Senior Application Security Engineer
$128k - $181.25kShutterfly
Senior Application Security Engineer (Offensive / Red Team) At Shutterfly, we make life’s experiences unforgettable. We believe there is extraordinary power in the self-expression. That’s why our family of brands helps customers create products and capture moments that reflect who they uniquely are. This is an exciting time for Shutterfly, and we are looking for a Senior Application Security Engineer (Offensive / Red Team) to join our team. In this role you will help shape an evolving offensive security practice, leading Red Team engagements against Shutterfly's critical applications while partnering closely with our Blue Team throughout each engagement to produce Purple Team outcomes — stronger detections, faster response, and measurably improved defenses. We're looking for someone who is as passionate about uncovering and exploiting a vulnerability as they are about working alongside defenders to make sure it can be detected, contained, and remediated. Just as important, you'll partner with developers and engineering teams to educate them on how to prevent and avoid vulnerabilities in the first place, and guide them on how to fix issues once identified. Your focus will be on building an offensive security capability that strengthens the entire security program, with collaboration between offense, defense, and engineering at its core. What You'll Do Here: Red Team Operations: Plan and lead offensive engagements against Shutterfly's applications and supporting infrastructure using established offensive and testing techniques — manual web penetration testing, exploitation, fuzzing, and adversary emulation supported by industry-standard offensive tooling — and coordinate with third-party testers when engagements call for it. Purple Team Collaboration: Work hand-in-hand with the Blue Team throughout every engagement. Share tactics, techniques, and procedures in real time, validate and improve detection and alerting coverage, run collaborative exercises, and convert offensive findings into concrete defensive improvements. AI-Driven Offensive Security: Augment conventional offensive techniques with AI and LLM-based tooling to accelerate and extend offensive and testing work — reconnaissance, payload and test-case generation, code and configuration review, and exploitation. Maintain a working understanding of how threat actors are weaponizing AI, and fold that knowledge into engagements and defensive recommendations to keep pace with a rapidly changing threat landscape. Bug Bounty Program Management: Manage the bug bounty program end to end — triage, impact assessment, risk scoring (CVSS), locating vulnerable code, providing mitigation guidance, thorough re-testing, and refining program policy and scope as needed. Vulnerability Management: Identify, triage, and drive remediation of application vulnerabilities through manual testing and exploitation, escalating systemic issues to the appropriate engineering teams. Threat Modeling & Risk Assessment: Lead threat modeling exercises and perform risk assessments for new and existing applications, using offensive insight to prioritize the risks that matter most. Incident Response: Collaborate with incident response and Blue Team partners to investigate application-related security incidents, applying offensive expertise to scope, reproduce, and understand attacker activity. Secure SDLC: Help define and reinforce secure development practices, including code reviews and integration of security checks into the CI/CD pipeline. Code Review: Perform and lead security reviews of critical PRs and code changes, and review code in most major languages. Security Architecture & Design: Partner with engineering and architecture teams to advise on secure systems and applications design, ensuring security is built in from the ground up. Subject Matter Expertise: Serve as a top technical resource to engineers across the organization. Help them reproduce vulnerabilities, understand impact, document issues, and validate the effectiveness of fixes. Mentorship & Leadership: Mentor junior security engineers and developers on offensive techniques, secure coding practices, and security principles. Build relationships with stakeholders and business leaders across the organization. Cross-Functional Collaboration: Work closely with product, engineering, DevOps, defensive security, and compliance teams to align security with business goals. Continuous Improvement: Maintain up-to-date knowledge of relevant offensive techniques, threats, mitigations, security best practices, and the evolving role of AI in both offensive operations and adversary activity. Security Tooling: Make effective use of the existing security tooling stack (e.g., SAST, SCA, DAST, IAST) to support offensive and defensive work. Required Qualifications: Bachelor's degree in computer science, cybersecurity, or a related technical field, or comparable hands-on experience in lieu of a degree. Demonstrated experience leading or performing offensive security work, such as web application penetration testing or Red Team engagements, with hands-on proficiency in conventional offensive and testing techniques and industry-standard offensive tooling. Hands-on experience using AI/LLM tools for offensive security or testing, with an understanding of how threat actors are leveraging AI in a rapidly evolving threat landscape. Proficient in one modern programming language (preferably Java) and able to review code in most major languages. Strong analytical and problem-solving abilities with a risk-based security approach. Advanced user of Burp Suite Pro; bonus if you have created custom extensions in Java or Python or have used or modified existing extensions. Excellent communication and collaboration skills, with the ability to work across offensive and defensive teams, IT, engineering, and business stakeholders. Preferred Qualifications: Experience running Purple Team exercises or otherwise collaborating directly with defensive/Blue Team functions to improve detection and response. Full stack web development experience within an active security program. Experience managing a bug bounty program. A security certification that demonstrates proficiency in offensive security, network/web/mobile/AD assessments, secure coding, and professional report creation (for example: OSCP, OSEP, CRTO, OSWA, OSWE, GWAPT, GWEB). Submitted reports to bug bounty programs or VDPs, and you've found a CVE along the way. Strong command-line and scripting skills (bash, zsh, Python) on Linux and Mac. Enjoy attending security conferences and occasionally participate in CTFs. Spend time on cyber security training platforms (HackTheBox, TryHackMe). Have worked with engineering teams to develop secure code libraries. Capable of rapidly learning and integrating emerging tools and platforms with minimal supervision. Supporting a diverse and inclusive workforce is important to Shutterfly not only because it directly reflects our value of Embracing our Differences, but also because it’s the right thing to do for our business and for our people. We welcome all applicants and evaluate them based on their qualifications. Learn more about our commitment to Diversity, Equity, and Inclusion on our Career Site. The compensation package for this role is based on multiple factors, such as job level, responsibilities, location, and candidate experience. The base pay ranges included below are specific to the locations listed, and may not be applicable to other locations. California : [$128,000-181,250] Connecticut and New York: [$128,000-165,750] Colorado, Illinois, Minnesota and Washington: [$128,000-153,000] Nevada: [$120,250-165,750] Maryland and New Jersey: [$138,250-165,750] Hawaii : [$120,250-144,750] This position may be eligible for a bonus incentive, health benefits, a 401K program, and other employee perks. More details about our company benefits can be found at This opportunity can be remote, but candidates must reside in a state in which Shutterfly is registered to do business. This includes all US states except District of Columbia, North Dakota, Mississippi, Rhode Island, Vermont, and Wyoming. This position will accept applications on an ongoing basis until filled. #SFLYTechnology Shutterfly
$100.63k - $167.79k
...Sr. Application Security Engineer Where Ambition Meets Innovation Build a career that matches all your initiative with an impressive dose of innovation. From cutting-edge resources and a collaborative environment to the freedom to make an impact and more, you'll...SeniorWork from home- ...our customers. Job Description POSITION TITLE: Sr. Application Database Engineer/Admin LOCATION: Phoenix AZ SALARY: Based on... ...experience in MySQL Database Administrator and/or held a Senior DBA position Degree in computer science, software engineering...SeniorFull time
- ...planning to optimize performance Conduct security checks, recovery drills, and compliance... ...threat modeling process.• Present work to seniors, the team, and other technical teams.•... ...provides equal employment opportunities to applicants and employees without regard to race;...SuggestedFull timeTemporary workRelocation
- ...Job Title : Application Engineer Location : Tempe, AZ Position Overview This position is responsible for supporting the application, setup, programming, and operation of CNC machines. The ideal candidate will have expertise in CNC programming...SuggestedRemote workNight shift
- Description PADT is seeking an engineer with a strong background in computational electromagnetics and high-frequency simulation to support... ...custom‑written material, customers and prospects on software applications or use cases Conducting in‑person and virtual meetings with...SuggestedPermanent employmentWork at office
- ...Application Engineering ManagerSyenta is pioneering a new era in semiconductor manufacturing with our groundbreaking Localised Electrochemical... ...demos, and updates to customer stakeholdersInterface with senior technical leaders (e.g., CTOs, Directors of Engineering)Handle...Flexible hours
$150k - $225k
Sr. Field Applications Engineer - Power Delivery Powerlattice is a well-funded semiconductor startup backed by leading Silicon Valley venture capital firms. We are developing a groundbreaking chiplet solution for a fundamental shift in how high-performance chips are powered...SeniorWork experience placementWork at officeShift work3 days per week- ...may close early due to the volume of applicants. Join a financial services firm... ...seeking a highly technical, hands-on Senior Non-Human Identity Engineer to lead the engineering, automation,... ...ensure non-human identities are properly secured, monitored, and managed throughout...SeniorTemporary workWork at officeHome officeFlexible hours3 days per week
$81.45k - $105.88k
...planning to optimize performance Conduct security checks, recovery drills, and compliance... ...Experience We are seeking an experienced Senior SailPoint Developer to support and... ...integrations with directories, databases, applications, web services, ticketing platforms, and...SeniorPermanent employmentFull timeTemporary workRelocation- ...robustness, cost and risk of designs. Lead Design FMEAs with cross-functional groups including Logistics, Manufacturing, Product Engineering, Purchasing, Quality, Suppliers and Tooling/Fixtures Utilize QPC process as outlined in IATF-16949 standard Will be the...SeniorTemporary work
- ...Senior Product Engineer Job Description Renesas Electronics, a leading global semiconductor company, is rapidly scaling its AI-focused... ...decision whether or not to file or pursue an export license application is at the sole discretion of Renesas. VideoUrl #...SeniorRemote work
- ...Your Mission Collaborate with customers' engineering, procurement, and quality teams, as well as Radiall's internal Engineering, Sales... ...-year college, or equivalent experience in lieu of degree Applications engineering and/or experience with RF, ARINC, or 38999...Permanent employmentWork at office
- ...for consumer & industrial power as well as automotive power applications. Benchmark, select and qualify suitable materials, processes... ...in Physics, Chemistry, Mechanical, Electrical or Materials Engineering. • 10-15 years of relevant experience in package development...SeniorContract workFor subcontractor
- Marathon Petroleum Company LP in Tempe, AZ is seeking a qualified engineer to join the Asphalt Technology West team. The role emphasizes quality oversight, product formulation, and cross-functional collaboration to support asphalt and heavy oil products. The candidate...Senior
- ...proactive individuals with mechanical/thermal/electrical degree engineering background, positive team player attitude who can plan and... ...candidates should possess skills in understanding thermal/mechanical applications, products development, solving complex situations/problems,...Full time
- ...staffing expertise include: • Application Development • Project Management... ...& Disaster Recovery • Security & Privacy Specialties• Contract... ...Management System) Job Description Senior .NET Application Developer/Software Engineer On behalf of our client,...SeniorPermanent employmentFull timeContract workFor contractorsH1bImmediate start
- Viasat is seeking an Embedded Software Engineer to contribute to a small, fast-paced team developing encrypted communications systems and embedded cryptographic devices. You will interface with system, test, and hardware engineers as new capabilities are developed and...
$161.5k - $218.5k
Overview The Arm Solutions Engineering Security IP Team is seeking creative and enthusiastic Security Hardware Designers to join our team.... ...Computer Science or Electrical/Computer Engineering. Successful applicants will have established track records of sophisticated...Work at officeLocal areaRelocation$100.55k - $194.27k
Software Application Development Engineer - Government Programs Intel's Foundry Automation group is seeking an experienced software application development... .... Ability to obtain and maintain US government TS security clearance and SCI access. Bachelor's degree computer...InternshipLocal areaShift work- Hi, we're Oscar. We're hiring a Senior Product Security Engineer 1 to join our Security Team.Oscar is the first health insurance company built around... .... You will work at the intersection of traditional application security and modern AI-driven engineering, ensuring that...SeniorFull timeWork experience placementWork at officeFlexible hours
$88k - $120k
...Job Description Resource Innovations is seeking a Senior Application Software Engineer to join our growing Grid Management Software division in... ...documentation. Follow best practices for software security to protect against vulnerabilities and ensure compliance...SeniorLocal areaRelocation$165k - $260.5k
...What you'll do This is a role for a senior Embedded Software Engineer within Space Infrastructure -... ...Design and implementation of Linux OS applications in Python, C/C++, and Rust Design and... ...to improve product reliability and security Lead design reviews and documentation...Senior- ...enabling advisors to offer comprehensive securities and investment advisory solutions to... ...-enabled capabilities. We are seeking a Senior Salesforce Developer to design, configure... ...certifications preferred. Internal Application Policy: Internal applicants must be...Senior
- Schedule: Hybrid - 3 days onsite per week W2 ONLY AND NO SPONSORSHIP ALLOWED Overview We are seeking an experienced Application / Production Support Engineer to provide production support for enterprise applications and batch processing environments. This role will...3 days per week
$150k
...years of professional software engineering experience delivering... ...experience modernizing legacy applications or incrementally improving older... ...who can operate as a senior individual contributor and mentor... ...maintainability, resiliency, and secure coding. We troubleshoot...SeniorFull timeImmediate start- ...Join to apply for the Senior PCB Design Engineer #ESF9817 role at COA Network Inc Join to apply for the Senior... ..., and cross-disciplinary collaboration. ~ Security Clearance Required Seniority level Not Applicable Employment type Full-time Job...SeniorFull time
- Senior AI Engineer / Data Scientist (Consulting) \ \ Location: United States (Remote) \ Employment Type: Full -Time / Contract \ Experience... ...: Implement and optimize cutting -edge Generative AI applications (such as LLMs and RAG) in live production settings. \*...SeniorRemote jobFull timeContract work
- Arm Chandler is seeking a Security Hardware Designer to develop architectures and security IP for next‑generation SoCs. You will drive RTL design, verification planning, and collaboration with cross‑functional teams to meet power and performance targets. The role emphasizes...
- ...(BRION based) customer projects, working with small team of engineers.CoachingAssesses skill levels and grows team members by coaching... ...areas where system design has sensitivity to product applications and convinces customer to provide data and internal stakeholders...SeniorFull timeLocal areaImmediate start
- ...Arizona is looking for an experienced and dynamic Sr Design Engineer. The individual will play a key role in a variety of projects... ...to the International Traffic in Arms Regulations (ITAR). All applicants must be U.S. persons within the meaning of ITAR. ITAR defines...SeniorPermanent employmentTemporary workWeekend work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Application Security Engineer. Be the first to apply!



