Senior Application Security Engineer
Job Description
Offensive security impact meets defensive outcomes in this Senior Application Security Engineer role at Shutterfly. You will plan and lead offensive engagements against critical applications, collaborate closely with Blue Team partners, and drive Purple Team improvements that strengthen detection, alerting, and real-world resilience.
This onsite position is located in Charlotte, NC, with a salary range of USD 120,250 - 165,750 per year. Shutterfly also offers bonus incentive eligibility along with health benefits and a 401K program, plus other employee perks.
Responsibilities
- Plan and lead offensive engagements across Shutterfly applications and supporting infrastructure using established techniques including manual web penetration testing, exploitation, fuzzing, and adversary emulation, leveraging industry-standard offensive tooling.
- Coordinate with third-party testers when engagements require it.
- Work with the Blue Team throughout engagements by sharing tactics, techniques, and procedures in real time, validating and improving detection and alerting coverage, and converting offensive findings into defensive improvements.
- Augment conventional testing with AI and LLM-based tooling to accelerate and extend work such as reconnaissance, payload and test-case generation, and review of code and configuration.
- Maintain awareness of how threat actors are weaponizing AI, and incorporate those realities into engagement planning and defensive recommendations.
- Manage the bug bounty program end to end, including triage, impact assessment and risk scoring (CVSS), locating vulnerable code, providing mitigation guidance, re-testing, and refining policy and scope as needed.
- Identify, triage, and drive remediation of application vulnerabilities through manual testing and exploitation, escalating systemic issues to appropriate engineering teams.
- Lead threat modeling and risk assessments for new and existing applications, using offensive insight to prioritize the highest-impact risks.
- Partner with incident response and Blue Team teams to investigate application-related security incidents by scoping, reproducing, and understanding attacker activity.
- Help define and reinforce secure development practices, including code reviews and integration of security checks into CI/CD pipelines.
- Lead security reviews of critical pull requests and code changes, and review code in most major languages.
- Advise engineering and architecture teams on secure system and application design.
- Serve as a top technical resource for engineers by helping reproduce vulnerabilities, explain impact, document issues, and validate fixes.
- Mentor junior security engineers and developers on offensive techniques and secure coding principles.
- Maintain up-to-date knowledge of offensive techniques, threats, mitigations, best practices, and the evolving role of AI in offensive operations and adversary activity.
- Use the security tooling stack (including SAST, SCA, DAST, and IAST) to support both offensive and defensive work.
Requirements
- Bachelor’s degree in computer science, cybersecurity, or a related technical field, or comparable hands-on experience.
- Demonstrated experience leading or performing offensive security work such as web application penetration testing or Red Team engagements, with hands-on proficiency in conventional offensive/testing techniques and industry-standard offensive tooling.
- Hands-on experience using AI/LLM tools for offensive security or testing, including understanding of how threat actors are leveraging AI.
- Proficiency in at least one modern programming language (preferably Java) and ability to review code in most major languages.
- Strong analytical and problem-solving skills with a risk-based security approach.
- Advanced Burp Suite Pro user; bonus if you have created custom extensions in Java or Python or have used or modified existing extensions.
- Excellent communication and collaboration skills across offensive and defensive teams, IT, engineering, and business stakeholders.
Technologies
- Burp Suite Pro
- Java
- Python
- AI, LLM
- CVSS
- SAST, SCA, DAST, IAST
- CI/CD
- bash, zsh
Preferred Qualifications
- Experience running Purple Team exercises or collaborating directly with defensive/Blue Team functions to improve detection and response.
- Full stack web development experience within an active security program.
- Experience managing a bug bounty program.
- A security certification demonstrating offensive security proficiency, secure coding, professional reporting, and assessments across areas such as network/web/mobile/AD (examples: OSCP, OSEP, CRTO, OSWA, OSWE, GWAPT, GWEB).
- Submitted reports to bug bounty programs or VDPs, including finding a CVE.
- Strong command-line and scripting skills (bash, zsh, Python) on Linux and Mac.
- Enjoy attending security conferences and occasionally participating in CTFs.
- Time spent on cyber security training platforms (HackTheBox, TryHackMe).
- Experience working with engineering teams to develop secure code libraries.
- Ability to rapidly learn and integrate emerging tools and platforms with minimal supervision.
Compensation / Location
- California: $128,000-181,250
- Connecticut and New York: $128,000-165,750
- Colorado, Illinois, Minnesota and Washington: $128,000-153,000
- Nevada: $120,250-165,750
- Maryland and New Jersey: $138,250-165,750
- Hawaii: $120,250-144,750
Remote eligibility: This opportunity can be remote, but candidates must reside in a state in which Shutterfly is registered to do business. This includes all US states except District of Columbia, North Dakota, Mississippi, Rhode Island, Vermont, and Wyoming.
Application Timing
This position will accept applications on an ongoing basis until filled.