Senior Application Security Engineer II
$128k - $181.25kShutterfly
At Shutterfly, we make life’s experiences unforgettable. We believe there is extraordinary power in the self-expression. That’s why our family of brands helps customers create products and capture moments that reflect who they uniquely are. This is an exciting time for Shutterfly and we are looking for a Senior Application Security Engineer to join our team! In this position you will be an integral part of a developing and expanding Application Security program. The Senior Application Security Engineer is a vital role that helps to provide assurance for Shutterfly’s critical applications and securely enables business functions. We’re looking for a person who is just as passionate about uncovering a security vulnerability as you are about educating developers on how to fix it. Your focus will be on helping to build and maintain an Application Security program that can be used as the benchmark for our industry. What You'll Do Here Manage our bug bounty program including triage, assessing impact, risk scoring (CVSS), helping to locate the vulnerable code, providing mitigation guidance, performing thorough re-testing, and refining program policy and scope as needed. Vulnerability Management: Identify, triage, and remediate application vulnerabilities (SAST, SCA, IAST) using automated tools or manual testing. Web Penetration Testing: assisting with internal web pen tests and coordinating with 3rd party testers. Threat Modeling & Risk Assessment: Lead threat modeling exercises and perform risk assessments for new and existing applications. Incident Response: Collaborate with incident response teams to investigate and remediate application‑related security incidents. Security Tooling: Evaluate, implement, maintain and decommission security tools and platforms to support application security efforts (SAST, SCA, DAST, IAST, RASP, WAF, ASPM, CNAPP, CSPM). Continuous Improvement: Keep up‑to‑date knowledge of relevant security threats, mitigations and security best practices. Secure SDLC: Define and implement secure development practices, including code reviews, static/dynamic analysis, and CI/CD pipeline integration. Provide guidance and recommendations to software engineering teams to implement effective security measures to mitigate risks. Become a Subject Matter Expert and top technical resource to engineers around the organization. Help engineers reproduce vulnerabilities, understand their impact, document issues, mitigate or retest the effectiveness of a fix, etc. Perform and lead code reviews of critical PRs and code changes. Security Architecture & Design: Partner with engineering teams to design secure systems and applications, ensuring security is built‑in from the ground up. Initiate and lead design, architecture, and solution reviews. Mentorship & Leadership: Mentor junior security engineers and developers on secure coding practices and security principles. Build relationships with stakeholders and business leaders across the organization. Cross‑Functional Collaboration: Work closely with product, engineering, DevOps, and compliance teams to align security with business goals. Required Qualifications Bachelor’s degree in computer science, cybersecurity, or related technical field. Proficient in one modern programming language (preferably Java) and can review code in most major languages. Strong analytical and problem‑solving abilities with a risk‑based security approach. Advanced user of Burp Suite Pro, bonus if you have created custom extensions in Java or Python and have used or modified existing extensions. Excellent communication and collaboration skills, able to work across IT, engineering, and business teams. Preferred Qualifications Full stack web development experience within an active security program. Experience managing a bug bounty program. Have a security certification that demonstrates proficiency in web assessments, secure coding, and professional report creation (For example: OSWA, OSWE, GWAPT, GWEB). Submitted reports to bug bounty programs or VDPs, and you've found a CVE along the way. Strong command‑line and scripting skills (bash, zsh, Python) on Linux and Mac. Enjoy attending security conferences and occasionally participate in CTFs. Spend time on cyber security training platforms (HackTheBox, TryHackMe). Work with engineering teams to develop secure code libraries. Experience deploying and managing a RASP solution (e.g. Contrast, Prevoty) on multiple tech stacks. Capable of rapidly learning and integrating emerging tools and platforms with minimal supervision. Supporting a diverse and inclusive workforce is important to Shutterfly not only because it directly reflects our value of Embracing our Differences, but also because it’s the right thing to do for our business and for our people. We welcome all applicants and evaluate them based on their qualifications. Learn more about our commitment to Diversity, Equity, and Inclusion on our Career Site. The compensation package for this role is based on multiple factors, such as job level, responsibilities, location, and candidate experience. The base pay ranges included below are specific to the locations listed, and may not be applicable to other locations. California : [$128,000-181,250] Connecticut and New York: [$128,000-165,750] Colorado, Illinois, Minnesota and Washington: [$128,000-153,000] Nevada: [$120,250-165,750] Maryland and New Jersey: [$138,250-165,750] Hawaii : [$120,250-144,750] This position may be eligible for a bonus incentive, health benefits, a 401K program, and other employee perks. More details about our company benefits can be found at This opportunity can be remote, but candidates must reside in a state in which Shutterfly is registered to do business. This includes all US states except District of Columbia, North Dakota, Mississippi, Rhode Island, Vermont, and Wyoming. This position will accept applications on an ongoing basis until filled. #SFLYTechnology #J-18808-Ljbffr
$130k - $218k
...A leading blockchain company is seeking a Senior Application Security Engineer to join their growing security team. The role involves embedding security throughout the software development lifecycle for MetaMask products, ensuring they meet high-security standards. Applicants...SeniorRemote work- ...A leading web platform company is seeking a Senior Application Security Engineer to enhance their secure development practices. This remote role involves collaborating with engineering teams, identifying security vulnerabilities, and leading security initiatives. Candidates...SeniorRemote work
$215k - $230k
...A leading blockchain intelligence firm is looking for an Application Security Engineer to secure mission-critical infrastructure. The role involves leading security reviews, developing testing methodologies, and managing vulnerability assessment processes. Candidates should...Senior- ...end‑users (and help the developers behind them get paid), you’ll fit right in. The role: We are looking for a Senior, proactive Application Security Engineer to work closely with engineering teams, PMs and external parties to ensure that RevenueCat's products are secure...SeniorRemote work
- ...Senior Security Engineer – Secure Code Review New York, NY On-site | Full-Time My client is seeking a Senior Security Engineer to join their Application Security practice. This role is ideal for a hands-on AppSec professional with a strong software development...SeniorFull time
$80 - $85 per hour
...risks specifically related to application security. ? Develop, socialize, and implement... ...vulnerabilities, to senior management. ? Perform/coordinate application... ...Requirements Senior Application Security Engineer Mandatory Skills/Experience...SeniorContract workFlexible hours$220k - $350k
...Senior Application Security Engineer [Remote-US] remote To help keep everyone safe, we encourage all applicants to pay close attention to protect themselves during their job search. When applying for a position online you are at risk of being targeted by malicious actors...SeniorExtra incomeLocal areaRemote workWork from homeHome office$140k - $170k
...growing and changing Stellar ecosystem. SDF is looking for a Senior Security Engineer to help shape and scale the security program across the... ...look forward to hearing from you! Privacy By submitting your application, you are agreeing to our use and processing of your data...SeniorContract workTemporary workWork at officeLocal areaWorldwideFlexible hoursNight shift$158k - $238k
...performant digital experiences, and scale without heavy engineering support. From independent designers and creative agencies... ...to power what’s possible on the web. We’re looking for a Senior Application Security Engineer to help us level up Webflow’s secure development...SeniorPermanent employmentFull timeTemporary workFixed term contractLocal areaRemote workFlexible hours- ...A leading security consulting firm seeks a Senior Application Security Engineer to manage security risks and ensure safe application development practices in the cloud. This remote role requires designing secure development frameworks and mentoring teams on best practices...SeniorFixed term contractRemote work
$140k - $200k
Role As a Senior Application Security Engineer on the Application Security team, you will be a trusted partner to engineering, product, and business teams across Gemini. You will help guide teams to design and build secure products while building systems and culture that...SeniorWork at officeRemote workFlexible hours- ..., we’d love to meet you. The Team The Security Engineering team at Imprint is foundational to ensuring... ...that protects our infrastructure, applications, and data from threats, all while... ...payments and card technology. The Role As a Senior Application Security Engineer, you’ll...SeniorRemote workFlexible hoursShift work3 days per week
- ...A leading software security company is seeking a Senior Staff Sales Engineer to drive sales strategies and provide technical leadership. The ideal candidate will have over 8 years of experience in application security and be capable of engaging effectively with both engineers...Senior
- Booz Allen Hamilton is seeking an Application Security Engineer to drive cloud capabilities for national security. In this role, you will modernize existing computing platforms and collaborate on advanced security measures. With at least 4 years of experience in DoD architectures...Senior
- A pioneering technology firm seeking an experienced Application Security Engineer to secure products for Fortune 500 clients. The role emphasizes collaboration with engineering teams and ensuring compliance with security standards. Candidates should have expertise in application...SeniorFull time
$86.4k - $129.6k
...Application Engineer II For this U.S. based position, the expected compensation range is $86,400 - $129,600 per year , which includes base pay... ...necessary clearance including but not limited to Homeland Security clearance, background and credit checks. Travel up to 15% to...Permanent employmentTemporary workFlexible hours- ...A technology services provider is seeking an E-Discovery Application Administrator II to support federal agencies with IT legal services. The role requires extensive programming experience, exceptional communication skills, and familiarity with IT environments. The ideal...
- ...Job Description Summary The Applications Engineer II, ECSA & Application Integration/Interfaces, reports to the Manager of the ECSA & Application Integration/Interfaces team in support of MUSC’s academic, research and healthcare missions. Under direct supervision, the...Work experience placementRemote workRotating shift
- ...Application Engineer II, Division Production Software Hexagon’s Manufacturing Intelligence is seeking an Application Engineer II for the Production Software Division. This is a remote position based in the United States. Responsibilities Provide Technical Support services...Work experience placementRemote workFlexible hours
$98.33k - $160.74k
...Application Support Engineer II- ERP SAP HANA Job Locations US-NJ-Secaucus Job ID 2026-6227 # of Openings 1 Category... ...with SAP S/4HANA Public Cloud architecture principles, security policies, and operational standards. Finance...Full timeContract workTemporary workWork at officeLocal areaFlexible hours$86.4k - $129.6k
...A leading energy management company is seeking an Application Engineer II in the U.S. This role involves creating engineering designs for power monitoring systems and consulting with stakeholders about system requirements. Candidates should possess a BS in Electrical Engineering...Flexible hours- ...Senior Security Engineer II – Threat Detection & Response Client is seeking a Senior Security Engineer- Detection & Response (Threat-Informed... ...threat controls using deep knowledge of cloud, identity, application, and data attack paths. What You’ll Do Adversary...SeniorImmediate start
- ...Overview As a Senior Security Engineer II for Identity and Access Management (IAM) at Aledade, you will play a central role in enhancing the... ...posture of our enterprise, cloud-native environments, and applications. We are seeking a dedicated professional with in-depth knowledge...SeniorTemporary workRemote workFlexible hours
$165k - $242k
...Senior Security Engineer II, Vulnerability Management Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA CoreWeave is The Essential... ...powering breakthrough AI research and enterprise AI applications. You'll solve security problems at the intersection of cloud...SeniorTemporary workFlexible hoursShift work$77.5k - $140.9k
...diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. As an Application Security Engineer, you will be responsible for implementing and managing application development platforms and optimizing security tools...SeniorFull timeSummer holidayFlexible hours$80.64k - $120.96k
...depends on start date), and military leave benefits. Shape the future of smart buildings and critical environments. As a Systems Application Engineer II , you’ll design and deliver innovative building automation solutions that improve energy efficiency, comfort, and...Full timeTemporary workFor contractorsFlexible hours$153k - $212k
...A technology firm is seeking a remote Security Researcher to conduct internet measurement research and analyze large datasets for security implications. The ideal candidate will have a strong understanding of internet protocols and excellent communication skills. You'...SeniorRemote work$97k - $207.5k
...L3Harris is seeking a Senior Specialist, Security Software Research Engineer to join their elite security team. The candidate will focus on finding vulnerabilities in software, constructing exploits, and guiding team deliverables. Candidates should possess a Bachelor’...SeniorRemote work- ...leading technology company in parenting products is seeking a Senior Product Security Engineer to advance their product security initiatives. The ideal... ...extensive experience in cloud security engineering and application/product security, with a focus on secure coding...SeniorRemote workFlexible hours
- ...Job Description: Looking for senior level Product Security Engineer who has prior experience with IEC 62443 controls, specifically from the perspective of a manufacturer producing products that can certify to 62443. ~ This candidate will have a blended...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Application Security Engineer II. Be the first to apply!
- senior application security engineer New York, NY
- application engineer New York, NY
- junior application support engineer New York, NY
- application system engineer New York, NY
- network applications engineer New York, NY
- cnc applications engineer New York, NY
- project application engineer New York, NY
- field applications engineer New York, NY
- hydraulic application engineer New York, NY
- application support engineer New York, NY


