Senior Security Engineer — Secure SDLC & Pen Tests (Remote)

ButterflyMX, Inc.

United States

Remote

USD 170,000 - 200,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical, Dental and Vision plans
401(k) plan with a match
Paid holidays and vacation
Short/Long-term disability
Employee assistance program
Quarterly stipends
Flexible spending accounts (FSA/HSA)

Job summary

ButterflyMX is seeking a Senior Security Engineer to drive application security across the full software development lifecycle. You will lead threat modeling, secure code reviews, and vulnerability management, building internal tooling for the defender’s loop.

You’ll partner with product teams to embed security early in development and own our active testing program. You will work cross-functionally to embed reusable secure patterns, scale security, and influence security architecture decisions.

Qualifications

  • 5+ years of application security experience including secure SDLC and offensive testing.
  • Strong knowledge of web app and API security fundamentals (OWASP, MITRE, CIS).
  • Experience with SAST/DAST/SCA ASPM tools.
  • Proficiency in scripting languages to review code and build tooling.
  • Experience conducting modern web and mobile pentests.
  • Familiar with cloud security (AWS) and container security (Kubernetes).
  • Excellent written and verbal communication; translate risk for non-technical stakeholders.
  • Certifications (OSCP, GWAPT, GPEN, CEH or similar) a plus.

Responsibilities

  • Lead application security reviews, threat modeling sessions, and secure code reviews for new features and product changes.
  • Operate and improve SAST, DAST, and SCA tooling; triage findings with engineering teams to harden the codebase.
  • Plan and execute internal penetration tests against web apps, APIs, and mobile clients; coordinate third-party assessments.
  • Own the vulnerability management lifecycle from discovery to validation.
  • Develop and maintain secure coding standards, developer guidance, and training materials.
  • Integrate security tooling into CI/CD pipelines and promote shift-left security across the SDLC.
  • Investigate security incidents and bug bounty submissions; provide root cause analysis and remediation recommendations.
  • Partner with Product and Engineering on security architecture for new features.
  • Stay current on threats, CVEs, and attack techniques relevant to our stack.

Skills

Application security
Threat modeling
Secure code review
Penetration testing
SAST/DAST/SCA tooling
CI/CD security
Security architecture
Cloud security (AWS)
Kubernetes security
Communication skills

Tools

SAST tools
DAST tools
SCA tools
CI/CD tooling

Job description

ButterflyMX is seeking a Senior Security Engineer to drive application security across the full software development lifecycle. You will lead threat modeling, secure code reviews, and vulnerability management, building internal tooling for the defender’s loop.

You’ll partner with product teams to embed security early in development and own our active testing program. You will work cross-functionally to embed reusable secure patterns, scale security, and influence security architecture decisions.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior AppSec Engineer — Threat Modeling & Defense
Senior AppSec Engineer — Threat Modeling & Defense

ButterflyMX • United States

On-site
USD 120,000 - 170,000
Medical/Dental/Vision
401(k) with match
Paid holidays and time off
+4
Sr. Security Engineer
Sr. Security Engineer

ButterflyMX, Inc. • United States

Remote
USD 170,000 - 200,000
Medical, Dental and Vision plans
401(k) plan with a match
Paid holidays and vacation
+4
Senior App Sec Engineer: Lead Secure SDLC (Remote)
Senior App Sec Engineer: Lead Secure SDLC (Remote)

platacard • United States

Hybrid
USD 120,000 - 180,000
Relocation with visa support
Flexible work office or remote
Healthcare coverage
+3
Senior Application Security Engineer - Remote
Senior Application Security Engineer - Remote

Agile Defense • United States

On-site
USD 110,000 - 165,000
Remote Senior AppSec Engineer - SDLC & Threat Modeling
Remote Senior AppSec Engineer - SDLC & Threat Modeling

Mitek Systems • United States

Remote
USD 140,000 - 190,000
AppSec ownership
Competitive compensation
Security-focused culture
+2
Senior Application Security Engineer | Flexible/Remote
Senior Application Security Engineer | Flexible/Remote

AgileEngine • Irving (IA)

On-site
USD 130,000 - 170,000
Professional growth
Competitive compensation
Exciting projects
+1
Senior Application Security Engineer — Remote/Flexible
Senior Application Security Engineer — Remote/Flexible

AgileEngine • Boca Raton (FL)

Hybrid
USD 120,000 - 180,000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Hybrid App Security Engineer—Secure SDLC Leader
Hybrid App Security Engineer—Secure SDLC Leader

Packsize • Salt Lake City (UT)

Hybrid
USD 120,000 - 150,000
Lead Application Security Engineer: Threat Modeling & Secure SDLC
Lead Application Security Engineer: Threat Modeling & Secure SDLC

Mach7 Technologies • Burlington (VT), Northern (KY)

Hybrid
USD 120,000 - 160,000
Senior Application Security Engineer — Secure CI/CD & Cloud
Senior Application Security Engineer — Secure CI/CD & Cloud

AgileEngine • West Palm Beach (FL)

Hybrid
USD 140,000 - 180,000
Professional growth
Competitive compensation
A selection of exciting projects
+1