Senior Application Security Engineer (Offensive / Red Team)
$128k - $181.25kShutterfly
Senior Application Security Engineer (Offensive / Red Team)
At Shutterfly, we make life's experiences unforgettable. We believe there is extraordinary power in the self-expression. That's why our family of brands helps customers create products and capture moments that reflect who they uniquely are.
This is an exciting time for Shutterfly, and we are looking for a Senior Application Security Engineer (Offensive / Red Team) to join our team. In this role you will help shape an evolving offensive security practice, leading Red Team engagements against Shutterfly's critical applications while partnering closely with our Blue Team throughout each engagement to produce Purple Team outcomes — stronger detections, faster response, and measurably improved defenses. We're looking for someone who is as passionate about uncovering and exploiting a vulnerability as they are about working alongside defenders to make sure it can be detected, contained, and remediated. Just as important, you'll partner with developers and engineering teams to educate them on how to prevent and avoid vulnerabilities in the first place, and guide them on how to fix issues once identified. Your focus will be on building an offensive security capability that strengthens the entire security program, with collaboration between offense, defense, and engineering at its core. Note: We are unable to provide any visa sponsorship for this position at this time.
What You'll Do Here:
- Red Team Operations: Plan and lead offensive engagements against Shutterfly's applications and supporting infrastructure using established offensive and testing techniques — manual web penetration testing, exploitation, fuzzing, and adversary emulation supported by industry-standard offensive tooling — and coordinate with third-party testers when engagements call for it.
- Purple Team Collaboration: Work hand-in-hand with the Blue Team throughout every engagement. Share tactics, techniques, and procedures in real time, validate and improve detection and alerting coverage, run collaborative exercises, and convert offensive findings into concrete defensive improvements.
- AI-Driven Offensive Security: Augment conventional offensive techniques with AI and LLM-based tooling to accelerate and extend offensive and testing work — reconnaissance, payload and test-case generation, code and configuration review, and exploitation.
- Maintain a working understanding of how threat actors are weaponizing AI, and fold that knowledge into engagements and defensive recommendations to keep pace with a rapidly changing threat landscape.
- Bug Bounty Program Management: Manage the bug bounty program end to end — triage, impact assessment, risk scoring (CVSS), locating vulnerable code, providing mitigation guidance, thorough re-testing, and refining program policy and scope as needed.
- Vulnerability Management: Identify, triage, and drive remediation of application vulnerabilities through manual testing and exploitation, escalating systemic issues to the appropriate engineering teams.
- Threat Modeling & Risk Assessment: Lead threat modeling exercises and perform risk assessments for new and existing applications, using offensive insight to prioritize the risks that matter most.
- Incident Response: Collaborate with incident response and Blue Team partners to investigate application-related security incidents, applying offensive expertise to scope, reproduce, and understand attacker activity.
- Secure SDLC: Help define and reinforce secure development practices, including code reviews and integration of security checks into the CI/CD pipeline.
- Code Review: Perform and lead security reviews of critical PRs and code changes, and review code in most major languages.
- Security Architecture & Design: Partner with engineering and architecture teams to advise on secure systems and applications design, ensuring security is built in from the ground up.
- Subject Matter Expertise: Serve as a top technical resource to engineers across the organization. Help them reproduce vulnerabilities, understand impact, document issues, and validate the effectiveness of fixes.
- Mentorship & Leadership: Mentor junior security engineers and developers on offensive techniques, secure coding practices, and security principles. Build relationships with stakeholders and business leaders across the organization.
- Cross-Functional Collaboration: Work closely with product, engineering, DevOps, defensive security, and compliance teams to align security with business goals.
- Continuous Improvement: Maintain up-to-date knowledge of relevant offensive techniques, threats, mitigations, security best practices, and the evolving role of AI in both offensive operations and adversary activity.
- Security Tooling: Make effective use of the existing security tooling stack (e.g., SAST, SCA, DAST, IAST) to support offensive and defensive work.
Required Qualifications:
- Bachelor's degree in computer science, cybersecurity, or a related technical field, or comparable hands-on experience in lieu of a degree.
- Demonstrated experience leading or performing offensive security work, such as web application penetration testing or Red Team engagements, with hands-on proficiency in conventional offensive and testing techniques and industry-standard offensive tooling. Hands-on experience using AI/LLM tools for offensive security or testing, with an understanding of how threat actors are leveraging AI in a rapidly evolving threat landscape.
- Proficient in one modern programming language (preferably Java) and able to review code in most major languages.
- Strong analytical and problem-solving abilities with a risk-based security approach.
- Advanced user of Burp Suite Pro; bonus if you have created custom extensions in Java or Python or have used or modified existing extensions.
- Excellent communication and collaboration skills, with the ability to work across offensive and defensive teams, IT, engineering, and business stakeholders.
Preferred Qualifications:
- Experience running Purple Team exercises or otherwise collaborating directly with defensive/Blue Team functions to improve detection and response.
- Full stack web development experience within an active security program.
- Experience managing a bug bounty program.
- A security certification that demonstrates proficiency in offensive security, network/web/mobile/AD assessments, secure coding, and professional report creation (for example: OSCP, OSEP, CRTO, OSWA, OSWE, GWAPT, GWEB).
- Submitted reports to bug bounty programs or VDPs, and you've found a CVE along the way.
- Strong command-line and scripting skills (bash, zsh, Python) on Linux and Mac.
- Enjoy attending security conferences and occasionally participate in CTFs.
- Spend time on cyber security training platforms (HackTheBox, TryHackMe).
- Have worked with engineering teams to develop secure code libraries.
- Capable of rapidly learning and integrating emerging tools and platforms with minimal supervision.
Supporting a diverse and inclusive workforce is important to Shutterfly not only because it directly reflects our value of Embracing our Differences, but also because it's the right thing to do for our business and for our people. We welcome all applicants and evaluate them based on their qualifications. Learn more about our commitment to Diversity, Equity, and Inclusion on our Career Site.
The compensation package for this role is based on multiple factors, such as job level, responsibilities, location, and candidate experience. The base pay ranges included below are specific to the locations listed, and may not be applicable to other locations.
California : [$128,000-181,250]
Connecticut and New York: [$128,000-165,750]
Colorado, Illinois, Minnesota and Washington: [$128,000-153,000]
Nevada: [$120,250-165,750]
Maryland and New Jersey: [$138,250-165,750]
Hawaii : [$120,250-144,750]
This position may be eligible for a bonus incentive, health benefits, a 401K program, and other employee perks. More details about our company benefits can be found at
This opportunity can be remote, but candidates must reside in a state in which Shutterfly is registered to do business. This includes all US states except District of Columbia, North Dakota, Mississippi, Rhode Island, Vermont, and Wyoming.
This position will accept applications on an ongoing basis until filled.
#SFLYTechnology
$120.25k - $181.25k
...This position is posted by Jobgether on behalf of a partner company. We are currently looking for a Senior Application Security Engineer (Offensive / Red Team) in United States. This is a unique opportunity for an experienced offensive security professional to play...SeniorRemote jobFull timeFlexible hours- ...Offchain Labs is seeking a Security Engineer to enhance infrastructure security... ...tests and leading red team exercises. You'll collaborate... ...role requires experience in offensive security, strong knowledge... ...we redefine decentralized application interactions! #J-18808-Ljbffr...SeniorRemote work
$110k - $165k
...passionate about breaking applications, devices,... ...advanced cyber security adversaries? The... ...Lead end-to-end red team operations aligned... ...and Detection Engineering to convert TTPs into... ...) and brief senior leadership. Mentor... ...capabilities for offensive use. Contribute...SeniorFull timeWork at officeRemote workWorldwide$96k - $181k
...Serves as the senior process owner for... ...advance an information security processes,... ...best practices, applicable federal and industry... ...and Exposure Mgmt. team rolls up into Key... ...defense. The Senior Offensive Security Engineer is a key member... ...traditional red teaming and penetration...SeniorWork experience placementWork at officeRemote workFlexible hours$60 per hour
Wal-Mart is looking for a Senior Offensive Security Engineer in Mountain View, CA to focus on security assessments for web platforms and AI systems.... ...developing exploitation tools, and collaborating with various teams to improve security measures. Candidates should have a...SeniorContract work- ...We are seeking a Sr. Application Security or DevSecOps Engineer with broad set of experiences... ...our hiring culture: Dream Team Culture Why You Want To Work... ...protect our applications. Red Teamer, Pen Tester, or Web... ...are eager to apply their offensive security skills to proactively...SeniorContract workRemote workFlexible hours
- ...Framework Ventures is seeking a Senior Security Engineer to lead offensive security initiatives. This role involves conducting penetration tests, collaborating with various security teams, and developing custom tools. Candidates should have over 5 years of related experience...SeniorRemote work
$180k - $210k
...Senior Application Security Engineer At Qualia, we've built the leading B2B real estate... ..., high-leverage AppSec team. This is a deep-technical... ...Responsibilities Run offensive assessments against Qualia... ...Detection engineering, DFIR, or red-team experience Open...SeniorWork at officeRemote workFlexible hours$180k - $220k
...Senior Application Security Engineer, AI and Machine Learning San Francisco, California, United States... ...cost-efficient, large-scale compute. Teams get the tools they need for... ...s a Strong Plus If You Have Red team or offensive security experience Experience...SeniorWork at officeWork from homeFlexible hours2 days per week$110k - $165k
...multinational consumer goods company seeks a Cyber Security Specialist in Cincinnati to lead red team operations and strengthen security measures. Candidates... ...Security or equivalent experience, with 3+ years in offensive operations, and strong skills in Python, PowerShell,...SeniorFull time$178.4k - $226.7k
...Amazon is seeking a Senior Security Engineer for our AI Red Team within Threat Operations. This experienced engineer will... ...have at least 5 years of experience in offensive security and a strong understanding of cloud and application security principles. The compensation...Senior$132k - $165k
Early Warning is seeking a Senior Red Team Engineer in Chicago, Illinois. This role involves executing... ...collaborating with internal teams on security assessments. Candidates should have... ...security experience, with 2 years in offensive security. Strong scripting skills in...Senior$178.4k - $226.7k
...Description Application deadline: Applications will be accepted on an ongoing... ...We are looking for an experienced Senior Security Engineer to join our AI Red Team within Threat Operations. You will conduct sophisticated offensive security operations targeting AI systems...SeniorLocal areaFlexible hours$132k - $198k
Early Warning is looking for a Senior Red Team Engineer in Scottsdale to identify emerging threats and create effective security solutions. The ideal candidate will have 6 years... ...information security, with strong skills in offensive security and scripting. The role offers...Senior- Early Warning is seeking a Senior Red Team Engineer in San Francisco. The role focuses on identifying threats and creating prototypes... .... Candidates should have 6+ years in information security and at least 2 years in offensive security, plus proficiency in scripting languages...Senior
- ...the hardest problems in security: giving every human,... ...secured identity, improving engineering velocity while... ...We are looking for an Offensive Security Engineer to work on Teleport's Red Team. You will develop a... ...against any employee or applicant on the basis of age, color...Local areaRemote work
- ...Offensive Security Engineer (Red Team) PlexTrac is a cybersecurity SaaS platform helping security teams streamline reporting, exposure management... ...(AWS/GCP/Azure), internal networks, web applications, and SaaS product Simulate realistic attack chains...Remote work
- ...PlexTrac is seeking an Offensive Security Engineer (Red Team) to enhance its cybersecurity SaaS platform. The ideal candidate will have 4+ years in offensive security and experience with cloud environments. You will play a key role in identifying vulnerabilities before...Remote work
$160k - $240k
...orchestrating procurement across teams, tools, and suppliers with... ...AI agents, companies can secure the resources they need to... ...' data. As our first Application Security Engineer , you will take on a dynamic... ...Hands-on experience in offensive security (eg, through bug bounty...SeniorHome officeFlexible hours$120k - $150k
...Our cybersecurity and information security teams at IDEXX contribute to a more resilient... ...care. IDEXX is seeking a Senior Application Security Engineer to join our Product & Application... ...Application Penetration Tester (GWAPT), Offensive Security Certified Professional (...SeniorLocal areaRemote workWorldwideFlexible hours- A leading technology firm in San Francisco is seeking a hands-on Security Engineer specializing in Offensive Security. This role involves designing and executing Red Team operations to assess readiness against advanced threats. Candidates should have over 2 years of experience...Work at office3 days per week
- ...Amazon is seeking a Senior Security Engineer for its STORM Red Team. This fully remote position demands expertise in leading Red Team engagements and addressing... ...while collaborating with various service teams. Applicants with strong programming and cloud knowledge, along...SeniorRemote work
$220k - $350k
...we encourage all applicants to pay close attention... ...and considered a security risk. About Us... ...customer centered team with a passion for... ...company that engineers advanced risk prediction... .... The role As a Senior Application... ...Working concepts of offensive security testing such...SeniorRemote jobExtra incomeLocal areaWork from homeHome officeFlexible hours- ...Senior Application Security Engineer / AppSec Architect Location: Irving/Addison TX... ...Compliance and Product Security teams to integrate security... ...adversary simulations and red-team-style attack assessments... ...to Have Red Team / Offensive Security experience AI/...SeniorFull timeContract workWork experience placementShift work
$143k - $224k
...deployed humanoids operate alongside teams in warehouses, manufacturing... ...robot fleets. About The Role As a Senior Application Security Engineer, you will be crucial in integrating... ...Application Security Testing: Perform offensive penetration testing on web applications...SeniorFull timeTemporary workRemote workRelocation packageFlexible hours- A defense contracting firm is looking for a Senior CANO Developer in Fort Belvoir to conduct advanced vulnerability research and exploitation... ...role requires dynamic analysis, development of shellcode, and offensive capability development. Employee well-being is a priority, with...Senior
$178.4k - $226.7k
...Job ID: 10432191 | Amazon.com Services LLC Application deadline: Jun 1, 2026 Amazon’s STORM Red Team (SDO Threat Operations, Research & Monitoring) is looking for a Senior Security Engineer to join our team of offensive security operators. We hack Amazon’s services, infrastructure...SeniorRemote workFlexible hours- A leading geolocation company seeks a red team security engineer to enhance application security by conducting penetration tests and ensuring compliance with jurisdictional regulations. This role involves engaging with customers to gather feedback and improve security measures...Senior
$200k - $300k
A leading geolocation technology company is looking for red team security engineers to focus on application security for their mobile and web SDKs. You will perform penetration tests, ensure compliance with regulations, and engage with customers to provide a superior experience...Senior- ...Research Corporation is seeking a Cyber Security Specialist in Maryland to join the Cyber Security Evaluation Team (CSET). The role requires a minimum... ...Responsibilities include executing Red Team engagements, providing security engineering consulting, and conducting...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Application Security Engineer (Offensive / Red Team). Be the first to apply!
- application support engineer United States
- senior application security engineer United States
- application engineering manager United States
- project application engineer United States
- network applications engineer United States
- technical application engineer United States
- cnc applications engineer United States
- hydraulic application engineer United States
- application system engineer United States
- application engineer United States



