SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Engineer II (Offensive)

Flywire - Bengaluru, KA, India - Hybrid - posted 2026-10-01

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Flywire is a global payments enablement and software company supporting 5,300+ clients across education, healthcare, travel, and B2B industries. They process payments across 240 countries and 140+ currencies with a team of 1,400+ employees across 15 offices worldwide. As a Security Engineer II on the Active Operational Defender track, you will develop hands-on expertise in offensive security within a high-velocity fintech environment. You will work under the direction of senior and lead engineers, progressively building independence and technical depth across penetration testing, threat detection, and incident response. Key responsibilities include: **Offensive Penetration Testing & Red Teaming:** Support penetration testing engagements across financial platforms and product architectures, building practical exploit research experience. Assist with manual security reviews including source code audits, API testing, and cloud configuration checks. Contribute to adversarial testing of AI features, learning to identify prompt injection and LLM-specific weaknesses. **Threat Detection Engineering & SIEM:** Help design and tune detection rules and alert workflows within the enterprise SIEM under senior guidance. Support SecOps in reviewing detection coverage against current threats using frameworks such as MITRE ATT&CK. **Incident Response & Forensics:** Act as a first-line responder during active security incidents, performing evidence collection and initial triage. Support post-incident analysis by compiling logs, timelines, and technical findings for senior review. **Cross-Functional Collaboration:** Participate in security operations and engineering planning. Communicate findings clearly to team members and stakeholders. Actively seek mentorship from senior and lead security engineers on offensive tooling, detection engineering, and incident response practice. **Requirements:** - Bachelor's degree in Computer Science, Cyber Security, Software Engineering, or related technical discipline, or equivalent practical experience - 1 to 3 years of hands-on experience in penetration testing, security operations, or closely related technical role - Exposure to manual web application testing, CTF-style exploitation, or vulnerability research (through work, personal projects, or study) - Basic working knowledge of SIEM concepts, EDR tooling, or network packet analysis; interest in frameworks such as MITRE ATT&CK - Comfort reading and ideally writing scripts in Python or similar language to support testing and automation - Working interest in OWASP Top 10 for LLMs and how adversarial testing of AI features differs from traditional application testing - General understanding of standards such as PCI-DSS, SOC 2, or DORA, with willingness to build practical depth on the job **Highly Preferred Certifications:** - Offensive & Red Team: OSCP, OSCE, or SANS GXPN (GIAC Exploit Researcher and Advanced Penetration Tester) - Incident Response & Defence: GCIH (GIAC Certified Incident Handler), GCFA (GIAC Certified Forensic Analyst), or specialized Blue Team certification - Modern AI Security: OffSec OSAI (Offensive Security AI Red Teamer) **Key Skills:** - Combines attacker's mindset for finding vulnerabilities with analytical discipline to write clear, actionable detection rules - Stays calm and analytically clear under intense pressure during active breach events or business-critical system failures - Communicates exploit chains and log anomalies clearly, translating technical detail into high-impact risk profiles for non-technical leadership - Balances technical risk reduction with business enablement, supporting security infrastructure as a competitive advantage

Similar roles