Application Security Engineer Jobs in North Carolina
Application Security Engineer jobs in North Carolina are in strong and sustained demand, concentrated in the financial services, defense contracting, and technology sectors, with openings at every level from entry-level analyst to principal security architect. The heaviest hiring is in Charlotte, Raleigh, and Durham, where employers like Bank of America, Cisco, and Fidelity Investments maintain significant engineering operations. The most sought-after specialties in North Carolina include secure software development lifecycle practices, cloud security architecture, and penetration testing. Find a role that fits below and apply directly.
Find JobsOverview
Showing 5 of 5+ Application Security Engineer jobs










Looking for more application security engineer jobs?
Explore related role searches to find more openings that fit.
See related jobs
At Shutterfly, we make life’s experiences unforgettable. We believe there is extraordinary power in the self-expression. That’s why our family of brands helps customers create products and capture moments that reflect who they uniquely are.
This is an exciting time for Shutterfly, and we are looking for a Senior Application Security Engineer (Offensive / Red Team) to join our team. In this role you will help shape an evolving offensive security practice, leading Red Team engagements against Shutterfly's critical applications while partnering closely with our Blue Team throughout each engagement to produce Purple Team outcomes — stronger detections, faster response, and measurably improved defenses. We're looking for someone who is as passionate about uncovering and exploiting a vulnerability as they are about working alongside defenders to make sure it can be detected, contained, and remediated. Just as important, you'll partner with developers and engineering teams to educate them on how to prevent and avoid vulnerabilities in the first place, and guide them on how to fix issues once identified. Your focus will be on building an offensive security capability that strengthens the entire security program, with collaboration between offense, defense, and engineering at its core.
What You'll Do Here:
- Red Team Operations: Plan and lead offensive engagements against Shutterfly's applications and supporting infrastructure using established offensive and testing techniques — manual web penetration testing, exploitation, fuzzing, and adversary emulation supported by industry-standard offensive tooling — and coordinate with third-party testers when engagements call for it.
- Purple Team Collaboration: Work hand-in-hand with the Blue Team throughout every engagement. Share tactics, techniques, and procedures in real time, validate and improve detection and alerting coverage, run collaborative exercises, and convert offensive findings into concrete defensive improvements.
- AI-Driven Offensive Security: Augment conventional offensive techniques with AI and LLM-based tooling to accelerate and extend offensive and testing work — reconnaissance, payload and test-case generation, code and configuration review, and exploitation.
- Maintain a working understanding of how threat actors are weaponizing AI, and fold that knowledge into engagements and defensive recommendations to keep pace with a rapidly changing threat landscape.
- Bug Bounty Program Management: Manage the bug bounty program end to end — triage, impact assessment, risk scoring (CVSS), locating vulnerable code, providing mitigation guidance, thorough re-testing, and refining program policy and scope as needed.
- Vulnerability Management: Identify, triage, and drive remediation of application vulnerabilities through manual testing and exploitation, escalating systemic issues to the appropriate engineering teams.
- Threat Modeling & Risk Assessment: Lead threat modeling exercises and perform risk assessments for new and existing applications, using offensive insight to prioritize the risks that matter most.
- Incident Response: Collaborate with incident response and Blue Team partners to investigate application-related security incidents, applying offensive expertise to scope, reproduce, and understand attacker activity.
- Secure SDLC: Help define and reinforce secure development practices, including code reviews and integration of security checks into the CI/CD pipeline.
- Code Review: Perform and lead security reviews of critical PRs and code changes, and review code in most major languages.
- Security Architecture & Design: Partner with engineering and architecture teams to advise on secure systems and applications design, ensuring security is built in from the ground up.
- Subject Matter Expertise: Serve as a top technical resource to engineers across the organization. Help them reproduce vulnerabilities, understand impact, document issues, and validate the effectiveness of fixes.
- Mentorship & Leadership: Mentor junior security engineers and developers on offensive techniques, secure coding practices, and security principles. Build relationships with stakeholders and business leaders across the organization.
- Cross-Functional Collaboration: Work closely with product, engineering, DevOps, defensive security, and compliance teams to align security with business goals.
- Continuous Improvement: Maintain up-to-date knowledge of relevant offensive techniques, threats, mitigations, security best practices, and the evolving role of AI in both offensive operations and adversary activity.
- Security Tooling: Make effective use of the existing security tooling stack (e.g., SAST, SCA, DAST, IAST) to support offensive and defensive work.
Required Qualifications:
-
Bachelor's degree in computer science, cybersecurity, or a related technical field, or comparable hands-on experience in lieu of a degree.
-
Demonstrated experience leading or performing offensive security work, such as web application penetration testing or Red Team engagements, with hands-on proficiency in conventional offensive and testing techniques and industry-standard offensive tooling.
Hands-on experience using AI/LLM tools for offensive security or testing, with an understanding of how threat actors are leveraging AI in a rapidly evolving threat landscape.
-
Proficient in one modern programming language (preferably Java) and able to review code in most major languages.
-
Strong analytical and problem-solving abilities with a risk-based security approach.
-
Advanced user of Burp Suite Pro; bonus if you have created custom extensions in Java or Python or have used or modified existing extensions.
- Excellent communication and collaboration skills, with the ability to work across offensive and defensive teams, IT, engineering, and business stakeholders.
Preferred Qualifications:
- Experience running Purple Team exercises or otherwise collaborating directly with defensive/Blue Team functions to improve detection and response.
- Full stack web development experience within an active security program.
- Experience managing a bug bounty program.
- A security certification that demonstrates proficiency in offensive security, network/web/mobile/AD assessments, secure coding, and professional report creation (for example: OSCP, OSEP, CRTO, OSWA, OSWE, GWAPT, GWEB).
- Submitted reports to bug bounty programs or VDPs, and you've found a CVE along the way.
- Strong command-line and scripting skills (bash, zsh, Python) on Linux and Mac.
- Enjoy attending security conferences and occasionally participate in CTFs.
- Spend time on cyber security training platforms (HackTheBox, TryHackMe).
- Have worked with engineering teams to develop secure code libraries.
- Capable of rapidly learning and integrating emerging tools and platforms with minimal supervision.
Supporting a diverse and inclusive workforce is important to Shutterfly not only because it directly reflects our value of Embracing our Differences, but also because it’s the right thing to do for our business and for our people. We welcome all applicants and evaluate them based on their qualifications. Learn more about our commitment to Diversity, Equity, and Inclusion on our Career Site.
The compensation package for this role is based on multiple factors, such as job level, responsibilities, location, and candidate experience. The base pay ranges included below are specific to the locations listed, and may not be applicable to other locations.
California : [$128,000-181,250]
Connecticut and New York: [$128,000-165,750]
Colorado, Illinois, Minnesota and Washington: [$128,000-153,000]
Nevada: [$120,250-165,750]
Maryland and New Jersey: [$138,250-165,750]
Hawaii : [$120,250-144,750]
This position may be eligible for a bonus incentive, health benefits, a 401K program, and other employee perks. More details about our company benefits can be found at https://shutterflyinc.com/benefits/.
This opportunity can be remote, but candidates must reside in a state in which Shutterfly is registered to do business. This includes all US states except District of Columbia, North Dakota, Mississippi, Rhode Island, Vermont, and Wyoming.
This position will accept applications on an ongoing basis until filled.
#SFLYTechnology
See All 5 Application Security Engineer Jobs in North Carolina
Find roles in North Carolina that match your experience and apply in just a few clicks.
Find JobsApplication Security Engineer Jobs by City in North Carolina
Where North Carolina roles are concentrated, by current openings.
Application Security Engineer Job Market in North Carolina
A snapshot from current North Carolina openings, updated as new roles post.
Who's Hiring



Top Industries Hiring
- News & Publishing
What North Carolina Employers Look For
The qualifications that appear most often in application security engineer jobs across North Carolina.
- Bachelor's degree in computer science, cybersecurity, or a closely related engineering field
- Hands-on experience with SAST, DAST, or SCA tools such as Checkmarx, Veracode, or Snyk
- Proficiency in at least one programming language used for secure code review, such as Java or Python
- Relevant certification such as CSSLP, CEH, OSCP, or an equivalent industry-recognized credential
- Experience integrating security controls into CI/CD pipelines and DevSecOps workflows
- Familiarity with compliance frameworks including NIST, PCI-DSS, SOC 2, or HIPAA as applied in North Carolina-regulated industries
Application Security Engineer Jobs in North Carolina: Frequently Asked Questions
How do you become a application security engineer in North Carolina?
Application security engineering in North Carolina has no state-issued license, so the path runs through education and industry credentials. Most employers expect a bachelor's degree in computer science, information security, or software engineering. From there, certifications like CSSLP, OSCP, or CEH carry real weight in North Carolina hiring, particularly in the financial and defense sectors. Building a portfolio of secure code reviews or penetration testing projects strengthens an application considerably at any level.
How much do application security engineers make in North Carolina?
Application security engineers in North Carolina earn a median of about $134,710 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $83,840 for the lowest 10% to over $179,310 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire application security engineers in North Carolina?
Employers hiring application security engineers in North Carolina right now include Kaiser Permanente, SAS, and Inmar, based on current listings on Migrate Mate as of September 2026. North Carolina's dense concentration of financial institutions in Charlotte and research-driven technology firms in the Research Triangle Park area means demand stays consistent year-round across both large enterprises and mid-sized contractors.
Which North Carolina cities have the most application security engineer jobs?
Greensboro, Cary, and Charlotte account for the largest share of application security engineer openings in North Carolina. Charlotte leads because of its concentration of major banks and fintech firms, while Raleigh and Durham benefit from the Research Triangle Park ecosystem, which draws cybersecurity-focused technology companies, federal contractors, and research institutions that collectively sustain a steady volume of security engineering roles.
Are there remote application security engineer jobs in North Carolina?
Yes, and more than most fields. Application security engineering is largely code-and-tool-based work that translates well to remote settings. About 100% of application security engineer openings tied to North Carolina are remote or hybrid as of September 2026, reflecting how broadly distributed the talent search has become. Roles focused on threat modeling, code review, and security tool integration are the most consistently offered as fully remote positions.
How can I get hired as a application security engineer in North Carolina with little or no experience?
The most realistic entry path is transitioning from a software development or IT role into a junior security position, since North Carolina employers in banking and defense actively look for engineers who already understand the development lifecycle. Companies anchored in the Research Triangle, including those with federal contracts, often bring on associate security analysts who rotate through application testing and vulnerability management before specializing. Earning the CompTIA Security+ or completing a recognized cybersecurity bootcamp tied to a North Carolina community college system adds credibility to an early-career application.
Where can I find and apply to application security engineer jobs in North Carolina?
You can find and apply to application security engineer jobs in North Carolina on Migrate Mate, which lists current openings tied to this role and state. Find roles that fit your experience and specialization, then apply directly through each listing without any intermediary steps.
See All 5 Application Security Engineer Jobs in North Carolina
Find roles in North Carolina that match your experience and apply in just a few clicks.
Find Jobs