Sr. Security Engineer
ButterflyMX · New York, NY · 3 days ago
On-siteInformation Technology$170k–$200k/yrFull-time
Responsibilities
- Lead application security reviews, threat modeling sessions, and secure code review for new features and significant product changes.
- Operate and continuously improve SAST, DAST, and SCA tooling; triage and prioritize findings in partnership with engineering teams to harden the codebase.
- Plan and execute internal penetration tests against web applications, APIs, and mobile clients; coordinate and support third-party assessments.
- Own the vulnerability management lifecycle from discovery, prioritization, remediation tracking, through to validation.
- Develop and maintain secure coding standards, developer security guidance, and training materials.
- Integrate security tooling into CI/CD pipelines and champion shift-left security practices across the SDLC.
- Investigate security incidents and bug bounty submissions; provide root cause analysis and remediation recommendations.
- Partner with Product and Engineering on security architecture decisions for new product capabilities.
- Stay current on emerging threats, CVEs, and attack techniques relevant to our technology stack and support continuous program improvement.
Requirements
- 5+ years of experience in application security, with hands-on proficiency in both secure development lifecycle practices and offensive testing.
- Strong understanding of web application and API security fundamentals (OWASP, MITRE, CIS, API-specific attack surfaces).
- Experience operating SAST/DAST/SCA ASPM tools.
- Fluency in scripting or development languages (Python, JavaScript, Go, Ruby, or similar) sufficient to review code and write internal tooling.
- Experience designing and executing penetration tests against modern web and mobile applications.
- Familiarity with cloud security (AWS preferred, some GCP and OVH) and container/Kubernetes security.
- Comfortable in a regulated environment (e.g., SOC 2 or similar).
- Excellent written and verbal communication skills; able to translate technical risk to non-technical stakeholders.
- Relevant certifications a plus: OSCP, GWAPT, GPEN, CEH, or equivalent.
- Proven experience with leveraging AI tools in both professional and personal settings.
Benefits
- Comprehensive Medical, Dental and Vision plans (ButterflyMX covers 80% of the cost)
- 10 paid holidays, 20 vacation days, 5 sick days, 3 floating holidays
- 10% 401(k) plan with a match
- Basic Life and Accidental Death and Dismemberment Insurance (ButterflyMX covers 100% of the cost)
- Short and Long Term Disability (ButterflyMX covers 100% of the cost)
- Paid Family Leave
- Employee Assistance Program
- Quarterly self-care stipends
- Access to optional benefits including pre-tax flexible healthcare spending accounts (FSA and HSA), Dependent Care FSA, and Commuter Benefits, as well as optional Supplemental Life, AD&D, Hospital Indemnity, Legal, Accident, Critical Illness, Pet, and Personal Liability Insurance
Pay
The expected base salary range for this position is $170,000-$200,000. Actual compensation will depend on factors including budget, skills, experience, location, and internal equity. This position may also be eligible for bonuses, equity, or other forms of compensation, where applicable.
Schedule
This is an individual contributor role reporting directly to the CISO. You will help shape our security program as an early, senior hire.