> Markdown version of [/jobs/ext/1218135-sr-security-engineer](https://www.wearedevelopers.com/jobs/ext/1218135-sr-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Security Engineer - **Company:** ButterflyMX, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, JavaScript (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Cloud Computing Security, Code Review, Cyber Security, Mobile Application Software, Python (Programming Language), Open Web Application Security, Systems Development Life Cycle, Ruby, Secure Coding, Software Engineering, Software Vulnerability Management, Web Applications, Scripting, Large Language Models, Software Security, Git, GWAPT, Static Application Security Testing, Golang, Programming Languages, Dynamic Application Security Testing - **Published:** July 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=3ac7bc45aa157192 ## About the Role * 5+ years of experience in application security, with hands-on proficiency in both secure development lifecycle practices and offensive testing. * Strong understanding of web application and API security fundamentals (OWASP, MITRE, CIS, API-specific attack surfaces). * Experience operating SAST/DAST/SCA ASPM tools. * Fluency in scripting or development languages (Python, JavaScript, Go, Ruby, or similar) sufficient to review code and write internal tooling. * Experience designing and executing penetration tests against modern web and mobile applications. * Familiarity with cloud security (AWS preferred, some GCP and OVH) and container/Kubernetes security. * Comfortable in a regulated environment (e.g., SOC 2 or similar). * Excellent written and verbal communication skills; able to translate technical risk to non-technical stakeholders. * Relevant certifications a plus: OSCP, GWAPT, GPEN, CEH, or equivalent. * Proven experience with leveraging AI tools in both professional and personal settings. ButterflyMX is an AI-forward organization and the ability to optimize efficiency using AI is crucial in every role. Can you use LLMs to build a threat model (bootstrap from the code, docs, and vulnerability history, entry points, git history, etc. and leverage Shostack's four questions); to build an isolation layer to run agents safely and verify exploitability matched to the threat model; to partition the search space and leverage SAST scanners or fuzzers; to filter out non-exploitable findings and triage for patch priority; and, to rate the severity based on reachability, attacker control, preconditions, authentication, read vs write, and blast radius. ## Description ButterflyMX is looking for a Senior Security Engineer to join our growing security team. In this role you will drive application security across the full software development lifecycle - from threat modeling and secure code review to penetration testing and vulnerability management. You will build the internal tooling that powers the "defender's loop" and scales security. You will partner with product teams to embed security into the development lifecycle and ensure reusable secure patterns. You will partner closely with engineering to build security in from the start, while also owning our active testing program to identify and remediate vulnerabilities before adversaries do. You will be the person engineers come to for clear and practical answers. This is an individual contributor role reporting directly to the CISO. You will help shape our security program as an early, senior hire., * Lead application security reviews, threat modeling sessions, and secure code review for new features and significant product changes. * Operate and continuously improve SAST, DAST, and SCA tooling; triage and prioritize findings in partnership with engineering teams to harden the codebase. * Plan and execute internal penetration tests against web applications, APIs, and mobile clients; coordinate and support third-party assessments. * Own the vulnerability management lifecycle from discovery, prioritization, remediation tracking, through to validation. * Develop and maintain secure coding standards, developer security guidance, and training materials. * Integrate security tooling into CI/CD pipelines and champion shift-left security practices across the SDLC. * Investigate security incidents and bug bounty submissions; provide root cause analysis and remediation recommendations. * Partner with Product and Engineering on security architecture decisions for new product capabilities. * Stay current on emerging threats, CVEs, and attack techniques relevant to our technology stack and support continuous program improvement. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)