Enable job alerts via email!

Senior Application Security Manager

Shutterfly

United States

Remote

USD 156,000 - 236,000

Full time

19 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An innovative company is seeking a Senior Application Security Manager to lead a talented team and shape the application security program. This role involves building relationships with engineering leadership to prioritize security challenges, overseeing penetration tests, and establishing training programs for developers. The ideal candidate will have a strong background in application security, leadership skills, and a passion for mentoring others. Join a forward-thinking firm that values diversity and inclusion while making a significant impact in the industry by enhancing application security practices.

Benefits

Health Benefits
401K Program
Bonus Incentive
Employee Perks

Qualifications

  • 6-8 years as an Application Security Engineer with leadership experience.
  • Proven risk assessment, communication, and management skills.

Responsibilities

  • Lead a team of application security engineers and manage the application security program.
  • Develop relationships with engineering teams to prioritize security challenges.
  • Mentor AppSec engineers and foster their professional growth.

Skills

Application Security
Leadership
Risk Assessment
Communication Skills
Penetration Testing
Vulnerability Management
CI/CD Pipeline
Relationship Management

Education

BS/MS in Computer Science

Tools

GIT
JIRA
Maven
Web Application Protection Tools
Linux
AWS
Kubernetes

Job description

At Shutterfly, we make life’s experiences unforgettable. We believe there is extraordinary power in self-expression. That’s why our family of brands helps customers create products and capture moments that reflect who they uniquely are.

This is an exciting time for Shutterfly. In this position, you will be leading the application security team to shape the application security program. Your focus will be on helping to build and maintain an Application Security program that can be used as the benchmark for our industry.

We are looking for an innovative Senior Application Security Manager who loves to lead, red team, train, resolve vulnerabilities, and much more. While also being a Subject Matter Expert in application security, you will work with application security engineers to evangelize shift-left security, engaging early and often with the engineering teams. You will bring your strong leadership skills, technical background in application security, and deep experience in building application security programs to help take Shutterfly’s application security program to the next level.

What You'll Do Here:
  • Lead a team of highly skilled application security engineers through planning, prioritization, and execution of work.
  • Manage the application security program. Design and execute automation services to enhance enterprise application security test tooling in SDLC and DevOps pipelines.
  • Develop close relationships with the engineering leadership across the company to help teams prioritize security challenges, track and resolve identified risks.
  • Establish and maintain Security Champion program.
  • Establish, maintain and roll out security training program for developers.
  • Build and grow an execution team to analyze and resolve application security issues.
  • Create and evolve sustainable processes and tools for operations through automation, self-service, and reducing complexity.
  • Oversee application security engineers performing penetration tests of services.
  • Define, monitor, and report application security metrics to accurately represent department statistics and team performance.
  • Manage the relationship with third-party vendors providing services to support application security program.
  • Work with engineering on vulnerability management program, maintaining backlog and driving remediation efforts.
  • Mentor and guide AppSec engineers, fostering professional growth and development through one-on-ones, coaching, and real-time feedback.
Qualifications:
Minimum Qualifications:
  • BS/MS in Computer Science or equivalent experience.
  • 6-8 years working as an Application Security Engineer and 1-3 years specifically leading application security team.
  • Experience recruiting and managing technical teams, including performance evaluation and management.
  • Experience with different styles of source control and CI/CD pipeline.
  • Experience building relationships with stakeholders and business leaders.
  • Proven risk assessment and mitigation skills.
  • Proven communication skills, the ability to present information clearly and concisely to all levels of management both formally and informally.
Preferred Qualifications:
  • Familiarity with OWASP top 10 vulnerabilities, mitigations, and their impact on application architecture.
  • Experience with application security testing including SAST, DAST, and SCA.
  • Experience with Web Application protection tools including RASP, WAF, and DDoS mitigation.
  • Experience with Code Review process.
  • Familiarity with programming languages such as Java, NodeJS, Python.
  • Experience managing and maintaining an enterprise bug bounty program.
  • Familiarity with cryptography including commonly implemented algorithms, standards, and best practices.
  • The candidate should have familiarity with a variety of development and testing tools, including IDE, GIT, JIRA, Maven.
Additional Qualifications:
  • Familiarity in both using and securing Linux based systems and containers.
  • Familiarity in both ECS and Kubernetes cluster deployment.
  • Familiarity in Micro Services architecture and security control in such environment.
  • Familiarity in deploying and maintaining controls within various public cloud environments (AWS/Azure/GCP).
  • Relevant security certifications (SANS/GIAC, CISSP, CSSLP, OCSP, etc.) are highly desirable.

Supporting a diverse and inclusive workforce is important to Shutterfly not only because it directly reflects our value of Embracing our Differences, but also because it’s the right thing to do for our business and for our people. We welcome all applicants and evaluate them based on their qualifications, without regard to age, race, creed, color, national origin, ancestry, marital status, affectional or sexual orientation, gender identity or expression, disability, nationality, sex, or other characteristic covered by law. Learn more about our commitment to Diversity, Equity, and Inclusion on our Career Site.

This position will accept applications on an ongoing basis until filled.

The compensation package for this role is based on multiple factors, such as job level, responsibilities, location, and candidate experience. The base pay ranges included below are specific to the locations listed, and may not be applicable to other locations.

California: [$166,000-236,000]

Connecticut and New York: [$166,000-216,000]

Colorado, Illinois, Minnesota, and Washington: [$166,000-200,000]

Nevada: [$156,000-216,000]

Maryland and New Jersey: [$179,250-216,000]

Hawaii: [$156,000-188,000]

This position may be eligible for a bonus incentive, health benefits, a 401K program, and other employee perks. More details about our company benefits can be found at https://shutterflyinc.com/benefits/.

This opportunity can be remote, but candidates must reside in a state in which Shutterfly is registered to do business. This includes all US states except District of Columbia, North Dakota, Mississippi, Rhode Island, Vermont, and Wyoming.

This position will accept applications on an ongoing basis until filled.

#SFLYTechnology

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior Application Security Manager

Shutterfly

Tempe

Remote

USD 156,000 - 236,000

30+ days ago

Staff Product Manager, Safety (Coaching)

Motive

Remote

USD 162,000 - 248,000

6 days ago
Be an early applicant

Sr Regional Health & Safety Manager

IDEX

Remote

USD 124,000 - 187,000

Yesterday
Be an early applicant

Security Operations Manager

HUB International

Remote

USD 120,000 - 165,000

6 days ago
Be an early applicant

Senior Global Category Manager - Security Software - Midwest US Remote

Motorola Solutions

Chicago

Remote

USD 98,000 - 197,000

2 days ago
Be an early applicant

Senior Product Marketing Manager, Security

Coalition Inc

Remote

USD 140,000 - 170,000

9 days ago

Senior Technical Program Manager, Security

Gemini

New York

Hybrid

USD 136,000 - 190,000

5 days ago
Be an early applicant

Senior Cybersecurity Information Systems Security Manager (ISSM)

LMI Consulting, LLC

Raleigh

Hybrid

USD 119,000 - 185,000

4 days ago
Be an early applicant

ENGINEERING MANAGER, SECURITY

Coinbase

Buffalo

Remote

USD 218,000 - 299,000

2 days ago
Be an early applicant