Flywire

Security Engineer II (Defensive Operations)

Flywire$99K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Cyber Security, Software Engineering, or related field
  • 3+ years in Application Security, Cloud Architecture Defense, or SecOps/Incident Response/Penetration Testing
  • Experience in deep manual penetration testing and incident containment
  • Practical knowledge of AWS, Docker, Kubernetes, and GitLab CI pipelines
  • Foundational proficiency with programming in Python, Ruby on Rails, Java, or Node.js
  • Understanding of OWASP Top 10 for LLMs and applied cryptography
  • Proficiency with EDR platforms, SIEM systems, and forensic collection tools

Responsibilities

  • Own and design automated technical security requirements integration into CI/CD pipelines
  • Collaborate with SRE and DevOps to establish secure cloud architecture and enforce Zero Trust
  • Deploy automated security review workflows and protect AI features from vulnerabilities
  • Perform offensive penetration testing and vulnerability research on financial platforms
  • Lead incident response efforts, technical containment, and design detection rules
  • Collaborate with development teams and mentor junior engineers on security best practices

Benefits

  • Comprehensive onboarding process with team integration and support
  • Encouragement of a collaborative work environment
  • Hybrid work model offering flexibility
  • Access to professional development opportunities
  • Engagement with experienced talents across various teams
Full Job Description
Job Description

At Flywire, we are looking for a Security Engineer II to join our global Security Engineering team. In this role, you will serve as a technical authority owning secure software design, cloud-native infrastructure defense, offensive penetration testing, and real-time incident detection across Flywire's global footprint. You will combine a "breaker" mindset with a builder's engineering empathy, operating fluidly across the entire product and infrastructure security lifecycle.

This role demands an "automation-first" approach embedded within a high-velocity fintech ecosystem. You will actively partner with software engineering and SRE squads to integrate security controls directly into our public cloud and GitLab CI/CD pipelines using AI workflows. Simultaneously, you will serve as an operational responder for threat detection engineering, red team penetration testing, and live incident containment.

Key Responsibilities:
  • Secure SDLC & CI/CD Automation: Own, design, and drive the end-to-end integration of automated technical security requirements and validation tools into high-velocity engineering pipelines. Build custom internal tooling, wrappers, and automated controls to maximize development velocity without friction.
  • SRE & Cloud Infrastructure Hardening: Partner directly with SRE and DevOps teams to establish secure cloud architecture blueprints, manage Infrastructure-as-Code (IaC) security scans (Terraform), and enforce Zero Trust boundaries in containerized environments (Docker/Kubernetes).
  • AI-Driven Security & Governance: Design and deploy automated security review workflows using LLM APIs (e.g., Claude). Establish controls to protect generative AI features against prompt injection, insecure output handling, model inversion, and data poisoning.
  • Offensive Penetration Testing & Red Teaming: Adopt an attacker's mindset to discover logic flaws, perform exploit research, and emulate zero-day adversarial behavior across financial platforms through manual source code audits, API exploitation, and cloud penetration testing.
  • Incident Response & Threat Detection: Lead technical containment, forensic collection, and rapid threat eradication during active security incidents. Design and deploy high-fidelity detection rules and automated alert workflows within the SIEM environment.
  • Cross-Functional Collaboration & Mentorship: Embed within software development and infrastructure sprint planning from inception to ensure security is built-in from day one. Provide actionable code modifications and mentor junior engineers.


Qualifications

Basic Qualifications:
  • Education: Bachelor's degree in Computer Science, Cyber Security, Software Engineering, or a related technical discipline (or equivalent experience).
  • Experience: 3+ years of progressive engineering experience moving fluidly between Application Security, Cloud Architecture Defense, and Active Security Operations (SecOps/Incident Response/Penetration Testing).
  • Advanced Exploitation & Defense: Proven track record of independently performing deep manual penetration testing, web application exploitation, and incident containment without relying solely on commercial automated scanners.
  • Cloud & DevOps Stack: Strong practical knowledge of AWS or public cloud topologies, containerization (Docker, Kubernetes), network security, and building/maintaining GitLab CI pipelines.
  • Programming Languages: Foundational proficiency with modern web development frameworks and programming languages including Python, Ruby on Rails, Java, or Node.js.
  • AI & Security Domains: Solid understanding of the OWASP Top 10 for LLMs framework, applied cryptography, cloud network isolation, and federated authentication architectures (OAuth2, SAML, OIDC, Zero Trust IAM).
  • SecOps & Forensics: Working proficiency with modern EDR platforms, SIEM systems, network packet analysis (PCAP), threat intelligence frameworks (MITRE ATT&CK), and forensic collection tools.
  • Compliance: Practical experience aligning technical software and infrastructure controls with standards like PCI-DSS (v4.0), SOC 1, SOC 2, or DORA.

Preferred Qualifications / Certifications:
  • Offensive/Red Team: OSCP, OSCE, or SANS GXPN.
  • Cloud & Architecture: AWS Certified Security - Specialty, CKS (Certified Kubernetes Security Specialist), or CISSP.
  • Incident Response: GCIH, GCFA, or specialized Blue Team certifications.
  • AI Security: OffSec OSAI.


Additional Information

Submit today and get started!

We are excited to get to know you! Throughout our process you can expect to meet different FlyMates including the Hiring Manager and other Flymates. Your Talent Acquisition Partner will walk you through the steps and be your "go-to" person for questions.

The US base salary range for this full-time position is $99,000 - 120,000 and benefits. Our salary ranges are determined by role, position level, and location. The range displayed on this job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. Within the range, individual pay is determined by work location and several other factors, including job-related skills, experience, relevant education and training.

#LI-Hybrid

About Flywire

Flywire is a financial technology company that provides payment solutions for businesses and institutions. The company was founded in 2009 and is headquartered in Boston, Massachusetts. Flywire's platform allows businesses to accept payments from customers around the world, with support for over 240 countries and 150 currencies. The company's solutions are used by a variety of industries, including education, healthcare, travel, and technology. Flywire has raised over $300 million in funding and has been recognized as one of the fastest-growing companies in the United States.
Learn more about Flywire
Size
500 employees
Market Cap
$2.4 billion
Industry
Founded
2009

Similar Jobs

More Jobs at Flywire

More Information Technology Jobs

Find similar Security Engineer II (Defensive Operations) jobs: