Talent.com
Information Security Governance and Control Engineer

Information Security Governance and Control Engineer

Butterfly NetworkNew York, NY, US
job_description.job_card.variable_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Job Description

Job Description

Company Description

At Butterfly Network, we're leading a digital revolution in medical imaging, transforming an industry that has long relied on bulky, analog systems. With our proprietary Ultrasound-on-Chip™ technology, we're democratizing healthcare by shifting ultrasound from the expensive, stationary systems of the past to the connected, mobile, and software-enabled platforms of today. In 2018, we launched the world's first handheld, whole-body ultrasound, Butterfly iQ – followed by iQ+ in 2020 and iQ3 in 2024, each more powerful than the last.

Our innovation doesn't stop at hardware. Butterfly combines our advanced device with intelligent software, AI, services, and education to drive adoption of affordable, accessible imaging. Our technology is proving to help clinicians, clinics, and hospitals enhance care, cut costs, and expand imaging access. We've been recognized by Prix Galien USA, Fierce 50, TIME's Best Inventions, Fast Company's World Changing Ideas, among other awards.

We're a team of bold thinkers, problem-solvers, and innovators ready to shape the future of medical imaging. Let's build something extraordinary together!

Job Description

You will be working in Butterfly's fast-growing Information Security (InfoSec) team to better meet the needs of our customers in the global healthcare sector. As a Security Engineer, you will have the opportunity to work closely with our DevOps, Hardware, Software, AI, Risk Management, Audit, Quality Team, and Cloud Engineering Teams to secure our product and our cloud security architecture. As we scale our business internationally and into large enterprises, security has never been more important to our company and those patients we help every day. Manage, Monitor, and Maintain Global Security Certifications rooted in National Institute of Standards and Technology (NIST) - International Organization for Standardization (ISO) - Health Information Technology for Economic and Clinical Health (HITECH) - International Electrotechnical Commission (IEC).

As part of our team, your core responsibilities will be :

  • Assess, triage, and prioritize security alerts from logging and monitoring systems.
  • Incident response management and breach mitigation.
  • Conduct vulnerability assessment, determine deviations from acceptable configurations, and assess the level of risk; recommend appropriate mitigation countermeasures.
  • Work in collaboration with IT, Cloud Operations, and Engineering Teams to secure our AWS environment.
  • Keep abreast of tools, techniques, and process improvements in support of security detection and analysis in accordance with current and emerging threat and attack vectors.
  • Support digital forensic activities including collecting, processing, preserve, analyze, and present evidence in support of vulnerability mitigation, and investigations.
  • Help mature and maintain an Incident Response Program.
  • Develop playbooks, work instructions, process flow, Risk Assessments, and automation solutions.
  • Evidence and artifact collection and articulation for purpose of Audit and Accreditations.
  • Supports Routine Governance and Control Meetings (e,g. Security Steering Committee, etc.)
  • Performs Third Party Risk Management of a selection of vendors via automated tool (e.g. VisoTrust).
  • Writing and maintaining a robust portfolio of prescribed Information Security Policies and Procedures.
  • Management of the Annual and Intermittent Security Training Curriculum (working with the Learning Management System (LMS) Admin.
  • Lead the administration Information Security Committee
  • Lead the administration of the BC / DR / IR Plans and Testing
  • Manage and Submit routine Con-Mon Reports to issue certification authorities.
  • Management of the Routine User Access Reviews and validation approvals.
  • Partnership with Internal / External Auditors on Statement of Compliance (SOC-2), ISO27001, C5 Germany, NHS DSPT England, GovRAMP, TX-RAMP, FedRAMP, HITRUST.
  • Contributes to Executive Presentations of the InfoSec state and environment.
  • Will require working nights (at times), weekends (at times), or holidays (at times) on a rotational basis with the rest of the team to ensure 24x7 coverage.
  • Supports our CISO in additional security initiatives and projects, as needed.

Qualifications

  • Baseline skills / experiences / attributes :
  • Minimum 7+ years of cybersecurity experience, 2 of which include being in a Security Operation Center (SOC) / Computer Security Incident Response Team (CSIRT) environment.
  • Experience investigating cybersecurity events and incidents using a full suite of alerting and response tools, digital forensic or malware analysis tools.
  • Firsthand experience with Vulnerability Management preferably Rapid7, perform scans, produce reports, and track remediation.
  • Experience managing User Access Reviews, to ensure access, proper roles, and findings are accurate and timely.
  • Strong familiarity with NIST 800-53 (Rev-5).
  • Strong familiarity with ISO27001.
  • Strong Project Management skills (PMP, Six Sigma, or Agile).
  • Strong Audit Coordination Skills (interpretation, artifact collection, and mapping).
  • Skilled in Plan of Action & Milestones (POA&M)
  • Skilled in Continuous Compliance Monitoring (Con-Mon)
  • Strong written and communications skills (collaborating with employees at all levels).
  • CISSP, GIAC, and or AWS Certified Security Specialty a plus.
  • Values

    Innovation is what we do. Our values are how we make it happen. Butterflies are and believe in…

  • Patient-Centric Innovators : Our mission is THE mission.
  • Empowered to Impact : Every voice matters.
  • One Team, One Goal : Unity fuels progress.
  • Growth Champions : We embrace challenges.
  • Action-Oriented Achievers : We follow through, every time.
  • Location

    Butterfly offers a hybrid work model for most positions, with team members spending two or more days a week in the office. While flexibility is key, we value in-person connections that spark creativity and teamwork. Our offices are designed for collaboration, with comfortable workspaces, stocked kitchens, and opportunities to connect with peers.

    This is a hybrid position and will be based out of our office in New York City Office two to three days every week.

    Benefits and Perks

  • Comprehensive health insurance, encompassing dental and vision coverage, is provided to all our employees. As a health-tech company, we prioritize the well-being of our teams. Additionally, employees have the option to buy up for enhanced health insurance coverage. We also contribute to Health Savings Account (HSA) accounts for all enrolled employees on an annual basis.
  • Comprehensive Employee Assistance Program - we provide access to tools and resources to support your emotional health and day-to-day needs.
  • 401k plan and match - we facilitate your retirement goals.
  • Eligible employees will have the opportunity to participate in Employee Stock Purchase Plan (ESPP)
  • Unlimited Paid Time Off + 10 Holiday Days a Year - recharge and come back ready to make an impact
  • Parental Leave - we aim to provide our employees with time to bond with their growing family, along with additional support for primary caregivers to help transition back to work
  • Competitive salaried compensation - we value our employees and show it
  • Equity - we want every employee to be a stakeholder
  • The opportunity to build a revolutionary healthcare product and save millions of lives!
  • Compensation

    Our estimated salary for this role based in NYC is around $100,000 base + bonus + equity + benefits. Actual pay is determined by multiple factors such as skills, qualifications, experience and market demand.

    For this role, we are only considering candidates who are legally authorized to work in the United States and who do not now or in the future require sponsorship for employment visa status.

    Butterfly Network does not accept agency resumes.

    Butterfly Network is an E-Verify Company.

    Butterfly Network is an equal opportunity employer. Regardless of race, traits associated with race, color, ancestry, religion, gender, national origin, sexual orientation, age, citizenship, marital status, disability or Veteran status. All your information will be kept confidential according to EEO guidelines.

    Butterfly requires security adherence responsibilities from all employees. These include : adhering to all company security policies and procedures, utilize provided company assets securely, and complete all required security awareness training programs. Safeguarding company data and systems from unauthorized access, modification, or destruction, contributing to the overall security posture of the organization. Immediately reporting any suspected or actual security incidents, including phishing attempts, malware infections, or unauthorized access, following the established incident response procedures.

    #LI-KG

    #KG-LI

    serp_jobs.job_alerts.create_a_job

    Information Security Engineer • New York, NY, US

    Job_description.internal_linking.related_jobs
    • serp_jobs.job_card.promoted
    Security Engineer, IDAM

    Security Engineer, IDAM

    VirtualVocationsElizabeth, New Jersey, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Engineer, IDAM Operations.Key Responsibilities Manage user access provisioning and resolve access issues Support complex application account provisioning and ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Infrastructure Security - Security Engineer

    Infrastructure Security - Security Engineer

    CoreWeaveLivingston, NJ, US
    serp_jobs.job_card.permanent
    CoreWeave is the AI Hyperscaler™, delivering a cloud platform of cutting edge services powering the next wave of AI.Our technology provides enterprises and leading AI labs with the most perfo...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    FIPS 140 Security Engineer

    FIPS 140 Security Engineer

    VirtualVocationsBronx, New York, United States
    serp_jobs.job_card.full_time
    A company is looking for a FIPS 140 Security Engineer to support national defense through IT security projects.Key Responsibilities Work on varied FIPS 140 validation projects including general s...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Tanium Security Engineer

    Senior Tanium Security Engineer

    VirtualVocationsNew York, New York, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Tanium Security & Asset Visibility Engineer.Key Responsibilities Implement cybersecurity and IT asset lifecycle management strategies Protect digital networks, ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    Information Security Analyst

    Information Security Analyst

    VDart IncStamford, CT, United States
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Job role : Information Security Analyst Duration : 6 months to start, potential extension or FTE conversion &l...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Lead IT Security Engineer

    Lead IT Security Engineer

    VirtualVocationsAstoria, New York, United States
    serp_jobs.job_card.full_time
    A company is looking for a Lead IT Security Engineer.Key Responsibilities Manage and optimize the Splunk security environment for performance and efficiency Architect cybersecurity solutions and...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Information Security Analyst (Application Security)

    Information Security Analyst (Application Security)

    ASCAPNew York, NY, US
    serp_jobs.job_card.full_time
    The American Society of Composers, Authors and Publishers (ASCAP) is a membership association of more than one million songwriters, composers and music publishers, and represents some of the world&...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Lead Security Engineer - Cyber Security

    Lead Security Engineer - Cyber Security

    RelativityNewark, NJ, United States
    serp_jobs.job_card.full_time
    As a Lead Cyber Security Engineer, you will ensure the security of Relativity's network and infrastructure.In this role, the main responsibilities will be to investigate and analyze emerging threat...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Security Architect, IGA

    Security Architect, IGA

    VirtualVocationsJamaica, New York, United States
    serp_jobs.job_card.full_time
    A company is looking for an IGA Architect (Remote in the US).Key Responsibilities Implement and enhance Entra ID Governance solutions Gather and document technical requirements and design Act a...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Director of Information Security

    Director of Information Security

    VirtualVocationsJamaica, New York, United States
    serp_jobs.job_card.full_time
    A company is looking for a Director of Information Security.Key Responsibilities Develop and execute a comprehensive information security roadmap Oversee security governance and risk management,...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    IAM Security Architect

    IAM Security Architect

    VirtualVocationsPaterson, New Jersey, United States
    serp_jobs.job_card.full_time
    A company is looking for an IAM and Security Services Architect.Key Responsibilities Define IAM and security services architecture roadmap, standards, and reference models Architect identity sol...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Information Security Analyst

    Information Security Analyst

    VirtualVocationsNewark, New Jersey, United States
    serp_jobs.job_card.full_time
    A company is looking for an Information Security Analyst to detect, prevent, and respond to information threats and security breaches. Key Responsibilities Maintain information security policies a...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Information Security Training Lead

    Information Security Training Lead

    VirtualVocationsNewark, New Jersey, United States
    serp_jobs.job_card.full_time
    A company is looking for an Information Security Training Awareness Lead to enhance cybersecurity awareness through training and outreach initiatives. Key Responsibilities Develop and implement an...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    VirtualVocationsJamaica, New York, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Application Security Engineer.Key Responsibilities Develop and implement technical security policies and procedures, and perform security measures Scan and test...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Principal Security Engineer

    Senior Principal Security Engineer

    VirtualVocationsElizabeth, New Jersey, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Principal Security Engineer.Key Responsibilities Collaborate to define and document the long-term security technology strategy Promote alignment on the security...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Security Engineer

    Senior Security Engineer

    VirtualVocationsElizabeth, New Jersey, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Security Engineer (US Remote).Key Responsibilities Implement and maintain security controls in AWS and Azure environments Participate in software and infrastruc...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Information Security Engineer

    Information Security Engineer

    VirtualVocationsElizabeth, New Jersey, United States
    serp_jobs.job_card.full_time
    A company is looking for an Information Security Engineer to join their Information Security and Technology team.Key Responsibilities Drive decision-making for platform and application security a...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Cloud Security Engineer

    Senior Cloud Security Engineer

    VirtualVocationsElizabeth, New Jersey, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Cloud Security Engineer.Key Responsibilities Implement and automate security controls using AWS native tools and third-party solutions Monitor AWS environments ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30