Sr. Security Engineer

RiverPark Ventures

New York (NY)

On-site

USD 170,000 - 200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, Dental, Vision
401(k) match
Paid time off
Disability insurance
Life insurance
HSA/FSA options

Job summary

ButterflyMX is seeking a Senior Security Engineer to drive application security across the full software development lifecycle. You will lead threat modeling, secure code reviews, and implement vulnerability management while building internal tooling to support the defender’s loop.

You will partner with product and engineering teams to embed security from the start, run internal penetration tests, and maintain secure coding standards.

Qualifications

  • 5+ years of application security experience with secure SDLC and offensive testing.
  • Strong understanding of web app and API security fundamentals (OWASP, MITRE, CIS).
  • Experience operating SAST/DAST/SCA tools and CI/CD security integration.
  • Fluency in scripting languages for code review and tooling (Python/JavaScript/Go).
  • Experience in penetration testing of web and mobile apps; cloud security knowledge (AWS).

Responsibilities

  • Lead application security reviews, threat modeling sessions, and secure code reviews.
  • Operate and improve SAST/DAST/SCA tooling; triage findings with engineering teams.
  • Plan and execute internal penetration tests against web apps, APIs, and mobile clients.
  • Own vulnerability management lifecycle from discovery to remediation.
  • Develop secure coding standards and security guidance for developers.
  • Integrate security tooling into CI/CD pipelines and promote shift-left security.
  • Investigate security incidents and provide remediation recommendations.
  • Partner with Product and Engineering on security architecture decisions.

Skills

Application security
Offensive testing
SAST/DAST/SCA
Cloud security
Python/JS/Go

Tools

SAST tooling
DAST tooling
SCA tooling

Job description

Overview

ButterflyMX is on a mission to empower people to automate property access, operations, and security from a single platform. Our products are installed in more than 20,000 multifamily, commercial, gated communities, and student-housing properties worldwide. Our features are designed for developers, owners, property managers, and tenants, and our products lower operating costs and improve tenant satisfaction. ButterflyMX is an AI-forward organization; the ability to optimize efficiency using AI is crucial in every role.

Our solution: Developers and owners no longer need to run building wiring or install in-unit hardware. Property managers can grant building access, revoke permissions, and review entry logs from an online dashboard. Residents can open doors from their smartphones, issue visitor access, and see who is trying to enter the building.

Our culture & values: Fantastic people are the key to our success. We’re a distributed, primarily remote workforce, seeking intelligent, passionate, collaborative, ai-forward, and down-to-earth individuals. We’re driven by a commitment to excellence and innovation, grounded in our core values: delight customers, take ownership, collaborate as a community, speak up, think big and do small, and be tenacious.

Role Overview

ButterflyMX is looking for a Senior Security Engineer to join our growing security team. In this role you will drive application security across the full software development lifecycle—from threat modeling and secure code review to penetration testing and vulnerability management. You will build internal tooling that powers the defender’s loop and scales security. You will partner with product teams to embed security into the development lifecycle and ensure reusable secure patterns. You will partner closely with engineering to build security in from the start, while also owning our active testing program to identify and remediate vulnerabilities before adversaries do. You will be the person engineers come to for clear and practical answers. This is an individual contributor role reporting directly to the CISO. You will help shape our security program as an early, senior hire.

Responsibilities
  • Lead application security reviews, threat modeling sessions, and secure code review for new features and significant product changes.
  • Operate and continuously improve SAST, DAST, and SCA tooling; triage and prioritize findings in partnership with engineering teams to harden the codebase.
  • Plan and execute internal penetration tests against web applications, APIs, and mobile clients; coordinate and support third-party assessments.
  • Own the vulnerability management lifecycle from discovery, prioritization, remediation tracking, through to validation.
  • Develop and maintain secure coding standards, developer security guidance, and training materials.
  • Integrate security tooling into CI/CD pipelines and champion shift-left security practices across the SDLC.
  • Investigate security incidents and bug bounty submissions; provide root cause analysis and remediation recommendations.
  • Partner with Product and Engineering on security architecture decisions for new product capabilities.
  • Stay current on emerging threats, CVEs, and attack techniques relevant to our technology stack and support continuous program improvement.
Requirements
  • 5+ years of experience in application security, with hands-on proficiency in both secure development lifecycle practices and offensive testing.
  • Strong understanding of web application and API security fundamentals (OWASP, MITRE, CIS, API-specific attack surfaces).
  • Experience operating SAST/DAST/SCA tools.
  • Fluency in scripting or development languages (Python, JavaScript, Go, Ruby, or similar) sufficient to review code and write internal tooling.
  • Experience designing and executing penetration tests against modern web and mobile applications.
  • Familiarity with cloud security (AWS preferred, some GCP and OVH) and container/Kubernetes security.
  • Comfortable in a regulated environment (e.g., SOC 2 or similar).
  • Excellent written and verbal communication skills; able to translate technical risk to non-technical stakeholders.
  • Relevant certifications a plus: OSCP, GWAPT, GPEN, CEH, or equivalent.
  • Proven experience with leveraging AI tools in both professional and personal settings. Ability to optimize efficiency using AI is crucial in this role; capability to use LLMs to build threat models, isolation layers for safe agent execution, partition search space for SAST/fuzzing, and triage findings for patch priority.
Compensation

The expected base salary range for this position is $170,000-$200,000. Actual compensation will depend on factors including budget, skills, experience, location, and internal equity. This position may also be eligible for bonuses, equity, or other forms of compensation, where applicable.

Benefits
  • Comprehensive Medical, Dental and Vision plans (ButterflyMX covers 80% of the cost) starting day 1
  • 401(k) plan with a match
  • 10 paid holidays, 20 vacation days, 5 sick days, 3 floating holidays
  • Basic Life and Accidental Death and Dismemberment Insurance (ButterflyMX covers 100% of the cost)
  • Short and Long Term Disability (ButterflyMX covers 100% of the cost)
  • Paid Family Leave
  • Employee Assistance Program
  • Quarterly self-care stipends
  • Access to optional benefits including pre-tax flexible healthcare spending accounts (FSA and HSA), Dependent Care FSA, and Commuter Benefits, as well as optional Supplemental Life, AD&D, Hospital Indemnity, Legal, Accident, Critical Illness, Pet, and Personal Liability Insurance
  • And more!

ButterflyMX is an equal opportunity employer and we value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. You must have the authorization to work in the US to become an employee. We strive to create an accessible and inclusive experience for all candidates and employees. If you need reasonable accommodations during the application or the recruiting process, please let our recruiting team know.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Engineer
GRC Engineer

RiverPark Ventures • New York (NY)

On-site
USD 130,000 - 170,000
Medical, Dental and Vision plans
401(k) plan with match
Paid holidays
+7
Director, AI Strategy & Transformation
Director, AI Strategy & Transformation

RiverPark Ventures • United States

Hybrid
USD 200,000 - 300,000
Medical plan
401(k) match
Paid holidays
+4
Director of Information Technology
Director of Information Technology

RiverPark Ventures • New York (NY)

On-site
USD 190,000 - 210,000
Medical, Dental, Vision
401(k) with match
Paid time off
+1
Chief Information Security Officer
Chief Information Security Officer

ButterflyMX • New York (NY)

On-site
USD 150,000 - 200,000
Comprehensive Medical, Dental, and Vision plans
401(k) plan with a match
25 days PTO
+1
Manager, Software Engineering
Manager, Software Engineering

Ekho Dealer (YC S22) • United States

On-site
USD 120,000 - 160,000
Comprehensive Medical, Dental and Vision plans
401(k) plan with a match
20 vacation days
+1
Senior Security Engineer
Senior Security Engineer

Butterfly Network • New York (NY)

On-site
USD 130,000 - 140,000
Comprehensive health insurance
401k plan and match
Unlimited Paid Time Off
+2
Principal AI-Native Software Engineer
Principal AI-Native Software Engineer

Far Coder • Northern (KY)

Hybrid
USD 215,000 - 250,000
Medical, Dental, Vision
401(k) match
Paid time off
Channel Sales Territory Manager
Channel Sales Territory Manager

ButterflyMX • United States

On-site
USD 90,000 - 100,000
Medical, Dental, Vision plans
401(k) plan with match
Paid holidays, vacation, and sick days
+6
Staff Product Designer
Staff Product Designer

Ekho Dealer (YC S22) • United States

Hybrid
USD 95,000 - 120,000
Comprehensive Medical, Dental and Vision plans
401(k) plan with a match
Paid Family Leave
Staff Data Engineer
Staff Data Engineer

the enough company • United States

Hybrid
USD 185,000 - 195,000
Health insurance
401k plan and match
ESPP
+4