Senior Application Security Engineer
$128k - $181.25kShutterfly
Senior Application Security Engineer (Offensive / Red Team)
At Shutterfly, we make life’s experiences unforgettable. We believe there is extraordinary power in the self-expression. That’s why our family of brands helps customers create products and capture moments that reflect who they uniquely are.
This is an exciting time for Shutterfly, and we are looking for a Senior Application Security Engineer (Offensive / Red Team) to join our team. In this role you will help shape an evolving offensive security practice, leading Red Team engagements against Shutterfly's critical applications while partnering closely with our Blue Team throughout each engagement to produce Purple Team outcomes — stronger detections, faster response, and measurably improved defenses. We're looking for someone who is as passionate about uncovering and exploiting a vulnerability as they are about working alongside defenders to make sure it can be detected, contained, and remediated. Just as important, you'll partner with developers and engineering teams to educate them on how to prevent and avoid vulnerabilities in the first place, and guide them on how to fix issues once identified. Your focus will be on building an offensive security capability that strengthens the entire security program, with collaboration between offense, defense, and engineering at its core.
What You'll Do Here:
- Red Team Operations: Plan and lead offensive engagements against Shutterfly's applications and supporting infrastructure using established offensive and testing techniques — manual web penetration testing, exploitation, fuzzing, and adversary emulation supported by industry-standard offensive tooling — and coordinate with third-party testers when engagements call for it.
- Purple Team Collaboration: Work hand-in-hand with the Blue Team throughout every engagement. Share tactics, techniques, and procedures in real time, validate and improve detection and alerting coverage, run collaborative exercises, and convert offensive findings into concrete defensive improvements.
- AI-Driven Offensive Security: Augment conventional offensive techniques with AI and LLM-based tooling to accelerate and extend offensive and testing work — reconnaissance, payload and test-case generation, code and configuration review, and exploitation.
- Maintain a working understanding of how threat actors are weaponizing AI, and fold that knowledge into engagements and defensive recommendations to keep pace with a rapidly changing threat landscape.
- Bug Bounty Program Management: Manage the bug bounty program end to end — triage, impact assessment, risk scoring (CVSS), locating vulnerable code, providing mitigation guidance, thorough re-testing, and refining program policy and scope as needed.
- Vulnerability Management: Identify, triage, and drive remediation of application vulnerabilities through manual testing and exploitation, escalating systemic issues to the appropriate engineering teams.
- Threat Modeling & Risk Assessment: Lead threat modeling exercises and perform risk assessments for new and existing applications, using offensive insight to prioritize the risks that matter most.
- Incident Response: Collaborate with incident response and Blue Team partners to investigate application-related security incidents, applying offensive expertise to scope, reproduce, and understand attacker activity.
- Secure SDLC: Help define and reinforce secure development practices, including code reviews and integration of security checks into the CI/CD pipeline.
- Code Review: Perform and lead security reviews of critical PRs and code changes, and review code in most major languages.
- Security Architecture & Design: Partner with engineering and architecture teams to advise on secure systems and applications design, ensuring security is built in from the ground up.
- Subject Matter Expertise: Serve as a top technical resource to engineers across the organization. Help them reproduce vulnerabilities, understand impact, document issues, and validate the effectiveness of fixes.
- Mentorship & Leadership: Mentor junior security engineers and developers on offensive techniques, secure coding practices, and security principles. Build relationships with stakeholders and business leaders across the organization.
- Cross-Functional Collaboration: Work closely with product, engineering, DevOps, defensive security, and compliance teams to align security with business goals.
- Continuous Improvement: Maintain up-to-date knowledge of relevant offensive techniques, threats, mitigations, security best practices, and the evolving role of AI in both offensive operations and adversary activity.
- Security Tooling: Make effective use of the existing security tooling stack (e.g., SAST, SCA, DAST, IAST) to support offensive and defensive work.
Required Qualifications:
- Bachelor's degree in computer science, cybersecurity, or a related technical field, or comparable hands-on experience in lieu of a degree.
- Demonstrated experience leading or performing offensive security work, such as web application penetration testing or Red Team engagements, with hands-on proficiency in conventional offensive and testing techniques and industry-standard offensive tooling. Hands-on experience using AI/LLM tools for offensive security or testing, with an understanding of how threat actors are leveraging AI in a rapidly evolving threat landscape.
- Proficient in one modern programming language (preferably Java) and able to review code in most major languages.
- Strong analytical and problem-solving abilities with a risk-based security approach.
- Advanced user of Burp Suite Pro; bonus if you have created custom extensions in Java or Python or have used or modified existing extensions.
- Excellent communication and collaboration skills, with the ability to work across offensive and defensive teams, IT, engineering, and business stakeholders.
Preferred Qualifications:
- Experience running Purple Team exercises or otherwise collaborating directly with defensive/Blue Team functions to improve detection and response.
- Full stack web development experience within an active security program.
- Experience managing a bug bounty program.
- A security certification that demonstrates proficiency in offensive security, network/web/mobile/AD assessments, secure coding, and professional report creation (for example: OSCP, OSEP, CRTO, OSWA, OSWE, GWAPT, GWEB).
- Submitted reports to bug bounty programs or VDPs, and you've found a CVE along the way.
- Strong command-line and scripting skills (bash, zsh, Python) on Linux and Mac.
- Enjoy attending security conferences and occasionally participate in CTFs.
- Spend time on cyber security training platforms (HackTheBox, TryHackMe).
- Have worked with engineering teams to develop secure code libraries.
- Capable of rapidly learning and integrating emerging tools and platforms with minimal supervision.
Supporting a diverse and inclusive workforce is important to Shutterfly not only because it directly reflects our value of Embracing our Differences, but also because it’s the right thing to do for our business and for our people. We welcome all applicants and evaluate them based on their qualifications. Learn more about our commitment to Diversity, Equity, and Inclusion on our Career Site.
The compensation package for this role is based on multiple factors, such as job level, responsibilities, location, and candidate experience. The base pay ranges included below are specific to the locations listed, and may not be applicable to other locations.
California : [$128,000-181,250]
Connecticut and New York: [$128,000-165,750]
Colorado, Illinois, Minnesota and Washington: [$128,000-153,000]
Nevada: [$120,250-165,750]
Maryland and New Jersey: [$138,250-165,750]
Hawaii : [$120,250-144,750]
This position may be eligible for a bonus incentive, health benefits, a 401K program, and other employee perks. More details about our company benefits can be found at
This opportunity can be remote, but candidates must reside in a state in which Shutterfly is registered to do business. This includes all US states except District of Columbia, North Dakota, Mississippi, Rhode Island, Vermont, and Wyoming.
This position will accept applications on an ongoing basis until filled.
#SFLYTechnology
- The Application Security team is responsible for the solutions and processes that secure Vanguard applications and operations. As an Application... ...(containers, serverless, API, AI/ML).Provide hands-on engineering support for security incidents, threat events, vulnerability...SeniorFull time
- ...Application Security Engineer – Bot Detection & Traffic Routing We are seeking an experienced Application Security Engineer to support the detection, analysis, and mitigation of automated bot traffic across enterprise web applications. This role will focus on web application...Suggested
- ...Application Security Engineer Network Infrastructure/Security This role is a key contributor to an enterprise-wide application security program, focusing on discovering, inventorying, and securing business applications across multiple units. The position involves implementing...Suggested
$90k - $100k
...Job Description Senior Application Engineer SEE Headquarters - Charlotte Requisition ID: 56327 If you are a current employee... ...application process, such as a Driver's License or Social Security Number. If you have any concerns about information...SeniorLocal areaWorldwideRelocationFlexible hours- ...Senior Applications Engineer At Okuma America Corporation, we are committed to helping manufacturers achieve exceptional productivity through innovative CNC technologies, application expertise, and long-term customer partnerships. As a Senior Applications Engineer,...SeniorFlexible hours
- ...provides an end-to-end portfolio of best-in-class products, engineering, service, parts, training, and integration. Methods has more... ...of 45,000 machines throughout North America. Title: Sr. Applications Engineer (Based at any of our offices) Responsibility: Lead...Senior
$65.05 per hour
...Job Description Job Description Job Title: Senior Production Support / Application Support Engineer Location: Charlotte, NC / Chandler, AZ Duration: Contract - 12 months Pay Range: $65.05/hr (W2) Job ID: 408907 About BCforward BCforward is a...SeniorContract workWeekend work- ...through innovative and sustainable solutions.The Engineering Manager is responsible for managing a team of Application Engineers focused on Xylem's capital solutions.... ...Impact Behaviors:• Strategic Vision and Foresight: Senior professionals should have the ability to develop...SeniorFull timeWork experience placement
$125k - $145k
...the energy transition, we are helping drive it forward. Senior Applications Engineer, Solar Inverters and Battery Storage Remote (Eastern or... ...never request payment, banking information, or a Social Security number during the recruitment process. If you are contacted...SeniorFull timeTemporary workH1bWork at officeRemote workRelocation package- ...you click Apply Now and complete your application, you'll be invited to create a profile,... ...looking for builders, problem-solvers, and security professionals who thrive in a fast-... ...Collaborate effectively across security, engineering, development, infrastructure teams, app...SeniorPermanent employmentFull timePart timeH1bWork visaShift workDay shift
- Job DescriptionAs an Advanced Application Engineer here at Brady Corp., you will lead a team to deliver high-quality solutions, provide technical expertise, and ensure exceptional customer service. Your leadership will drive innovative solutions and business growth. You...Flexible hoursShift workNight shiftWeekend work
- ...you click Apply Now and complete your application, you'll be invited to create a... ...description:• This team uses automated API security tools like Akamai, Salt Security and... ...vulnerabilities in running APIs.• This Senior Security Engineer will be experienced with API...SeniorFull timePart timeShift workDay shift
$98k - $113.5k
...Energy Delivery & Utilization Applications EngineerLocation:Charlotte,... ...for a versatile, collaborative engineer to join our group. You will... ...candidateWhy EPRI Applications?Take on senior-level project responsibility... ...the Department of Homeland Security and the Social Security...Full timeWork at officeRemote workWork from homeHome officeRelocation packageFlexible hours$23 per hour
...including their R&D, Procurement, Marketing, Engineering and other departments. o Understand... ...equal employment opportunities to all applicants for employment and to all employees,... ..., such as a Driver's License or Social Security Number. If you have any concerns about...Full timeSummer workInternshipLocal areaWorldwideRelocationFlexible hours- ...Title: Applications Engineer II Reports to : Applications Manager Location : DMG MORI USA Hours : Full Time, Core Business Hours Classification : Non Exempt Travel : 50%+ Employment is conditioned on DMG MORI's ability to obtain and maintain any...Full timeWork at officeShift work
- ...Applications Engineer, Polymer PumpsMAAG Pump Systems, Automatik Plastics Machinery, Maag Gala Industries, Reduction Engineering Scheer, Ettlinger, AMN, and Witte – seven successful and well-experienced companies have joined forces to become the global partner for the...Temporary workWork experience placementWork at officeLocal areaFlexible hours
- ...technical design for Palantir applications, workflows, integrations,... ...are built with appropriate security, reliability, maintainability... ...performance considerations. Engineering Standards and Patterns: Establish... ..., vendors, management, and senior leaders. Technical...Full time
- ...of this page. After you click Apply Now and complete your application, you'll be invited to create a profile, which will let you... ...following job description:The Open Source Software (OSS) Senior Security Engineer owns the practical execution of open source software security...SeniorFull timePart timeShift workDay shift
- ...onsite – 3 days in office 2 days remote 6 months Contract to hire Seeking a senior, hands-on engineer to support and maintain a business-critical physical security and access management application hosted on AWS. The role will troubleshoot issues across the application,...Contract workWork at officeRemote work
- ...Job Title 5+ years of experience in application development and support. CatsWeb or Assurex Experience 3+ years scripting experience (Power BI, Kafka, Python). Bachelor’s degree in Computer Science or a related field. Strong SQL and data structure knowledge...
- ...Required Qualifications ~5+ years of experience in application development and support. ~ CatsWeb or Assurex Experience ~3+ years Scripting experience (Power BI, Kafka, Python). ~ Bachelor s degree in Computer Science or a related field. ~ Strong...
- ...Application Support Engineer Location: Charlotte, North Carolina (Onsite) Role Overview This role offers an opportunity to enhance domain... ...to operate in high-pressure situations and interact with senior management. Willingness to provide stand-by out-of-hours...
- ...Job Title: Application Support Engineer Location: Charlott, NC Type: Contract Job Description: Provide go live... ...release activities Work closely with infrastructure security network and database teams to ensure application availability...Contract work
$100k - $180k
We are seeking a full‑stack engineer with strong UI specialization to help build the next... ...workflowsDevelop rich, data‑driven applications supporting portfolio analysis and operationsCreate... ..., technical limitations, and security.Elevates code into the development, test...Full timeWork experience placementWork at officeRemote workWork from homeVisa sponsorship- Core ResponsibilitiesTest Engineering & Automation FrameworksDesign and build automated testing frameworks for backend services, data pipelines... ...‑release verificationEnsure solutions comply with information security and technology policiesExperience Required5+ years of...Full timeVisa sponsorship
- ...Application Support Engineer 6 months contract - CHARLOTTE NC SAS BI Tools 5+ years of experience in SAS Enterprise Application Development and Support Reporting experience specially with SSAS CUBES is a must Excellent Data analysis, data modelling and SQL skills...Contract workWork at officeRemote work
$128.4k - $192.6k
Senior Security Engineer - IS07FEWe’re determined to make a difference and are proud to be an insurance company that goes well beyond coverages... ..., AI‑driven cyber security solutions that strengthen application security, vulnerability management, and enterprise cyber resilience...SeniorFull timeTemporary workWork at office3 days per week- It's more than a jobAs a Senior Logistics Systems Engineer at Kuehne+Nagel, you will design, implement, and optimizes IT systems that power contract... ...is not eligible for employment visa sponsorship. Applicants must be currently authorized to work in the United States...SeniorPermanent employmentFull timeContract workLocal areaRemote work
$134.5k - $265.1k
...As a Cyber Forward Deployed Engineer (FDE), you will work at the intersection... ...-enabled capabilities where applicable, and deploying them in... ...concepts (e.g., application security, cloud security, identity,... ...From entry-level employees to senior leaders, we believe there’s always...SeniorLocal areaVisa sponsorship- ...Individuals with Disabilities. If you are also looking for an attractive employer to work with, then simply get to know us. As an Applications Engineer, you will support the sales team by developing innovative warehouse automation and intralogistics solutions that meet...Work at officeRemote workWorldwide
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Application Security Engineer. Be the first to apply!
- cnc applications engineer Charlotte, NC
- senior application support engineer Charlotte, NC
- technical application engineer Charlotte, NC
- application performance engineer Charlotte, NC
- project application engineer Charlotte, NC
- application system engineer Charlotte, NC
- application engineer Charlotte, NC
- hydraulic application engineer Charlotte, NC
- senior application security engineer Charlotte, NC
- application security engineer Charlotte, NC



