Full-Time

Information Security Governance and Control Engineer

Posted on 10/31/2025

Butterfly Network

Butterfly Network

201-500 employees

Handheld ultrasound device for point-of-care imaging

Compensation Overview

$100k/yr

+ Bonus + Equity + Benefits

New York, NY, USA

Hybrid

Hybrid role; in-office 2-3 days per week in NYC.

Category
IT & Security (2)
,
Required Skills
Agile
AWS
Requirements
  • Minimum 7+ years of cybersecurity experience, 2 of which include being in a Security Operation Center (SOC)/Computer Security Incident Response Team (CSIRT) environment.
  • Experience investigating cybersecurity events and incidents using a full suite of alerting and response tools, digital forensic or malware analysis tools.
  • Firsthand experience with Vulnerability Management preferably Rapid7, perform scans, produce reports, and track remediation.
  • Experience managing User Access Reviews, to ensure access, proper roles, and findings are accurate and timely.
  • Strong familiarity with NIST 800-53 (Rev-5).
  • Strong familiarity with ISO27001.
  • Strong Project Management skills (PMP, Six Sigma, or Agile).
  • Strong Audit Coordination Skills (interpretation, artifact collection, and mapping).
  • Skilled in Plan of Action & Milestones (POA&M)
  • Skilled in Continuous Compliance Monitoring (Con-Mon)
  • Strong written and communications skills (collaborating with employees at all levels).
  • CISSP, GIAC, and or AWS Certified Security Specialty a plus.
Responsibilities
  • Assess, triage, and prioritize security alerts from logging and monitoring systems.
  • Incident response management and breach mitigation.
  • Conduct vulnerability assessment, determine deviations from acceptable configurations, and assess the level of risk; recommend appropriate mitigation countermeasures.
  • Work in collaboration with IT, Cloud Operations, and Engineering Teams to secure our AWS environment.
  • Keep abreast of tools, techniques, and process improvements in support of security detection and analysis in accordance with current and emerging threat and attack vectors.
  • Support digital forensic activities including collecting, processing, preserve, analyze, and present evidence in support of vulnerability mitigation, and investigations.
  • Help mature and maintain an Incident Response Program.
  • Develop playbooks, work instructions, process flow, Risk Assessments, and automation solutions.
  • Evidence and artifact collection and articulation for purpose of Audit and Accreditations.
  • Supports Routine Governance and Control Meetings (e,g. Security Steering Committee, etc.)
  • Performs Third Party Risk Management of a selection of vendors via automated tool (e.g. VisoTrust).
  • Writing and maintaining a robust portfolio of prescribed Information Security Policies and Procedures.
  • Management of the Annual and Intermittent Security Training Curriculum (working with the Learning Management System (LMS) Admin.
  • Lead the administration Information Security Committee
  • Lead the administration of the BC/DR/IR Plans and Testing
  • Manage and Submit routine Con-Mon Reports to issue certification authorities.
  • Management of the Routine User Access Reviews and validation approvals.
  • Partnership with Internal/External Auditors on Statement of Compliance (SOC-2), ISO27001, C5 Germany, NHS DSPT England, GovRAMP, TX-RAMP, FedRAMP, HITRUST.
  • Contributes to Executive Presentations of the InfoSec state and environment.
  • Will require working nights (at times), weekends (at times), or holidays (at times) on a rotational basis with the rest of the team to ensure 24x7 coverage.
  • Supports our CISO in additional security initiatives and projects, as needed.
Desired Qualifications
  • CISSP, GIAC, and or AWS Certified Security Specialty a plus.

Butterfly Network makes medical imaging tools, focusing on point-of-care ultrasound (POCUS). Its main product is the Butterfly iQ, a handheld ultrasound device that uses a single probe to scan the whole body. The iQ connects to a software platform, storing images, supporting telehealth, and providing advanced imaging tools. The device is sold to doctors, nurses, and medical technicians in hospitals, clinics, and rural settings, with revenue from device sales, software subscriptions, and educational resources. What sets Butterfly Network apart is its single-probe, portable design that aims to simplify ultrasound workflows and make high-quality imaging more affordable and accessible, especially in underserved areas. The company’s goal is to improve diagnostic access and patient outcomes worldwide by delivering cost-effective, easy-to-use ultrasound technology that integrates hardware and software in one connected system.

Company Size

201-500

Company Stage

IPO

Headquarters

Burlington, Massachusetts

Founded

2011

Simplify Jobs

Simplify's Take

What believers are saying

  • Q1 2026 revenue hit $26.5M, up 25% YoY, with 68.9% gross margins.
  • GovRAMP authorization unlocks sales to all U.S. state governments.
  • Home & Community Care rollout targets H2 2026 revenue in new markets.

What critics are saying

  • Clarius AI ultrasound erodes Butterfly's POCUS share within 12 months.
  • Exo's $100M funding ramps production, pressuring Butterfly pricing in 6 months.
  • Philips Lumify 3.0 causes 25% drop in Butterfly subscription renewals.

What makes Butterfly Network unique

  • Butterfly iQ3 uses Ultrasound-on-Chip semiconductor for single-probe whole-body imaging.
  • FDA-cleared blind sweep AI tool estimates gestational age in two minutes.
  • Butterfly Embedded licenses chip technology to partners like Midjourney.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health, dental & vision insurance

Equity

401k

PTO

Flexible hybrid work

Parental leave

Home office stipend

Rewards & recognition program

LinkedIn Learning

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

1%

2 year growth

0%
The Associated Press
Mar 10th, 2026
Butterfly Network appoints David Horsley to scale Ultrasound-on-Chip licensing initiative

Butterfly Network has appointed David Horsley as Senior Vice President of Innovation for Butterfly Embedded, its ultrasound-on-chip licensing and co-development initiative. Dr Horsley will lead strategy, partnerships and commercialisation efforts to scale the programme. Dr Horsley is a Professor of Electrical and Computer Engineering at Northeastern University and previously served as Chief Technology Officer at TDK InvenSense. He co-founded Chirp Microsystems, a sensor pioneer acquired by TDK, and is a Fellow of IEEE and the National Academy of Inventors. Butterfly Embedded enables partners to integrate the company's semiconductor-based ultrasound technology into new products and applications. Chief executive Joseph DeVivo said momentum is increasing, with growing demand and early collaborations beginning to generate revenue.

Yahoo Finance
Mar 10th, 2026
Butterfly Network shares gain 64% upside potential as Q4 revenue jumps 41% to $31.5M

Butterfly Network has received a price target increase from TD Cowen to $6 from $4.50, maintaining a Buy rating with over 64% upside potential. The upgrade follows strong fourth-quarter results showing revenue of $31.5 million, up 41% year-over-year from $22.4 million. TD Cowen highlighted Butterfly Embedded as an emerging revenue stream that could transform the company from a pure medical technology business into a broader tech player. The platform supplements Butterfly's core point-of-care ultrasound business. CEO Joseph DeVivo stated the company is shifting from a medical device focus to becoming a semiconductor-based firm centred on AI-native imaging. Butterfly Network develops ultrasound imaging solutions, including its Butterfly iQ+ and iQ3 handheld devices, serving markets worldwide.

Business Wire
Feb 26th, 2026
Butterfly Network hits record $31.5M quarterly revenue, first positive operating cash flow

Butterfly Network reported record quarterly revenue of $31.5 million for Q4 2025, up 41% year-over-year, and achieved its first quarter of positive operating cash flow. The digital health company, which makes semiconductor chip-based ultrasound devices, reached a post-money valuation based on its expanded partnerships and product initiatives. US revenue grew 55% to $26.8 million, driven partly by a co-development partnership with Midjourney that contributed $6.8 million in Q4. The agreement, disclosed in November 2025, anticipates up to $74 million in payments over five years. Gross margin improved to 67.3% from 61.4% in the prior year. For fiscal year 2026, Butterfly forecasts revenue of $117 million to $121 million, representing 20% to 24% growth, with an adjusted EBITDA loss of $21 million to $25 million.

Yahoo Finance
Feb 13th, 2026
Butterfly Network gains GovRAMP authorisation, Craig-Hallum lifts price target to $5.25

Butterfly Network has secured GovRAMP and TX-RAMP authorizations for its Butterfly iQ+/iQ3 and Compass AI ultrasound solution, enabling the company to sell cloud services to all state and local government agencies, including Texas. The certifications demonstrate compliance with the highest security standards. The digital health company reported at least 17% year-over-year revenue growth in Q4, reaching $26.2 million compared to Street estimates of $25.7 million, with full-year revenue landing at $92.3 million. Growth was primarily driven by its core business, with some contribution from its Midjourney partnership. Following these announcements, Craig-Hallum raised its price target on Butterfly Network to $5.25 from $3.25 on 21 January whilst maintaining a Buy rating on the shares.

AInvest
Nov 26th, 2025
Glenview Buys 2.8M Butterfly Shares

Larry Robbins' Glenview Capital Management acquired 2.8 million shares of Butterfly Network Inc at $2.65 per share, raising its total holdings to 12.8 million shares. This strategic move in the medical devices sector impacted Glenview's portfolio by 0.16%. Despite being overvalued compared to its GF Value, the stock saw a 22.45% price gain post-transaction.

INACTIVE