
Senior Security Engineer
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in United States.
• Oversee application security assessments, facilitate threat modeling sessions, and conduct secure code reviews for new features and major product modifications.
• Manage and enhance SAST, DAST, and SCA tools; collaborate with engineering teams to triage and prioritize findings to strengthen the codebase.
• Plan and carry out internal penetration testing on web applications, APIs, and mobile clients; coordinate and assist with third-party evaluations.
• Take ownership of the vulnerability management lifecycle from identification and prioritization to remediation tracking and validation.
• Create and uphold secure coding standards, provide developer security guidance, and develop training resources.
• Integrate security tools into CI/CD pipelines and advocate for shift-left security practices throughout the SDLC.
• Investigate security incidents and bug bounty submissions; deliver root cause analysis and remediation recommendations.
• Collaborate with Product and Engineering teams on security architecture decisions for new product features.
• Stay informed about emerging threats, CVEs, and attack techniques pertinent to our technology stack and contribute to ongoing program improvements.
• Over 5 years of experience in application security, demonstrating hands-on expertise in secure development lifecycle practices and offensive testing.
• Strong grasp of web application and API security principles (OWASP, MITRE, CIS, API-specific attack surfaces).
• Experience in operating SAST/DAST/SCA ASPM tools.
• Proficient in scripting or programming languages (Python, JavaScript, Go, Ruby, or similar) adequate for code review and internal tool development.
• Proven experience in designing and executing penetration tests for contemporary web and mobile applications.
• Familiarity with cloud security (preferably AWS, with some experience in GCP and OVH) and security for containers/Kubernetes.
• Comfortable working in a regulated environment (e.g., SOC 2 or similar).
• Exceptional written and verbal communication abilities; capable of conveying technical risks to non-technical audiences.
• Relevant certifications are a plus: OSCP, GWAPT, GPEN, CEH, or equivalent.
• Demonstrated experience in utilizing AI tools in both professional and personal contexts. As ButterflyMX is an AI-driven organization, the capacity to enhance efficiency using AI is vital in all roles.
• Comprehensive Medical, Dental, and Vision plans (ButterflyMX covers 80% of the cost) starting on the first day.
• 401(k) plan with a matching contribution.
• 10 paid holidays, 20 vacation days, 5 sick days, and 3 floating holidays.
• Basic Life and Accidental Death and Dismemberment Insurance (ButterflyMX covers 100% of the cost).
• Short and Long Term Disability (ButterflyMX covers 100% of the cost).
• Paid Family Leave.
• Employee Assistance Program.
• Quarterly self-care stipends.
• Access to optional benefits including pre-tax flexible healthcare spending accounts (FSA and HSA), Dependent Care FSA, and Commuter Benefits, along with optional Supplemental Life, AD&D, Hospital Indemnity, Legal, Accident, Critical Illness, Pet, and Personal Liability Insurance.
• And more!
GTT
Packetlabs
Akamai Technologies
Carilion Clinic
Get handpicked remote jobs straight to your inbox weekly.