Shutterfly is hiring a Senior Application Security Engineer (Offensive / Red Team) in Charlotte, NC to plan and lead offensive engagements against critical applications, partnering closely with Blue Team stakeholders to produce Purple Team outcomes and strengthen defenses.
Location and Compensation
- Location: Charlotte, NC (onsite)
- Base Salary: USD 120,250 - 165,750 per year
Compensation by location (listed by Shutterfly):
- California: [$128,000-181,250]
- Connecticut and New York: [$128,000-165,750]
- Colorado, Illinois, Minnesota and Washington: [$128,000-153,000]
- Nevada: [$120,250-165,750]
- Maryland and New Jersey: [$138,250-165,750]
- Hawaii: [$120,250-144,750]
Role Summary
This senior role focuses on offensive application security, secure SDLC initiatives, vulnerability management, threat modeling, and incident response support. Responsibilities also include AI-augmented offensive testing and end-to-end management of a bug bounty program.
Key Responsibilities
- Plan and lead offensive engagements against Shutterfly applications and supporting infrastructure, using manual web penetration testing, exploitation, fuzzing, and adversary emulation supported by industry-standard offensive tooling, including coordination with third-party testers when needed.
- Collaborate with the Blue Team throughout engagements by sharing tactics, techniques, and procedures in real time, validating and improving detection and alerting coverage, running joint exercises, and converting offensive findings into defensive improvements.
- Apply AI and LLM-based tooling to augment offensive techniques, including reconnaissance, payload and test-case generation, code and configuration review, and exploitation.
- Maintain awareness of how threat actors are weaponizing AI and incorporate that knowledge into engagements and defensive recommendations.
- Manage the bug bounty program end to end, including triage, impact assessment, risk scoring using CVSS, locating vulnerable code, providing mitigation guidance, re-testing, and refining program policy and scope.
- Identify, triage, and drive remediation of application vulnerabilities by conducting manual testing and exploitation, escalating systemic issues to the appropriate engineering teams.
- Lead threat modeling exercises and perform risk assessments for new and existing applications, using offensive insight to prioritize the highest-value risks.
- Partner with incident response and Blue Team counterparts to investigate application-related incidents by scoping, reproducing, and understanding attacker activity.
- Support secure development practices by reinforcing code reviews and integrating security checks into the CI/CD pipeline.
- Lead security reviews of critical pull requests and code changes, and review code in most major languages.
- Advise engineering and architecture teams on secure systems and application design with security built in from the ground up.
- Act as a technical resource across the organization by helping engineers reproduce vulnerabilities, understand impact, document issues, and validate fixes.
- Mentor junior security engineers and developers on offensive techniques, secure coding practices, and security principles; build relationships across stakeholders and business leaders.
- Coordinate with product, engineering, DevOps, defensive security, and compliance teams to align security work with business goals.
- Stay current on offensive techniques, threats, mitigations, and security best practices, including the evolving role of AI in both offensive operations and adversary activity.
- Use the security tooling stack (SAST, SCA, DAST, IAST) to support both offensive and defensive work.
Required Qualifications
- Bachelorβs degree in computer science, cybersecurity, or a related technical field, or comparable hands-on experience in lieu of a degree.
- Proven experience leading or performing offensive security work, such as web application penetration testing or Red Team engagements, with hands-on proficiency in conventional offensive/testing techniques and industry-standard offensive tooling.
- Hands-on experience using AI/LLM tools for offensive security or testing, including an understanding of how threat actors leverage AI in a rapidly evolving landscape.
- Proficiency in at least one modern programming language (preferably Java) and the ability to review code in most major languages.
- Strong analytical and problem-solving skills with a risk-based security approach.
- Advanced proficiency with Burp Suite Pro; bonus for creating custom extensions in Java or Python, or for using/modifying existing extensions.
- Excellent communication and collaboration skills across offensive and defensive teams, IT, engineering, and business stakeholders.
Preferred Qualifications
- Experience running Purple Team exercises or direct collaboration with Blue Team functions to improve detection and response.
- Full stack web development experience within an active security program.
- Experience managing a bug bounty program.
- A security certification demonstrating offensive security proficiency across network/web/mobile/AD assessments, secure coding, and professional report creation (examples include OSCP, OSEP, CRTO, OSWA, OSWE, GWAPT, GWEB).
- Submitted reports to bug bounty programs or VDPs, including having found a CVE.
- Strong command-line and scripting ability (bash, zsh, Python) on Linux and Mac.
- Enjoyment of attending security conferences and occasionally participating in CTFs.
- Time spent training on security platforms such as HackTheBox and TryHackMe.
- Experience working with engineering teams to develop secure code libraries.
- Ability to rapidly learn and integrate emerging tools and platforms with minimal supervision.
Technology Stack
- Burp Suite Pro
- Java, Python
- AI, LLM
- CVSS
- SAST, SCA, DAST, IAST
- CI/CD
- bash, zsh
Benefits
- Bonus incentive eligibility
- Health benefits
- 401K program
- Other employee perks
Remote Eligibility
This opportunity can be remote, provided candidates reside in a state where Shutterfly is registered to do business. This includes all US states except District of Columbia, North Dakota, Mississippi, Rhode Island, Vermont, and Wyoming.
Application Timing
This position accepts applications on an ongoing basis until filled.