ButterflyMX

Product Security Engineer

Remote US
AWS Terraform API
Description

Our Mission:
ButterflyMX is on a mission to empower people to open and manage doors & gates from a smartphone. Our products are installed in more than 15,000+ multifamily, commercial, gated communities, and student-housing properties worldwide, including properties developed, owned, and managed by the most trusted names in real estate. Our features are designed for developers, owners, property managers, and tenants and our products lower operating costs and improve tenant satisfaction.

Our Solution:
Developers and owners no longer need to run building wiring or install in-unit hardware. Property managers can grant building access, revoke permissions, and review entry logs from an online dashboard. Residents can open doors from their smartphones, issue visitor access, and see who is trying to enter the building.

Our Culture & Values:
Fantastic people are the key to our success. As a distributed, primarily remote workforce, we’re looking for more intelligent, passionate, collaborative, and down-to-earth individuals to join our growing team. We’re driven by a shared commitment to excellence and innovation, grounded in our core values: We delight our customers, We take ownership, We are a community of collaborators, We speak up, We think big and do small, and We are tenacious.

About the role

Are you ready for an exciting, unique & game-changing opportunity? Join us as a Product Security Engineer at ButterflyMX, where you will assume a pivotal role in delivering substantial value to the organization by prioritizing the protection of clients', tenants’ & employees' information assets, ensuring the comprehensive security of systems & data. You will mature, build, scale & operationalize our information security program as a senior security engineer. Your expertise will be instrumental in safeguarding our innovative solutions & protecting our valuable assets &, most importantly, our customers & tenants. 

As our Product Security Engineer at ButterflyMX, you'll wear multiple “security hats” to ensure the resilience, safety, confidentiality, availability & integrity of our cloud, IoT, mobile, web-based solutions & data throughout the environment. This role will report directly into our VP of Information Security & Privacy.

What You’ll Do

  • Design, implement, mature & maintain our robust security controls & processes across our technology stack to protect sensitive data & systems
  • This role will wear multiple hats, including Security Engineer, SOC Analyst, GRC Analyst, & Privacy Analyst while the team is building out. You should be flexible, a go-getter & a self-starter to be successful in this role.
  • Lead vulnerability management & remediation efforts to improve the security posture & resiliency of ButterflyMX – prioritizing solutions, implementing mitigations, & designing strategic preventative controls
  • Build out Security Assessment, red-teaming, application security & product security capabilities
  • Manage internal & external penetration testing efforts. You should be comfortable executing a penetration test with both manual & automated testing techniques, doing source code reviews, & working with developers &/or devops engineers to remediate the findings.
  • Mature & lead threat modeling 
  • Ensure security controls are implemented to enable compliance with industry standards, regulations, frameworks,& best practices (e.g., SOC2, ISO, NIST, CIS, GDPR, CCPA)
  • Evaluation, analysis & implementation of new security technologies & solutions to enhance the organization’s security posture
  • Collaborate with cross-functional teams to integrate security & privacy seamlessly into our product development lifecycle
  • Stay up-to-date with the latest security threats, technologies, & trends to proactively protect our systems
  • Develop & conduct regular security awareness training & security education programs for employees
  • Serve as a point of contact for customers & partners regarding security-related inquiries
  • Foster a culture of security awareness & accountability throughout the organization

  • 5+ years of security engineering experience building, managing & scaling security operations at a fast-paced, agile/dynamic, cloud native, technology-driven startup
  • You enjoy working as a security engineer in organizations that develop software as a service &/or operate managed infrastructure & technology services for their own customers
  • Experience securing a tech stack/solution that includes SaaS, Mobile, & IoT
  • Experience working with cross-functional teams to identify & mitigate security, compliance & data privacy risks
  • Proficiency with performing penetration testing, application security assessments & secure code reviews on applications with an AWS cloud tech stack built for providing SaaS.
  • Expertise in developing & maturing Threat Models working with engineering teams to ensure application resiliency
  • Expertise in DevSecOps practices, such as automating security testing within CI/CD pipelines & conducting static & dynamic code analyses, through remediation of findings.
  • Experience automating security controls. Proven technical proficiency using Terraform & other infrastructure as code tools, with a strong track record of managing vulnerabilities in ephemeral cloud infrastructure environments.
  • Extensive experience & expertise across multiple security domains including cloud security, data security, network security, application security, incident management, threat/vulnerability/patch/configuration management, identity & access management..
  • Strong understanding of security best practices, frameworks, standards, & compliance requirements, & particularly how these apply to a startup environment through enterprise environments. Experience maturing security controls as an organization matures.
  • Experience maintaining SOC 2 Type II compliance & associated security controls within an organization
  • Demonstrated technical expertise in implementing data privacy controls & safeguards to include facilitating the deployment of technical measures to ensure compliance with data privacy regulations such as GDPR & CCPA
  • Incident response management: Experience in developing & implementing incident response plans, conducting investigations, & managing security incidents effectively
  • Demonstrated ability to educate an engineering audience about technical application security vulnerabilities, i.e., OWASP Top Ten, OWASP API Security Top 10
  • Adept in a data-driven approach for decision-making & a risk-based mindset to prioritize & address security concerns effectively.
  • Experience with implementing Security & Privacy by design principles into a development lifecycle involving incorporating threat modeling to identify potential risks & ultimately design appropriate security controls.
  • Customer focused & Solution oriented, Enthusiastic, Empathetic, Adaptable/Flexible, Bias for Action, Forward thinking, Optimistic, Trusted Advisor
  • Important to see everyone is a customer & that everyone is on the security team
  • A strong inclination to dive into the details, actively engaging in hands-on work
  • Continuous improvement mindset. Pursues ongoing professional development, stays updated with emerging threats & technologies.
  • Industry certifications such as AWS Security Certified, CISSP, CCSP, CSSLP, GXPEN, OSCP, SANS Certifications, Burp Suite Certified, Security+, CEH, CIPP, CIPT
ButterflyMX
ButterflyMX
Real Estate Security Smart Home Software

0 applies

5 views

Other Jobs from ButterflyMX

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

60,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 452 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

To try it out

For active job seekers

For those who are passive looking

Cancel anytime

Frequently Asked Questions

  • We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
  • We've got about 70,000 jobs from 5,000 vetted companies. No fake or sleazy jobs here!
  • We aggregate jobs from 5,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
  • We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
  • Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
  • Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
  • Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅

What Fellow Engineers Say

Sid avatar
Sid
Very nice portal for searching jobs in this rough market.
Mar 6, 2025
Michael Duran avatar
Michael Duran
Software Engineer
I've been using this job search site for a while now, and it’s honestly one of the best out there! The clean and easy-to-navigate UI makes the whole job-hunting process so much smoother. Plus, the job postings are always up-to-date, so I never feel like I’m wasting time. The cherry on top is the owner—super kind and always quick to respond. Definitely recommend checking it out if you're on the job hunt!
Aug 21, 2024
Sai avatar
Sai
It’s really great website for finding jobs based on skills it’s really helpful give a go
Aug 21, 2024
Adinadh avatar
Adinadh
What I like most about Echo Jobs is how easy it is to use. The platform helps me quickly find jobs that match my skills and interests, thanks to its great recommendations and filters. Yes, I would definitely recommend Echo Jobs to a friend. It makes job searching simple and efficient, making it a great tool for anyone looking for a new job.
Jul 23, 2024
As a student navigating the job market, I've found LinkedIn increasingly frustrating due to numerous fake postings by consultancies. In contrast, this job posting website has been a game-changer for me. It offers genuine opportunities and a straightforward application process, making it much easier to find and apply for real jobs. Highly recommend it to fellow students seeking reliable job listings!
Jul 16, 2024
Cliff Gor avatar
Echo Jobs has been exceptional in my job hunt where it provides one platform to job hunt and I don't have to open 10 websites just to look for a job. It has also helped me focus much on the job skill and the location filtering out the onsite jobs and remote ones. The only feature that I would request is to display fully remote jobs that are not restricted to a country since the one available shows ie, Remote, US yet. But if it could show remote only, that would be helpful not only to me but to other people applying for full remote and not tied to only US candidates
Apr 22, 2024
I found EchoJobs in 2022, and I love it. It has a lot of remote jobs. It's exclusive to software and technology jobs (helpful for devs like me). What I like the most are its filters and its API. If you're a tech professional seeking remote work, I highly recommend giving it a try to EchoJobs.
Mar 4, 2024
Would definitely recommend it! Excellent product, dedicated founder, Jobs are easier to find. Congrats 🎉 to the entire team!
Mar 3, 2024
Brandon Banks avatar
Brandon Banks
Echo Jobs is really impressive. It provides a great user experience with an ability to quickly search through the many job postings. There is an impressive amount of jobs here and it is quickly updated. The details in the each job posting is helpful when determining if it is worth pursuing. I would highly recommend using Echo Jobs to find the next step in your career.
Mar 2, 2024
Tyler Young avatar
Tyler Young
tylerayoung.com
Best wishes with EchoJobs—it's become my favorite job board overnight!
Dec 16, 2023
Simply put, it's the most up to date tech jobs aggregator I’ve found. I'm like... "I don't have to check 10+ jobs boards daily just to see if there's a new job listing? sign me up!" The filters are also quite helpful! The UI is very clean and straightforward. Love it!
Oct 5, 2023