, repetition, and a whole lot of failing forward. Every “no” and every bad score just taught me how to learn, adapt, and out-work the gap. If there's one thing I'd want people to take from my story, it's that you are not stuck with whatever you started with. Keep showing up, keep failing better, and you'll be amazed where it takes you.

Subscribe to the Security@Adobe newsletter

Don’t miss out! Get the latest Adobe security news and exclusive content delivered straight to your inbox.
Sign up