Flywire

Security Engineer, Application Security

Flywire$109K — $114K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Master's in Computer Science or equivalent with Info Sec focus
  • 1+ year experience in application or information security
  • Proficient with vulnerability and risk management tools like Tenable and Qualys
  • Hands-on experience with application security testing tools like Veracode and BurpSuite
  • Strong programming skills in Ruby on Rails, Java, Python, or Go

Responsibilities

  • Ensure application security throughout the development lifecycle
  • Conduct thorough application security reviews and secure code analysis
  • Integrate security testing into CI/CD pipelines with GitLab
  • Design security protocols for healthcare and educational applications
  • Perform threat modeling and vulnerability assessments regularly
  • Develop cryptographic solutions to protect sensitive data
  • Support client and third-party security audits efficiently

Benefits

  • Remote work flexibility from any location in the US
  • Opportunity to work with diverse applications across Healthcare and education sectors
  • Involvement in cutting-edge security practices and protocols
  • Collaborative work environment with opportunities to engage with multiple teams
  • Potential for professional growth and development in security engineering field
Full Job Description
Job Title: Security Engineer, Application Security

Salary Range: $109,221 - $114,221/year

Job Location: 141 Tremont St, 10th Floor, Boston, MA 02111; Telecommuting permissible from
any location within US

Job Description: Responsible for ensuring the security of applications and software systems developed and used within the organization. This role involves conducting application security reviews, performing secure code analysis, integrating security testing into CI/CD pipelines, and guiding developers on secure coding practices. Design and implement security protocols for Healthcare, EDU, and B2B applications, conducting regular threat modeling and vulnerability assessments to identify and mitigate risks, and developing and deploying cryptographic solutions to protect sensitive data. Analyze and interpret student-related data from Indian and Chinese markets to inform strategies for mitigating payer fraud and enhancing security for international student transactions. Telecommuting permissible from any location within US.

Requirements: Master's degree or foreign equivalent in Computer Science with a specialization in Information Security, or a related field, and one (1) of experience in computer science, information security, application security or a closely related role.

Experience and/or education must include:
  1. Vulnerability & Risk Management: Perform comprehensive vulnerability management and risk assessments using industry tools such as Tenable and Qualys. Deliver actionable reports with remediation guidance and continuously monitor and triage alerts with SIEM platforms including Splunk, Sumo Logic, ELK, and Wazuh.
  2. Application Security Testing: Conduct hands-on application security testing using a variety of SAST, SCA, and DAST tools, including Veracode, BurpSuite, Snyk, Semgrep, OWASP ZAP, Arachni, SonarQube, and OWASP Dependency-Check.
  3. Secure Software Development: Develop and review secure applications in programming languages such as Ruby on Rails, Java, Python, and Go, focusing on modern UI web interfaces (e.g., JavaScript, ReactJS, AngularJS, Node.js). Ensure adherence to secure coding standards (OWASP Top 10) and protect against threats like XSS and SQL injection.
  4. Threat Modeling & Security Architecture: Conduct peer code reviews, perform in-depth threat modeling using methodologies like STRIDE, and execute security architecture assessments to proactively identify and mitigate risks throughout the software development lifecycle.
  5. DevSecOps & CI/CD Integration: Embed security into CI/CD pipelines, specifically within GitLab, by writing custom jobs and rules. Integrate and automate security tools like Trivy
  6. Sensitivity: Confidential and Semgrep to ensure continuous security checks and early vulnerability detection within a DevSecOps framework.
  7. Data Security & Cryptography: Securely handle sensitive data using credential management tools like HashiCorp Vault. Design and implement strong cryptographic techniques, including AES, RSA, ECC, and various hashing algorithms.
  8. Cloud Security & Compliance: Review and enforce cloud security best practices for AWS and GCP environments. Conduct internal and external security audits aligned with compliance frameworks such as SOC II Type 2, ISO 27002, NIST, and PCI, and prepareassociated reports and policy updates.
  9. Authentication & Authorization: Design and implement robust authentication and authorization systems utilizing protocols such as OAuth 2.0, SAML, JWT, and access control models like RBAC/ABAC.
  10. Security Automation: Develop custom security software using Python, Bash, and Ruby to automate security processes, from vulnerability scanning to incident response.
  11. Client & Third-Party Support: Support client and third-party security audits by preparing responses to security assessments and risk questionnaires, including those from platforms like OneTrust.


CONTACT:

Qualifications

Additional Information

Submit today and get started!

We are excited to get to know you! Throughout our process you can expect to meet different FlyMates including the Hiring Manager and other Flymates. Your Talent Acquisition Partner will walk you through the steps and be your "go-to" person for questions.

About Flywire

Flywire is a financial technology company that provides payment solutions for businesses and institutions. The company was founded in 2009 and is headquartered in Boston, Massachusetts. Flywire's platform allows businesses to accept payments from customers around the world, with support for over 240 countries and 150 currencies. The company's solutions are used by a variety of industries, including education, healthcare, travel, and technology. Flywire has raised over $300 million in funding and has been recognized as one of the fastest-growing companies in the United States.
Learn more about Flywire
Size
500 employees
Market Cap
$2.4 billion
Industry
Founded
2009

Similar Jobs

More Jobs at Flywire

More Information Technology Jobs

Find similar Security Engineer, Application Security jobs: