SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Engineer II (Offensive Operations)

Flywire - Boston, MA, United States - Hybrid - posted 2026-09-11

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 99,000 - 120,000 / annual

Flywire is seeking a Security Engineer II to join its offensive security operations team. In this role, you will execute manual penetration testing and adversarial security operations across cloud infrastructure, web applications, and APIs. You'll work under the guidance of senior engineers while building technical depth to lead independent engagements. Key responsibilities include: • Conduct manual internal and external penetration testing across AWS and multicloud environments, identifying vulnerabilities, misconfigurations, and privilege escalation paths. • Perform deep-dive assessments on web applications and REST/GraphQL APIs, targeting complex business logic flaws, authentication bypasses, and OWASP Top 10 risks. • Review SAST/DAST findings and conduct targeted source code audits (Python, Java, Ruby) to eliminate false positives and prioritize high-risk fixes. • Partner with the Blue Team during purple team adversary emulation exercises to validate security controls, refine SIEM detection rules, and optimize real-time alerting. • Participate in red team engagements and goal-oriented adversarial simulations evaluating Flywire's physical and digital security posture and incident response readiness. • Manage external vulnerability disclosure and bug bounty programs, including triage, severity validation, and coordination of engineering fixes. • Apply emerging threat actor tactics, techniques, and procedures (TTPs) to align testing methodologies with the MITRE ATT&CK framework. • Deliver actionable remediation guidance to Engineering, SRE, and IT teams, balancing robust security fixes with business velocity. Flywire is a global payments enablement and software company supporting over 5,300 clients across education, healthcare, travel, and B2B industries. The company operates in 15 offices worldwide with over 1,400 employees representing 40+ nationalities. REQUIREMENTS: • Bachelor of Science degree and at least 2+ years of experience in IT security and penetration testing. • Demonstrated track record executing network, web application, and API penetration tests. • Proficiency with Kali Linux, commercial and open-source penetration testing tools, and active involvement on bug bounty platforms. • Experience with SAST/DAST tools, secure code reviews, and scripting knowledge in Python, Java, or Ruby. • Understanding of AWS cloud infrastructure, Agile environments, CI/CD pipelines, and Infrastructure as Code (IaC). • Strong knowledge of OWASP methodologies, threat vectors (malware, intrusion, DoS), and platform security strategies. • Ability to write formal and informal technical reports and translate complex exploit chains to non-technical stakeholders. PREFERRED CERTIFICATIONS: • Offensive & Red Team: OSCP, OSCE, or SANS GXPN. • AI Security: OffSec OSAI (Offensive Security AI Red Teamer). MINDSET & SOFT SKILLS: • Combines an attacker's drive to break systems with a defender's discipline to build actionable SIEM detection rules. • Analytical and composed during live security breaches or tight release windows. • Business-minded approach that balances risk mitigation with organizational growth.

Similar roles