SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 99,000 - 120,000 / annual
Flywire, a global payments enablement and software company, is seeking a Security Engineer II to join its global Security Engineering team. This role combines offensive and defensive security expertise within a high-velocity fintech ecosystem, requiring you to operate fluidly across the entire product and infrastructure security lifecycle.
You will own secure software design, cloud-native infrastructure defense, offensive penetration testing, and real-time incident detection across Flywire's global footprint. The role demands an "automation-first" approach, with active partnership across software engineering and SRE squads to integrate security controls directly into public cloud and GitLab CI/CD pipelines using AI workflows.
Key responsibilities include:
**Secure SDLC & CI/CD Automation:** Design and drive end-to-end integration of automated technical security requirements and validation tools into high-velocity engineering pipelines. Build custom internal tooling, wrappers, and automated controls to maximize development velocity without friction.
**SRE & Cloud Infrastructure Hardening:** Partner with SRE and DevOps teams to establish secure cloud architecture blueprints, manage Infrastructure-as-Code security scans (Terraform), and enforce Zero Trust boundaries in containerized environments (Docker/Kubernetes).
**AI-Driven Security & Governance:** Design and deploy automated security review workflows using LLM APIs (e.g., Claude). Establish controls to protect generative AI features against prompt injection, insecure output handling, model inversion, and data poisoning.
**Offensive Penetration Testing & Red Teaming:** Adopt an attacker's mindset to discover logic flaws, perform exploit research, and emulate zero-day adversarial behavior across financial platforms through manual source code audits, API exploitation, and cloud penetration testing.
**Incident Response & Threat Detection:** Lead technical containment, forensic collection, and rapid threat eradication during active security incidents. Design and deploy high-fidelity detection rules and automated alert workflows within the SIEM environment.
**Cross-Functional Collaboration & Mentorship:** Embed within software development and infrastructure sprint planning from inception to ensure security is built-in from day one. Provide actionable code modifications and mentor junior engineers.
**Requirements:**
- Bachelor's degree in Computer Science, Cyber Security, Software Engineering, or related technical discipline (or equivalent experience)
- 3+ years of progressive engineering experience moving fluidly between Application Security, Cloud Architecture Defense, and Active Security Operations (SecOps/Incident Response/Penetration Testing)
- Proven track record of independently performing deep manual penetration testing, web application exploitation, and incident containment without relying solely on commercial automated scanners
- Strong practical knowledge of AWS or public cloud topologies, containerization (Docker, Kubernetes), network security, and building/maintaining GitLab CI pipelines
- Foundational proficiency with modern web development frameworks and programming languages including Python, Ruby on Rails, Java, or Node.js
- Solid understanding of OWASP Top 10 for LLMs framework, applied cryptography, cloud network isolation, and federated authentication architectures (OAuth2, SAML, OIDC, Zero Trust IAM)
- Working proficiency with modern EDR platforms, SIEM systems, network packet analysis (PCAP), threat intelligence frameworks (MITRE ATT&CK), and forensic collection tools
- Practical experience aligning technical software and infrastructure controls with standards like PCI-DSS (v4.0), SOC 1, SOC 2, or DORA
**Preferred Qualifications/Certifications:**
- Offensive/Red Team: OSCP, OSCE, or SANS GXPN
- Cloud & Architecture: AWS Certified Security - Specialty, CKS (Certified Kubernetes Security Specialist), or CISSP
- Incident Response: GCIH, GCFA, or specialized Blue Team certifications
- AI Security: OffSec OSAI