SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Flywire is seeking a Lead Security Engineer to set technical direction for security engineering across defensive (AppSec, CloudSec) and offensive (PenTest, SecOps) disciplines. You will act as the senior technical authority for the security engineering team, combining deep hands-on expertise with strategic leadership and mentorship capabilities.
Key responsibilities include defining and owning technical strategy across secure software design, cloud infrastructure defense, offensive testing, and incident detection. You will represent security engineering in cross-functional and executive forums, translating technical risk into business impact for non-technical stakeholders. You'll direct the integration of automated security controls into engineering pipelines and cloud infrastructure, own escalation and sign-off on complex cloud architecture and Zero Trust design decisions, and set standards for penetration testing, red team simulations, and detection engineering.
You will serve as the senior technical escalation point during critical security incidents, directing containment and post-incident reviews. Additionally, you'll mentor senior and junior security engineers across both defensive and offensive tracks, shape career development within the team, and partner with leadership on hiring and resourcing decisions.
Required qualifications include a Bachelor's degree in Computer Science, Cyber Security, Software Engineering, or related discipline (Master's preferred). You need 8+ years of progressive engineering experience with demonstrated depth in either defensive or offensive security and strong working fluency across both. You must have hands-on seniority in application security, cloud architecture defense, penetration testing, or security operations, with the ability to speak authoritatively across the wider security function.
Deep practical knowledge is required in public cloud topologies, containerization and orchestration, CI/CD pipelines, and manual testing/forensic tooling. Expert-level understanding of OWASP Top 10 for LLMs, applied cryptography, federated authentication architectures, and practical experience aligning controls to PCI-DSS v4.0, SOC 1, SOC 2, and DORA are essential. Prior experience mentoring engineers, shaping technical roadmaps, or influencing hiring decisions within security or engineering functions is required.
Highly preferred certifications include AWS Certified Security - Specialty, CKS, CISSP, OSCP, OSCE, SANS GXPN, GCIH, GCFA, and OffSec OSAI. You should move credibly between builder and breaker mindsets, lead with influence, demonstrate calm analytical decision-making under pressure, and balance technical risk reduction with business enablement.