
Sr. Security Engineer
ButterflyMX3 months ago
Responsibilities
- Lead application security reviews, threat modeling sessions, and secure code reviews for new features and significant product changes
- Operate and continuously improve SAST, DAST, and SCA tooling while triaging and prioritizing findings with engineering teams
- Plan and execute internal penetration tests against web applications, APIs, and mobile clients, and coordinate third-party assessments
- Own the vulnerability management lifecycle from discovery and prioritization through remediation tracking and validation
- Develop secure coding standards, developer security guidance, and training materials
- Integrate security tooling into development pipelines and promote shift-left security across the software development lifecycle
- Investigate security incidents and bug bounty submissions and provide root cause analysis and remediation recommendations
- Partner with Product and Engineering on security architecture decisions for new capabilities
- Track emerging threats, CVEs, and attack techniques relevant to the technology stack and improve the security program continuously
Requirements
- At least 5 years of application security experience with hands-on secure development lifecycle and offensive testing experience
- Strong understanding of web application and API security fundamentals, including OWASP, MITRE, CIS, and API-specific attack surfaces
- Experience operating SAST, DAST, SCA, and ASPM tools
- Fluency in Python, JavaScript, Go, Ruby, or a similar scripting or development language for code review and internal tooling
- Experience designing and executing penetration tests against modern web and mobile applications
- Familiarity with cloud security, including AWS, GCP, or OVH, and container/Kubernetes security
- Comfort working in a regulated environment such as SOC 2
- Strong written and verbal communication skills, including the ability to explain technical risk to non-technical stakeholders
- OSCP, GWAPT, GPEN, CEH, or equivalent certification is a plus
- Proven experience leveraging AI tools in professional and personal settings, including LLM-assisted threat modeling, exploitability verification, vulnerability triage, and severity assessment
- Authorization to work in the United States
Benefits
- Distributed, primarily remote workforce
- Medical, dental, and vision plans starting day one, with ButterflyMX covering 80% of the cost
- 401(k) plan with employer match
- 10 paid holidays, 20 vacation days, 5 sick days, and 3 floating holidays
- Life and accidental death and dismemberment insurance, fully covered by ButterflyMX
- Short- and long-term disability insurance, fully covered by ButterflyMX
- Paid family leave and an Employee Assistance Program
- Quarterly self-care stipends
- Optional FSA, HSA, Dependent Care FSA, commuter, supplemental insurance, and other benefits
- US work authorization is required
Tech Stack
Categories
About ButterflyMX
ButterflyMX builds a smartphone-based access control and property management platform for multifamily, commercial, and gated properties, combining cloud software with video intercoms, keypads, package rooms, and smart lock integrations. The company sells hardware plus subscriptions that let owners and managers control doors, gates, elevators, and garages from web or mobile. Founded in 2014 and headquartered in New York, ButterflyMX is privately held and serves real estate operators across North America.