Flywire

Director of Security Risk Engineering

Flywire$200K — $210K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or related field; Master's preferred.
  • 12+ years in information security or cyber defense; hands-on experience in penetration testing and vulnerability management.
  • 3+ years in senior leadership within a security engineering environment managing teams and complex programs.
  • In-depth knowledge of security architecture, secure cloud infrastructure (AWS/Azure/GCP), and application security principles.

Responsibilities

  • Define and implement a security engineering strategy across multiple domains aligned with business objectives.
  • Lead and mentor the global security engineering team, handling hiring, training, and performance management.
  • Oversee the design and improvement of secure architecture for systems, networks, and applications.
  • Collaborate with cross-functional teams to integrate security controls throughout the engineering lifecycle.
  • Develop proactive risk measures using AI and automated tools to combat vulnerabilities.
  • Conduct penetration testing to identify complex security flaws within financial platforms.
  • Manage responses to major security incidents, coordinating containment and remediation efforts.

Benefits

  • Employee Stock Purchase Plan (ESPP)
  • Competitive time off, including Digital Disconnect and volunteer opportunities.
  • Access to wellbeing programs including mental health and fitness classes.
  • Engagement in a global work culture with insights via social media initiatives.
  • Talent development programs for career progression.
Full Job Description
Job Description

The Opportunity:

As the Director of Security Risk Engineering, you will serve as a key senior leader working in direct partnership with the CISO to drive, shape, and mature Flywire's global enterprise security infrastructure and systems. In this role, you will bridge the gap between high-level security strategy and tactical engineering execution across six core domains: Application Security, AI Security, Cloud Security, Corporate Security, Security Operations (SecOps), and Red Teaming (Penetration Testing).
In partnership with the internal stakeholder organizations, you will lead the organizational shift from technical recovery to global enterprise operational resilience, managing a highly impactful program that safeguards our global payment rails while fostering a culture of collaboration, innovation, and continuous improvement. A solid working knowledge of all aspects of cloud-native infrastructure, software applications, AI/LLM model development, governance & validation, and automated risk mitigation is required.
Responsibilities:
  • Strategic Domain Leadership: Define, implement, and monitor a comprehensive security engineering strategy across Application Security, AI Security, Cloud Security, Corporate Security, Security Operations (SecOps/Incident Detection & Response), and Red Teaming (Penetration Testing), aligning initiatives with global business objectives and emerging financial threats.
  • Team Management & Mentorship: Support the CISO to lead and manage the global security engineering organization, including hiring, training, mentoring, performance management, and budget oversight.
  • Secure Architecture & Governance: Oversee the design and continuous improvement of secure architecture for systems, cloud infrastructure, networks, and applications, ensuring strict alignment with security best practices.
  • Global Cross-Functional Collaboration: Partner with Business, Development, DevOps, Product, Program, Risk/Compliance, and IT leaders to seamlessly integrate security controls into all phases of the engineering and CI/CD lifecycle. Engage actively with external stakeholders, auditors and global regulators on related fronts.
  • Advanced Cyber Risk Efficacy: Leverage AI and automated tooling to develop proactive measures, threat intelligence capabilities, and scalable defenses against vulnerabilities across all engineering domains.
  • Adversarial / Penetration Testing: Personally adopt an attacker's mindset to identify complex attack chains, logic flaws, and zero-day vulnerabilities within financial platforms and product architectures.
  • Incident Response & Operational Resilience: Direct and coordinate responses to critical enterprise security incidents, managing containment, forensic investigation, and rapid remediation efforts alongside SecOps.
  • Regulatory Compliance Frameworks: Maintain an information security framework that ensures continuous readiness for strict industry audits and regulatory compliance requirements globally (e.g., NIST CSF 2.0, ISO 27001, PCI-DSS 4.0, DORA).
  • Executive & Stakeholder Reporting: Define and maintain metrics that communicate security posture, program progress, and incident risk analysis to the CISO, senior executive leadership, and the Board.
  • Innovation & Emerging Tech: Stay ahead of global fintech trends, adopting cutting-edge technologies and methodologies-specifically regarding secure AI deployment-to continuously strengthen the organization's security posture.


Qualifications

Here's What We're Looking For:
  • Education: Bachelor's degree required in Computer Science, Information Security, or a related technical field. A Master's degree is highly preferred.
  • Core Experience: 12+ years of progressive experience in information security, IT risk management, or cyber defense roles. Must be an active technical practitioner with a proven track record of independently performing manual penetration testing, vulnerability exploitation, detection/response activities, and code reviews across cloud and application infrastructures, without relying solely on automated commercial tools.
  • Leadership Experience: 3+ years of proven experience in senior leadership or management roles specifically within a security engineering organization, managing people, cross-functional teams and complex security programs.
  • Domain Mastery: In-depth technical knowledge of security architecture, secure cloud infrastructure (e.g., AWS/Azure/GCP), application security principles, and adversarial emulation (Red Teaming).

Highly Preferred Certifications
  • Core Security: CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager)
  • Governance & Risk: CRISC (Certified in Risk and Information Systems Control), CISA (Certified Information Systems Auditor), or ISACA AAISM™ (Advanced in AI Security Management)
  • Hands-On Offensive & AI: OffSec OSAI (Offensive Security AI Red Teamer), OSCP (Offensive Security Certified Professional), OSCE (Offensive Security Certified Expert), or SANS GXPN (GIAC Exploit Researcher and Advanced Penetration Tester)


Skills and Abilities
  • Strategic & Tactical Balancer with a Commercial Mindset: Highly hands-on and technically skilled. Strong strategic thinker with the ability to contribute to and translate the CISO's high-level vision into actionable plans and drive successful execution. Balances technical risk reduction with business enablement, ensuring security infrastructure serves as a competitive advantage that unblocks global revenue and enterprise-client acquisition.
  • Executive Presence: Exceptional communication and stakeholder management skills, with a demonstrated ability to articulate complex security risks and technical concepts to both engineering teams and executive management/the Board.
  • 2nd-Line Cyber Risk Oversight & Governance: Robust capability to operate as a strategic second-line risk leader. Proven experience defining enterprise security risk appetites, establishing governance frameworks, and executing independent control testing to validate that the first line (engineering/product teams) effectively manages cyber risk.
  • Defense-in-Depth Expertise: Comprehensive understanding of modern system security design principles, intrusion prevention, API security, and automated vulnerability management.
  • High-Pressure Decision Making: Demonstrated capability to prioritize tasks, maintain cross-functional transparency, and make critical risk decisions under pressure during live security incidents.
  • Lateral Influencing / Influential Leadership: Ability to collaborate effectively as a trusted partner across the global organization, promoting a collaborative culture of continuous resilience and security awareness.


Additional Information

What We Offer:
  • Competitive compensation
  • Employee Stock Purchase Plan (ESPP)
  • Competitive time off, including Digital Disconnect and FlyBetter Days to volunteer in a cause you believe in.
  • Work with brilliant people globally Learn more about their journeys by checking out #InsideFlywire on social media
  • Wellbeing Programs (Mental Health, Wellness, Yoga/Pilates/HIIT Classes) with Global FlyMates
  • Be a meaningful part in our success - every FlyMate makes an impact
  • Great Talent & Development Programs (Managers Taking Flight - for new or aspiring managers, OneFlywire Career Mobility)

Submit today and get started!

We are excited to get to know you! Throughout our process you can expect to meet with different FlyMates including the Hiring Manager, Peers on the team, the VP of the department, and a skills assessment. Your Talent Acquisition Partner will walk you through the steps and be your "go-to" person for any questions.

The US base salary range for this full-time position is $200,000 - 210,000 and benefits. Our salary ranges are determined by role, position level, and location. The range displayed on this job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. Within the range, individual pay is determined by work location and several other factors, including job-related skills, experience, relevant education and training.

#LI-Hybrid

About Flywire

Flywire is a financial technology company that provides payment solutions for businesses and institutions. The company was founded in 2009 and is headquartered in Boston, Massachusetts. Flywire's platform allows businesses to accept payments from customers around the world, with support for over 240 countries and 150 currencies. The company's solutions are used by a variety of industries, including education, healthcare, travel, and technology. Flywire has raised over $300 million in funding and has been recognized as one of the fastest-growing companies in the United States.
Learn more about Flywire
Size
500 employees
Market Cap
$2.4 billion
Industry
Founded
2009

Similar Jobs

More Jobs at Flywire

More Information Technology Jobs

Find similar Director of Security Risk Engineering jobs: