Senior AppSec Engineer — Threat Modeling & Defense

ButterflyMX

United States

On-site

USD 120,000 - 170,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical/Dental/Vision
401(k) with match
Paid holidays and time off
Life/ Disability insurance
Parental leave
Remote work stipend
AI security tooling stipend

Job summary

ButterflyMX is seeking a Senior Security Engineer to drive application security across the full software development lifecycle. You will model threats, review secure coding, perform penetration testing, and manage vulnerabilities while building internal tooling to support the defender’s loop.

You will partner with product and engineering to embed security from the start, own the active testing program, and report to the CISO as a senior contributor in a distributed, largely remote team.

Qualifications

  • 5+ years of hands-on application security experience across SDLC, with practical security risk management.
  • Strong understanding of web and API security fundamentals (OWASP, MITRE, CIS).
  • Experience with SAST/DAST/SCA ASPM tools and vulnerability management.
  • Proficiency in scripting or development languages for code reviews and tooling.
  • Ability to design and execute modern penetration tests on web/mobile apps.
  • Familiarity with cloud security (AWS preferred) and container security (Kubernetes).
  • Comfortable in regulated environments (SOC 2 or similar).
  • Excellent communication; translate risk to non-technical stakeholders.
  • Certifications (OSCP, GWAPT, GPEN, CEH) are a plus; AI tooling experience valued.

Responsibilities

  • Lead application security reviews, threat modeling sessions, and secure code reviews.
  • Operate and improve SAST/DAST/SCA tooling; triage findings with engineering teams.
  • Plan and execute internal penetration tests against web apps, APIs, and mobile clients; coordinate third‑party assessments.
  • Own the vulnerability management lifecycle from discovery to remediation and validation.
  • Develop and maintain secure coding standards and developer security guidance.
  • Integrate security tooling into CI/CD and promote shift-left security in SDLC.
  • Investigate security incidents and bug bounty submissions; provide root cause analysis.
  • Partner with Product and Engineering on security architecture decisions for new features.
  • Stay current on threats, CVEs, and attack techniques relevant to the stack.

Skills

5+ years in app security
Secure SDLC
Threat modeling
Penetration testing
SAST/DAST/SCA tools
AWS cloud security
Kubernetes security
Python/JavaScript/Go/Ruby
Communication
AI tools in security

Tools

SAST tools
DAST tools
SCA tooling
AWS
Kubernetes
CI/CD tooling
Security certifications (OSCP/GWAPT/GPEN/CEH)

Job description

ButterflyMX is seeking a Senior Security Engineer to drive application security across the full software development lifecycle. You will model threats, review secure coding, perform penetration testing, and manage vulnerabilities while building internal tooling to support the defender’s loop.

You will partner with product and engineering to embed security from the start, own the active testing program, and report to the CISO as a senior contributor in a distributed, largely remote team.

Get your free, confidential resume review.
or drag and drop your file here.