SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Engineer II (Offensive)

Flywire - Bengaluru, KA, India - Hybrid - posted 2026-09-11

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Flywire is a global payments enablement and software company supporting 5,300+ clients across education, healthcare, travel, and B2B industries. They operate in 15 offices worldwide with 1,400+ employees across 40+ nationalities. As a Security Engineer II on the Active Operational Defender track, you will develop hands-on expertise in penetration testing, threat detection, and incident response within a high-velocity fintech environment. Working under the direction of senior and lead engineers, you will build practical skills and gradually take on more independent responsibility. Key responsibilities include: **Offensive Penetration Testing & Red Teaming:** Support penetration testing engagements across financial platforms and product architectures under senior guidance. Assist with manual security reviews including source code audits, API testing, and cloud configuration checks. Contribute to adversarial testing of AI features, learning to identify prompt injection and LLM-specific weaknesses. **Threat Detection Engineering & SIEM:** Help design and tune detection rules and alert workflows within the enterprise SIEM, working from senior engineers' guidance and established detection frameworks. Support SecOps in reviewing detection coverage against current threats using frameworks such as MITRE ATT&CK. **Incident Response & Forensics:** Act as a first-line responder during active security incidents, performing evidence collection and initial triage under senior direction. Support post-incident analysis by compiling logs, timelines, and technical findings for senior review. **Cross-Functional Collaboration:** Participate in security operations and engineering planning. Communicate findings from testing and incidents clearly to team members and stakeholders. Actively seek mentorship from senior and lead security engineers on offensive tooling, detection engineering, and incident response practice. The role offers competitive compensation, employee stock purchase plan, competitive time off including volunteer days, immersive global induction program, wellbeing programs, and talent development opportunities. **Requirements:** - Bachelor's degree in Computer Science, Cyber Security, Software Engineering, or related technical discipline, or equivalent practical experience - 1 to 3 years of hands-on experience in penetration testing, security operations, or closely related technical role - Exposure to manual web application testing, CTF-style exploitation, or vulnerability research (through work, personal projects, or study) - Basic working knowledge of SIEM concepts, EDR tooling, or network packet analysis; interest in frameworks such as MITRE ATT&CK - Comfort reading and ideally writing scripts in Python or similar language to support testing and automation - Working interest in OWASP Top 10 for LLMs and how adversarial testing of AI features differs from traditional application testing - General understanding of standards such as PCI-DSS, SOC 2, or DORA, with willingness to build practical depth on the job **Highly Preferred Certifications:** - Offensive & Red Team: OSCP, OSCE, SANS GXPN (GIAC Exploit Researcher and Advanced Penetration Tester), or OffSec OSAI (Offensive Security AI Red Teamer) - Incident Response & Defence: GCIH (GIAC Certified Incident Handler) or GCFA (GIAC Certified Forensic Analyst) **Key Skills:** - Combines attacker's mindset with analytical discipline to write clear, actionable detection rules - Stays calm and analytically clear under intense pressure during active breaches or business-critical system failures - Communicates exploit chains and log anomalies clearly, translating technical detail into high-impact risk profiles for non-technical leadership - Balances technical risk reduction with business enablement - Modern AI security awareness

Similar roles