Senior Application Security Engineer
$128k - $181.25kShutterfly Inc
Senior Application Security Engineer (Offensive / Red Team)
At Shutterfly, we make life’s experiences unforgettable. We believe there is extraordinary power in the self-expression. That’s why our family of brands helps customers create products and capture moments that reflect who they uniquely are.
This is an exciting time for Shutterfly, and we are looking for a Senior Application Security Engineer (Offensive / Red Team) to join our team. In this role you will help shape an evolving offensive security practice, leading Red Team engagements against Shutterfly's critical applications while partnering closely with our Blue Team throughout each engagement to produce Purple Team outcomes — stronger detections, faster response, and measurably improved defenses. We're looking for someone who is as passionate about uncovering and exploiting a vulnerability as they are about working alongside defenders to make sure it can be detected, contained, and remediated. Just as important, you'll partner with developers and engineering teams to educate them on how to prevent and avoid vulnerabilities in the first place, and guide them on how to fix issues once identified. Your focus will be on building an offensive security capability that strengthens the entire security program, with collaboration between offense, defense, and engineering at its core.
What You'll Do Here:
- Red Team Operations: Plan and lead offensive engagements against Shutterfly's applications and supporting infrastructure using established offensive and testing techniques — manual web penetration testing, exploitation, fuzzing, and adversary emulation supported by industry-standard offensive tooling — and coordinate with third-party testers when engagements call for it.
- Purple Team Collaboration: Work hand-in-hand with the Blue Team throughout every engagement. Share tactics, techniques, and procedures in real time, validate and improve detection and alerting coverage, run collaborative exercises, and convert offensive findings into concrete defensive improvements.
- AI-Driven Offensive Security: Augment conventional offensive techniques with AI and LLM-based tooling to accelerate and extend offensive and testing work — reconnaissance, payload and test-case generation, code and configuration review, and exploitation.
- Maintain a working understanding of how threat actors are weaponizing AI, and fold that knowledge into engagements and defensive recommendations to keep pace with a rapidly changing threat landscape.
- Bug Bounty Program Management: Manage the bug bounty program end to end — triage, impact assessment, risk scoring (CVSS), locating vulnerable code, providing mitigation guidance, thorough re-testing, and refining program policy and scope as needed.
- Vulnerability Management: Identify, triage, and drive remediation of application vulnerabilities through manual testing and exploitation, escalating systemic issues to the appropriate engineering teams.
- Threat Modeling & Risk Assessment: Lead threat modeling exercises and perform risk assessments for new and existing applications, using offensive insight to prioritize the risks that matter most.
- Incident Response: Collaborate with incident response and Blue Team partners to investigate application-related security incidents, applying offensive expertise to scope, reproduce, and understand attacker activity.
- Secure SDLC: Help define and reinforce secure development practices, including code reviews and integration of security checks into the CI/CD pipeline.
- Code Review: Perform and lead security reviews of critical PRs and code changes, and review code in most major languages.
- Security Architecture & Design: Partner with engineering and architecture teams to advise on secure systems and applications design, ensuring security is built in from the ground up.
- Subject Matter Expertise: Serve as a top technical resource to engineers across the organization. Help them reproduce vulnerabilities, understand impact, document issues, and validate the effectiveness of fixes.
- Mentorship & Leadership: Mentor junior security engineers and developers on offensive techniques, secure coding practices, and security principles. Build relationships with stakeholders and business leaders across the organization.
- Cross-Functional Collaboration: Work closely with product, engineering, DevOps, defensive security, and compliance teams to align security with business goals.
- Continuous Improvement: Maintain up-to-date knowledge of relevant offensive techniques, threats, mitigations, security best practices, and the evolving role of AI in both offensive operations and adversary activity.
- Security Tooling: Make effective use of the existing security tooling stack (e.g., SAST, SCA, DAST, IAST) to support offensive and defensive work.
Required Qualifications:
- Bachelor's degree in computer science, cybersecurity, or a related technical field, or comparable hands-on experience in lieu of a degree.
- Demonstrated experience leading or performing offensive security work, such as web application penetration testing or Red Team engagements, with hands-on proficiency in conventional offensive and testing techniques and industry-standard offensive tooling. Hands-on experience using AI/LLM tools for offensive security or testing, with an understanding of how threat actors are leveraging AI in a rapidly evolving threat landscape.
- Proficient in one modern programming language (preferably Java) and able to review code in most major languages.
- Strong analytical and problem-solving abilities with a risk-based security approach.
- Advanced user of Burp Suite Pro; bonus if you have created custom extensions in Java or Python or have used or modified existing extensions.
- Excellent communication and collaboration skills, with the ability to work across offensive and defensive teams, IT, engineering, and business stakeholders.
Preferred Qualifications:
- Experience running Purple Team exercises or otherwise collaborating directly with defensive/Blue Team functions to improve detection and response.
- Full stack web development experience within an active security program.
- Experience managing a bug bounty program.
- A security certification that demonstrates proficiency in offensive security, network/web/mobile/AD assessments, secure coding, and professional report creation (for example: OSCP, OSEP, CRTO, OSWA, OSWE, GWAPT, GWEB).
- Submitted reports to bug bounty programs or VDPs, and you've found a CVE along the way.
- Strong command-line and scripting skills (bash, zsh, Python) on Linux and Mac.
- Enjoy attending security conferences and occasionally participate in CTFs.
- Spend time on cyber security training platforms (HackTheBox, TryHackMe).
- Have worked with engineering teams to develop secure code libraries.
- Capable of rapidly learning and integrating emerging tools and platforms with minimal supervision.
Supporting a diverse and inclusive workforce is important to Shutterfly not only because it directly reflects our value of Embracing our Differences, but also because it’s the right thing to do for our business and for our people. We welcome all applicants and evaluate them based on their qualifications. Learn more about our commitment to Diversity, Equity, and Inclusion on our Career Site.
The compensation package for this role is based on multiple factors, such as job level, responsibilities, location, and candidate experience. The base pay ranges included below are specific to the locations listed, and may not be applicable to other locations.
California : [$128,000-181,250]
Connecticut and New York: [$128,000-165,750]
Colorado, Illinois, Minnesota and Washington: [$128,000-153,000]
Nevada: [$120,250-165,750]
Maryland and New Jersey: [$138,250-165,750]
Hawaii : [$120,250-144,750]
This position may be eligible for a bonus incentive, health benefits, a 401K program, and other employee perks. More details about our company benefits can be found at
This opportunity can be remote, but candidates must reside in a state in which Shutterfly is registered to do business. This includes all US states except District of Columbia, North Dakota, Mississippi, Rhode Island, Vermont, and Wyoming.
This position will accept applications on an ongoing basis until filled.
#SFLYTechnology
$128k - $181.25k
...capture moments that reflect who they uniquely are.This is an exciting time for Shutterfly, and we are looking for a Senior Application Security Engineer (Offensive / Red Team) to join our team. In this role you will help shape an evolving offensive security practice,...SeniorRemote work- The Application Security team is responsible for the solutions and processes that secure Vanguard applications and operations. As an Application... ...(containers, serverless, API, AI/ML).Provide hands-on engineering support for security incidents, threat events, vulnerability...SeniorFull time
- ...7+ industries. We rank among the leaders in areas like application development and AI/ML, and our people-first culture has... ...to meet you! ABOUT THE ROLE We are looking for a Senior Application Security Engineer to strengthen secure coding and DevSecOps practices across...SeniorWork at officeWork from homeVisa sponsorshipWork visa
- ...planning to optimize performance Conduct security checks, recovery drills, and compliance... ...threat modeling process.• Present work to seniors, the team, and other technical teams.•... ...provides equal employment opportunities to applicants and employees without regard to race;...SuggestedFull timeTemporary workRelocation
$106.6k - $146.5k
...Application Security Engineer The Application Security Engineer will help strengthen application security across web, mobile, and restaurant technology environments by partnering closely with engineering, product, and security teams. This role will focus on identifying...SuggestedFull timeRemote work- ...and support capacity planning to optimize performance Conduct security checks, recovery drills, and compliance audits, implement security... ...with cross-functional teamsRequired Skill and Experience• Application Security Testing: Conduct SAST/SCA using GHAS and DAST using Burp...Full timeTemporary workRelocationShift work
- ...Job Summary: ASSET InterTech creates software (ScanWorks BST) that tests hardware. We are seeking a Senior Applications Engineer with deep expertise in both hardware and software to lead technical support initiatives and mentor junior team members. This role is critical...SeniorPermanent employmentRelocation
- Senior Application Engineer (Legal Technology)Location: Dallas, TX / Austin, TX / Houston, TX / Chicago, IL / Philadelphia, PA / Miami, FL / NYC... ...non-IT business partnersEnsure all applications comply with security, governance, and compliance standardsCreate and maintain...SeniorPermanent employmentRemote work
- ...Title: Application Security Engineer Location: Dallas, TX (5 Days Onsite) Job Description: Application Security Engineer Should have a strong proficiency in at least one of the following areas # Application Security Testing particularly...
- ...Required Qualifications ~5+ years of professional experience in Web Application Firewall / Layer 7 security. ~ Deep hands-on experience with WAF (Web Application Firewalls) configuration, tuning, and monitoring or WAF's from vendors such as Imperva, ASM...Local area
- ...we serve. The Information Technology group delivers secure, reliable technology solutions that enable DTCC to be... ...employee).The Impact You Will Have in This RoleAs an Senior Associate Application Support Engineer, you will play a key role in supporting mission-critical...SeniorRemote workFlexible hours
$189k - $303k
...crucial goods where they need to go, and make mobility more efficient and accessible for all. We’re looking for a Staff Application Security Engineer with a strong software engineering background to help build and maintain an AI-native application security program for...Work at officeLocal area3 days per week- ...the next chapter in your professional life. Job Summary The Senior Security Engineer will be responsible for strengthening and continuously improving the security posture of the applications within Equinix. This role involves integrating security best...Full timeContract workTraineeshipWork experience placementInternshipShift work
- ...challenge of scaling product security at a Fortune 500 company and... ...faster, securely. We're a team of engineers who work to enable other... ...technical audiences, including senior leadership. Proven ability to... ...information about its applicants for employment that may include...SeniorLocal area
$95.6k - $188.4k
...Join our Deloitte AI & Engineering team to transform technology... ...integrate, and sustain enterprise applications supporting Dynamics 365,... ...solutions in addition to delivering secure, scalable APIs, integrations... ...entry-level employees to senior leaders, we believe there’s...SeniorLocal areaFlexible hours- ...annually across thousands of connected devices. The Samsara Application Security team protects this vast footprint end-to-end, spanning cloud... ...IoT hardware in the field. As a Staff Application Security Engineer, you’ll drive the overarching technical direction for our application...Full timeRemote workFlexible hoursShift work
$178k - $285k
...goods where they need to go, and make mobility more efficient and accessible for all. We’re searching for a Senior Manager - Hardware Systems Applications Engineering.In this role, you willWork on-site in the DFW area which is our center of excellence for fleet operations...SeniorWork at officeLocal areaRemote workHome officeShift work3 days per week- ...for existing and new portfolios. As a Senior Technical Support Engineer, you will work closely with internal... ...customer reported issues; implement security and permissions configuration... ...driving issues to resolution. Qualified applicants must not require employer sponsored...Senior
$101.6k - $152.4k
...date), and military leave benefits.You must submit an online application to be considered for the position. The Company will accept applications... ...Compliance Form.Join Schneider Electric as a Sr. Application Engineer - Protection, Controls & AutomationTravel: This role will...SeniorOngoing contractFull timeTemporary workWork at officeImmediate startRemote workFlexible hours- Amphenol Communications Solutions (ACS), a division of Amphenol Corporation, seeks a Senior Field Applications Engineer to be the primary technical interface between customers and internal engineering teams. This engineering‑first role combines deep technical insight with...Senior
$125k - $145k
...the energy transition, we are helping drive it forward. Senior Applications Engineer, Solar Inverters and Battery Storage Remote (Eastern or... ...never request payment, banking information, or a Social Security number during the recruitment process. If you are contacted...SeniorFull timeTemporary workH1bWork at officeRemote workRelocation package$180k - $210k
...Job Description Job Description Title: Senior Manager, Applications Engineering Location: Allen, TX Compensation: $180,000–$210,000 Base + 15% Bonus + $50,000–$60,000 RSUs (Annual Grants) Work Type: On-Site Initially | Hybrid Flexibility Thereafter...SeniorH1bWorldwideVisa sponsorshipRelocation package- ...measurable reliability targets for critical application environments, ensuring operational... ...operational standards across support and engineering groups. Develop, automate, and maintain... ...load balancing, and service discovery; Security including least privilege, secrets...Full timeRemote work
- ...Application Engineer At Crestron Electronics, Inc we build the technology that integrates technology. We are proud to be the largest and... ...integrating systems such as Audio Visual, Lighting, Shading, Security, Building Management Systems and HVAC to provide greater comfort...Temporary workNight shiftAfternoon shift
- ...The Integrated Circuit Solutions business group within Nexperia is seeking an Application Engineer to join our organization. This position requires strong communication skills and leadership qualities. The ICS business group is a growing organization within an established...Local area
- ...Applications Engineer Apogee Semiconductor provides products and technologies for space and other extreme environments. We are focused on making the frontier of space more accessible by bridging the technology gap between commercial and high-reliability technologies...Full timeWork at officeFlexible hours
$100k - $150k
A leading engineering firm is seeking an Application Engineer in Plano, TX, to act as a subject matter expert in transportation technologies and facilitate customer engagement. You will translate complex technical information and partner with Sales to ensure optimal product...Full time- Embedded Software Application Engineer (Avionics / Aerospace) Location: Onsite in Plano, TX or Rockford, IL Duration: 12 Months + Extensions Position Overview We are seeking a highly skilled Embedded Software Application Engineer to support the design, development, integration...
- A network security firm based in Texas is seeking a Mid-Senior level contract technical advisor. The role involves providing expertise on Next Generation Firewall... ...technologies, working closely with Product and Engineering teams, and ensuring customer satisfaction....SeniorContract work
- Job DescriptionWe are seeking an experienced Application Engineering Manager to lead and oversee the development, implementation, and optimization of Power, Analog and Converter “PAC” account support strategies for 93k products. The ideal candidate will have a strong background...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Application Security Engineer. Be the first to apply!
- senior application support engineer Richardson, TX
- application performance engineer Richardson, TX
- senior application security engineer Richardson, TX
- application engineering manager Richardson, TX
- app developer Richardson, TX
- software applications developer Richardson, TX
- network security engineer Richardson, TX
- security engineer Richardson, TX
- IT security engineer Richardson, TX
- aws cloud security engineer Richardson, TX



