remote
Senior Security Engineer - Butterfly Network
Security Engineer
Lead security initiatives for a cloud‑native medical imaging platform, designing and implementing controls across AWS infrastructure, IAM, threat modeling, and incident response to protect patient data and AI‑driven services.
About the role
Key Responsibilities
- Design, implement, and maintain security controls for large‑scale AWS environments supporting real‑time ultrasound imaging and AI services.
- Develop and enforce identity and access management policies, including least‑privilege access, role‑based access control, and privileged account monitoring.
- Conduct threat modeling and risk assessments for new product features, ensuring compliance with healthcare regulations (HIPAA, GDPR).
- Lead incident response activities, from detection through remediation, and improve detection capabilities with automation and tooling.
- Collaborate with software, hardware, and data science teams to embed security best practices throughout the development lifecycle.
Requirements
- 5+ years of experience securing cloud‑native applications, preferably on AWS.
- Deep knowledge of IAM, network security, encryption, and security monitoring tools (e.g., GuardDuty, CloudTrail, Security Hub).
- Proven experience with threat modeling frameworks (STRIDE, PASTA) and incident response in regulated environments.
- Strong scripting or programming skills (Python, Bash) for automation of security controls and investigations.
- Excellent communication skills and ability to work cross‑functionally in a fast‑paced, highly regulated medical technology setting.