SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 99,000 - 120,000 / annual
Flywire is seeking a Security Engineer II to join its global Security Engineering team. This role combines offensive and defensive security expertise across the full product and infrastructure lifecycle in a high-velocity fintech environment.
You will own secure software design, cloud-native infrastructure defense, offensive penetration testing, and real-time incident detection across Flywire's global footprint. Operating with an "automation-first" mindset, you will partner with software engineering and SRE squads to integrate security controls directly into public cloud and GitLab CI/CD pipelines using AI workflows. You will also serve as an operational responder for threat detection engineering, red team penetration testing, and live incident containment.
Key responsibilities include:
• Secure SDLC & CI/CD Automation: Design and drive end-to-end integration of automated technical security requirements and validation tools into high-velocity engineering pipelines. Build custom internal tooling, wrappers, and automated controls to maximize development velocity without friction.
• SRE & Cloud Infrastructure Hardening: Partner with SRE and DevOps teams to establish secure cloud architecture blueprints, manage Infrastructure-as-Code security scans (Terraform), and enforce Zero Trust boundaries in containerized environments (Docker/Kubernetes).
• AI-Driven Security & Governance: Design and deploy automated security review workflows using LLM APIs (e.g., Claude). Establish controls to protect generative AI features against prompt injection, insecure output handling, model inversion, and data poisoning.
• Offensive Penetration Testing & Red Teaming: Adopt an attacker's mindset to discover logic flaws, perform exploit research, and emulate zero-day adversarial behavior across financial platforms through manual source code audits, API exploitation, and cloud penetration testing.
• Incident Response & Threat Detection: Lead technical containment, forensic collection, and rapid threat eradication during active security incidents. Design and deploy high-fidelity detection rules and automated alert workflows within the SIEM environment.
• Cross-Functional Collaboration & Mentorship: Embed within software development and infrastructure sprint planning from inception to ensure security is built-in from day one. Provide actionable code modifications and mentor junior engineers.
Flywire is a global payments enablement and software company supporting over 5,300 clients across education, healthcare, travel, and B2B industries, with operations in 15 offices worldwide and over 1,400 employees representing 40+ nationalities.
REQUIREMENTS:
Basic Qualifications:
• Bachelor's degree in Computer Science, Cyber Security, Software Engineering, or related technical discipline (or equivalent experience)
• 3+ years of progressive engineering experience moving fluidly between Application Security, Cloud Architecture Defense, and Active Security Operations (SecOps/Incident Response/Penetration Testing)
• Proven track record of independently performing deep manual penetration testing, web application exploitation, and incident containment without relying solely on commercial automated scanners
• Strong practical knowledge of AWS or public cloud topologies, containerization (Docker, Kubernetes), network security, and building/maintaining GitLab CI pipelines
• Foundational proficiency with modern web development frameworks and programming languages including Python, Ruby on Rails, Java, or Node.js
• Solid understanding of OWASP Top 10 for LLMs framework, applied cryptography, cloud network isolation, and federated authentication architectures (OAuth2, SAML, OIDC, Zero Trust IAM)
• Working proficiency with modern EDR platforms, SIEM systems, network packet analysis (PCAP), threat intelligence frameworks (MITRE ATT&CK), and forensic collection tools
• Practical experience aligning technical software and infrastructure controls with standards like PCI-DSS (v4.0), SOC 1, SOC 2, or DORA
Preferred Qualifications/Certifications:
• Offensive/Red Team: OSCP, OSCE, or SANS GXPN
• Cloud & Architecture: AWS Certified Security - Specialty, CKS (Certified Kubernetes Security Specialist), or CISSP
• Incident Response: GCIH, GCFA, or specialized Blue Team certifications
• AI Security: OffSec OSAI