SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Engineer II (Defensive)

Flywire - Bengaluru, KA, India - Hybrid - posted 2026-09-11

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Flywire is seeking a Security Engineer II on the Defensive Platform Builder track to build hands-on experience in secure software design and cloud-native infrastructure defense within a high-velocity fintech environment. You will work under the direction of senior and lead engineers, developing an automation-first mindset while supporting the integration of security controls into public cloud and GitLab CI/CD pipelines, with a trajectory toward independent ownership of AppSec and CloudSec work. Key responsibilities include: **Secure SDLC & CI/CD Automation**: Support integration of automated security requirements and validation tooling into engineering pipelines. Help build and maintain internal tooling and automated controls that reduce reliance on manual security checkpoints. **Cloud & Infrastructure Hardening**: Work alongside SRE and DevOps teams on secure public cloud architecture, running Infrastructure as Code security scans (e.g., Terraform) and supporting network isolation controls. Contribute to cloud Identity and Access Management reviews and help maintain Zero Trust boundaries within containerized environments such as Docker and Kubernetes. **AI-Driven Security & Application Reviews**: Assist in configuring and running automated security review workflows using LLM APIs for pull request analysis. Learn and apply technical controls protecting generative AI features against LLM-specific risks such as prompt injection and insecure output handling. Support source code audits and API security reviews, building toward independent ownership of more complex assessments. **Cross-Functional Collaboration & Development**: Participate in software development and infrastructure sprint planning to understand how security fits into the wider engineering lifecycle. Provide clear, actionable feedback on code and configuration issues under guidance of senior and lead engineers. Actively seek mentorship to develop breadth across the security function. Flywire is a global payments enablement and software company supporting over 5,300 clients across education, healthcare, travel, and B2B industries, with operations in 15 offices worldwide and over 1,400 employees representing 40+ nationalities. **Requirements**: - Bachelor's degree in Computer Science, Cyber Security, Software Engineering, or related technical discipline, or equivalent practical experience - 1 to 3 years of hands-on experience in application or cloud security, software engineering, or closely related technical role - Exposure to manual code review, dependency or container scanning, and cloud security concepts (through work experience, personal projects, or study) - Working knowledge of a public cloud platform such as AWS, plus basic familiarity with containerization (Docker) and CI/CD pipelines - Comfort reading and writing code in at least one modern language such as Python, Java, or Node.js - Working interest in OWASP Top 10 for LLMs and how AI features introduce new categories of risk - General understanding of standards such as PCI-DSS, SOC 2, or DORA, with willingness to build practical depth on the job **Highly Preferred Certifications**: - Cloud & Architecture: AWS Certified Security - Specialty, Certified Kubernetes Security Specialist (CKS), or CISSP - Modern AI Security: OffSec OSAI (Offensive Security AI Red Teamer) - Broader Depth: OSCP or GCIH, with exposure to offensive or incident response work as secondary strength **Skills and Abilities**: - Balances builder's engineering empathy with security-first mindset, treating software, SRE, and product teams as operational allies - Communicates clearly under pressure, distilling cloud configuration drift or vulnerabilities into high-impact risk summaries for non-technical stakeholders - Creative, novel problem-solving across complex, non-standard application and cloud infrastructure challenges in distributed financial microservices environments - Resilience and analytical clarity in high-pressure scenarios, supporting transparent communication during active security incidents or compressed product launch windows - Balances technical risk reduction with business enablement, supporting security infrastructure as competitive advantage

Similar roles