Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Application Security Engineer II

$128k - $181.25k

Shutterfly

At Shutterfly, we make life’s experiences unforgettable. We believe there is extraordinary power in the self-expression. That’s why our family of brands helps customers create products and capture moments that reflect who they uniquely are. This is an exciting time for Shutterfly and we are looking for a Senior Application Security Engineer to join our team! In this position you will be an integral part of a developing and expanding Application Security program. The Senior Application Security Engineer is a vital role that helps to provide assurance for Shutterfly’s critical applications and securely enables business functions. We’re looking for a person who is just as passionate about uncovering a security vulnerability as you are about educating developers on how to fix it. Your focus will be on helping to build and maintain an Application Security program that can be used as the benchmark for our industry. What You'll Do Here Manage our bug bounty program including triage, assessing impact, risk scoring (CVSS), helping to locate the vulnerable code, providing mitigation guidance, performing thorough re-testing, and refining program policy and scope as needed. Vulnerability Management: Identify, triage, and remediate application vulnerabilities (SAST, SCA, IAST) using automated tools or manual testing. Web Penetration Testing: assisting with internal web pen tests and coordinating with 3rd party testers. Threat Modeling & Risk Assessment: Lead threat modeling exercises and perform risk assessments for new and existing applications. Incident Response: Collaborate with incident response teams to investigate and remediate application‑related security incidents. Security Tooling: Evaluate, implement, maintain and decommission security tools and platforms to support application security efforts (SAST, SCA, DAST, IAST, RASP, WAF, ASPM, CNAPP, CSPM). Continuous Improvement: Keep up‑to‑date knowledge of relevant security threats, mitigations and security best practices. Secure SDLC: Define and implement secure development practices, including code reviews, static/dynamic analysis, and CI/CD pipeline integration. Provide guidance and recommendations to software engineering teams to implement effective security measures to mitigate risks. Become a Subject Matter Expert and top technical resource to engineers around the organization. Help engineers reproduce vulnerabilities, understand their impact, document issues, mitigate or retest the effectiveness of a fix, etc. Perform and lead code reviews of critical PRs and code changes. Security Architecture & Design: Partner with engineering teams to design secure systems and applications, ensuring security is built‑in from the ground up. Initiate and lead design, architecture, and solution reviews. Mentorship & Leadership: Mentor junior security engineers and developers on secure coding practices and security principles. Build relationships with stakeholders and business leaders across the organization. Cross‑Functional Collaboration: Work closely with product, engineering, DevOps, and compliance teams to align security with business goals. Required Qualifications Bachelor’s degree in computer science, cybersecurity, or related technical field. Proficient in one modern programming language (preferably Java) and can review code in most major languages. Strong analytical and problem‑solving abilities with a risk‑based security approach. Advanced user of Burp Suite Pro, bonus if you have created custom extensions in Java or Python and have used or modified existing extensions. Excellent communication and collaboration skills, able to work across IT, engineering, and business teams. Preferred Qualifications Full stack web development experience within an active security program. Experience managing a bug bounty program. Have a security certification that demonstrates proficiency in web assessments, secure coding, and professional report creation (For example: OSWA, OSWE, GWAPT, GWEB). Submitted reports to bug bounty programs or VDPs, and you've found a CVE along the way. Strong command‑line and scripting skills (bash, zsh, Python) on Linux and Mac. Enjoy attending security conferences and occasionally participate in CTFs. Spend time on cyber security training platforms (HackTheBox, TryHackMe). Work with engineering teams to develop secure code libraries. Experience deploying and managing a RASP solution (e.g. Contrast, Prevoty) on multiple tech stacks. Capable of rapidly learning and integrating emerging tools and platforms with minimal supervision. Supporting a diverse and inclusive workforce is important to Shutterfly not only because it directly reflects our value of Embracing our Differences, but also because it’s the right thing to do for our business and for our people. We welcome all applicants and evaluate them based on their qualifications. Learn more about our commitment to Diversity, Equity, and Inclusion on our Career Site. The compensation package for this role is based on multiple factors, such as job level, responsibilities, location, and candidate experience. The base pay ranges included below are specific to the locations listed, and may not be applicable to other locations. California : [$128,000-181,250] Connecticut and New York: [$128,000-165,750] Colorado, Illinois, Minnesota and Washington: [$128,000-153,000] Nevada: [$120,250-165,750] Maryland and New Jersey: [$138,250-165,750] Hawaii : [$120,250-144,750] This position may be eligible for a bonus incentive, health benefits, a 401K program, and other employee perks. More details about our company benefits can be found at This opportunity can be remote, but candidates must reside in a state in which Shutterfly is registered to do business. This includes all US states except District of Columbia, North Dakota, Mississippi, Rhode Island, Vermont, and Wyoming. This position will accept applications on an ongoing basis until filled. #SFLYTechnology #J-18808-Ljbffr

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Senior Application Security Engineer II in New York, NY vacancy
  • $130k - $218k

     ...A leading blockchain company is seeking a Senior Application Security Engineer to join their growing security team. The role involves embedding security throughout the software development lifecycle for MetaMask products, ensuring they meet high-security standards. Applicants... 
    Senior
    Remote work

    ConsenSys

    New York, NY
    1 day ago
  •  ...A leading web platform company is seeking a Senior Application Security Engineer to enhance their secure development practices. This remote role involves collaborating with engineering teams, identifying security vulnerabilities, and leading security initiatives. Candidates... 
    Senior
    Remote work

    Webflow

    New York, NY
    1 day ago
  • $215k - $230k

     ...A leading blockchain intelligence firm is looking for an Application Security Engineer to secure mission-critical infrastructure. The role involves leading security reviews, developing testing methodologies, and managing vulnerability assessment processes. Candidates should... 
    Senior

    Crypto Pro Network

    New York, NY
    1 day ago
  •  ...end‑users (and help the developers behind them get paid), you’ll fit right in. The role: We are looking for a Senior, proactive Application Security Engineer to work closely with engineering teams, PMs and external parties to ensure that RevenueCat's products are secure... 
    Senior
    Remote work

    RevenueCat

    New York, NY
    1 day ago
  •  ...Senior Security Engineer – Secure Code Review New York, NY On-site | Full-Time My client is seeking a Senior Security Engineer to join their Application Security practice. This role is ideal for a hands-on AppSec professional with a strong software development... 
    Senior
    Full time

    AGS

    New York, NY
    2 days ago
  • $80 - $85 per hour

     ...risks specifically related to application security. ? Develop, socialize, and implement...  ...vulnerabilities, to senior management. ? Perform/coordinate application...  ...Requirements Senior Application Security Engineer Mandatory Skills/Experience... 
    Senior
    Contract work
    Flexible hours

    Network Temp Inc

    New York, NY
    3 days ago
  • $220k - $350k

     ...Senior Application Security Engineer [Remote-US] remote To help keep everyone safe, we encourage all applicants to pay close attention to protect themselves during their job search. When applying for a position online you are at risk of being targeted by malicious actors... 
    Senior
    Extra income
    Local area
    Remote work
    Work from home
    Home office

    Quanata

    New York, NY
    1 day ago
  • $140k - $170k

     ...growing and changing Stellar ecosystem. SDF is looking for a Senior Security Engineer to help shape and scale the security program across the...  ...look forward to hearing from you! Privacy By submitting your application, you are agreeing to our use and processing of your data... 
    Senior
    Contract work
    Temporary work
    Work at office
    Local area
    Worldwide
    Flexible hours
    Night shift

    Energent Media

    New York, NY
    1 day ago
  • $158k - $238k

     ...performant digital experiences, and scale without heavy engineering support. From independent designers and creative agencies...  ...to power what’s possible on the web. We’re looking for a Senior Application Security Engineer to help us level up Webflow’s secure development... 
    Senior
    Permanent employment
    Full time
    Temporary work
    Fixed term contract
    Local area
    Remote work
    Flexible hours

    Webflow

    New York, NY
    1 day ago
  •  ...A leading security consulting firm seeks a Senior Application Security Engineer to manage security risks and ensure safe application development practices in the cloud. This remote role requires designing secure development frameworks and mentoring teams on best practices... 
    Senior
    Fixed term contract
    Remote work

    Hampton North

    New York, NY
    1 day ago
  • $140k - $200k

    Role As a Senior Application Security Engineer on the Application Security team, you will be a trusted partner to engineering, product, and business teams across Gemini. You will help guide teams to design and build secure products while building systems and culture that... 
    Senior
    Work at office
    Remote work
    Flexible hours

    I did my part and supported the Regular Toilet

    New York, NY
    2 days ago
  •  ..., we’d love to meet you. The Team The Security Engineering team at Imprint is foundational to ensuring...  ...that protects our infrastructure, applications, and data from threats, all while...  ...payments and card technology. The Role As a Senior Application Security Engineer, you’ll... 
    Senior
    Remote work
    Flexible hours
    Shift work
    3 days per week

    Imprint

    New York, NY
    1 day ago
  •  ...A leading software security company is seeking a Senior Staff Sales Engineer to drive sales strategies and provide technical leadership. The ideal candidate will have over 8 years of experience in application security and be capable of engaging effectively with both engineers... 
    Senior

    Remote Jobs

    New York, NY
    1 day ago
  • Booz Allen Hamilton is seeking an Application Security Engineer to drive cloud capabilities for national security. In this role, you will modernize existing computing platforms and collaborate on advanced security measures. With at least 4 years of experience in DoD architectures... 
    Senior

    Booz Allen Hamilton

    New York, NY
    1 day ago
  • A pioneering technology firm seeking an experienced Application Security Engineer to secure products for Fortune 500 clients. The role emphasizes collaboration with engineering teams and ensuring compliance with security standards. Candidates should have expertise in application... 
    Senior
    Full time

    Valence

    New York, NY
    3 days ago
  • $86.4k - $129.6k

     ...Application Engineer II For this U.S. based position, the expected compensation range is $86,400 - $129,600 per year , which includes base pay...  ...necessary clearance including but not limited to Homeland Security clearance, background and credit checks. Travel up to 15% to... 
    Permanent employment
    Temporary work
    Flexible hours

    Schneider Electric

    New York, NY
    1 day ago
  •  ...A technology services provider is seeking an E-Discovery Application Administrator II to support federal agencies with IT legal services. The role requires extensive programming experience, exceptional communication skills, and familiarity with IT environments. The ideal... 

    Contact Government Services, LLC

    New York, NY
    1 day ago
  •  ...Job Description Summary The Applications Engineer II, ECSA & Application Integration/Interfaces, reports to the Manager of the ECSA & Application Integration/Interfaces team in support of MUSC’s academic, research and healthcare missions. Under direct supervision, the... 
    Work experience placement
    Remote work
    Rotating shift

    Medical University of South Carolina

    New York, NY
    3 days ago
  •  ...Application Engineer II, Division Production Software Hexagon’s Manufacturing Intelligence is seeking an Application Engineer II for the Production Software Division. This is a remote position based in the United States. Responsibilities Provide Technical Support services... 
    Work experience placement
    Remote work
    Flexible hours

    Hexagon AB

    New York, NY
    1 day ago
  • $98.33k - $160.74k

     ...Application Support Engineer II- ERP SAP HANA Job Locations US-NJ-Secaucus Job ID 2026-6227 # of Openings 1 Category...  ...with SAP S/4HANA Public Cloud architecture principles, security policies, and operational standards. Finance... 
    Full time
    Contract work
    Temporary work
    Work at office
    Local area
    Flexible hours

    Yusen Logistics (Americas), Inc.

    Secaucus, NJ
    2 days ago
  • $86.4k - $129.6k

     ...A leading energy management company is seeking an Application Engineer II in the U.S. This role involves creating engineering designs for power monitoring systems and consulting with stakeholders about system requirements. Candidates should possess a BS in Electrical Engineering... 
    Flexible hours

    Schneider Electric

    New York, NY
    1 day ago
  •  ...Senior Security Engineer II – Threat Detection & Response Client is seeking a Senior Security Engineer- Detection & Response (Threat-Informed...  ...threat controls using deep knowledge of cloud, identity, application, and data attack paths. What You’ll Do Adversary... 
    Senior
    Immediate start

    WinMax

    New York, NY
    13 hours ago
  •  ...Overview As a Senior Security Engineer II for Identity and Access Management (IAM) at Aledade, you will play a central role in enhancing the...  ...posture of our enterprise, cloud-native environments, and applications. We are seeking a dedicated professional with in-depth knowledge... 
    Senior
    Temporary work
    Remote work
    Flexible hours

    Aledade, Inc.

    New York, NY
    1 day ago
  • $165k - $242k

     ...Senior Security Engineer II, Vulnerability Management Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA CoreWeave is The Essential...  ...powering breakthrough AI research and enterprise AI applications. You'll solve security problems at the intersection of cloud... 
    Senior
    Temporary work
    Flexible hours
    Shift work

    CoreWeave

    New York, NY
    13 hours ago
  • $77.5k - $140.9k

     ...diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. As an Application Security Engineer, you will be responsible for implementing and managing application development platforms and optimizing security tools... 
    Senior
    Full time
    Summer holiday
    Flexible hours

    EY

    Secaucus, NJ
    4 days ago
  • $80.64k - $120.96k

     ...depends on start date), and military leave benefits. Shape the future of smart buildings and critical environments. As a Systems Application Engineer II , you’ll design and deliver innovative building automation solutions that improve energy efficiency, comfort, and... 
    Full time
    Temporary work
    For contractors
    Flexible hours

    Schneider Electric

    New York, NY
    4 days ago
  • $153k - $212k

     ...A technology firm is seeking a remote Security Researcher to conduct internet measurement research and analyze large datasets for security implications. The ideal candidate will have a strong understanding of internet protocols and excellent communication skills. You'... 
    Senior
    Remote work

    Censys

    New York, NY
    1 day ago
  • $97k - $207.5k

     ...L3Harris is seeking a Senior Specialist, Security Software Research Engineer to join their elite security team. The candidate will focus on finding vulnerabilities in software, constructing exploits, and guiding team deliverables. Candidates should possess a Bachelor’... 
    Senior
    Remote work

    L3Harris

    New York, NY
    1 day ago
  •  ...leading technology company in parenting products is seeking a Senior Product Security Engineer to advance their product security initiatives. The ideal...  ...extensive experience in cloud security engineering and application/product security, with a focus on secure coding... 
    Senior
    Remote work
    Flexible hours

    CloudDevs

    New York, NY
    1 day ago
  •  ...Job Description: Looking for senior level Product Security Engineer who has prior experience with IEC 62443 controls, specifically from the perspective of a manufacturer producing products that can certify to 62443. ~ This candidate will have a blended... 
    Senior

    3B Staffing LLC

    Jersey City, NJ
    13 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Application Security Engineer II. Be the first to apply!