SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Flywire is seeking a Senior Security Engineer to serve as a technical authority for secure software design and cloud-native infrastructure defense across its global fintech platform. This role sits on the Defensive Platform Builder track and focuses on embedding security controls directly into development pipelines and cloud infrastructure.
Key Responsibilities:
1. Secure SDLC & CI/CD Automation: Own the end-to-end integration of automated security requirements and validation tooling into high-velocity engineering pipelines. Build custom internal tooling, wrappers, and automated controls to replace manual security checkpoints while maintaining development velocity.
2. Cloud & Infrastructure Hardening: Partner with SRE and DevOps teams to establish secure public cloud architecture blueprints, manage Infrastructure as Code security scanning (e.g., Terraform), and enforce strict network isolation. Architect and maintain cloud Identity and Access Management controls and enforce Zero Trust boundaries within containerized environments (Docker, Kubernetes).
3. AI-Driven Security & Application Reviews: Design, prompt engineer, and deploy automated security review workflows using LLM APIs for real-time code analysis and context-aware pull request feedback. Establish technical controls protecting internal and external generative AI features against LLM-specific risks (prompt injection, insecure output handling, model inversion, data poisoning). Conduct deep-dive source code audits and API security reviews beyond automated scanning.
4. Cross-Functional Collaboration & Mentorship: Embed within software development and infrastructure sprint planning from inception to ensure security is built in from day one. Provide expert-level, actionable guidance to software and SRE engineers. Mentor junior security, software, and SRE engineers to raise technical resilience across the organization.
The role requires balancing a builder's engineering empathy with a security-first mindset, treating engineering teams as operational allies. You will communicate clearly under pressure, distilling complex cloud configuration or vulnerability issues into high-impact risk summaries for non-technical stakeholders. The position demands creative problem-solving in a distributed financial microservices environment and resilience during high-pressure scenarios including active security incidents or compressed product launch windows.
Requirements:
- Education: Bachelor's degree in Computer Science, Cyber Security, Software Engineering, or related technical discipline (Master's preferred)
- Core Experience: 5–8 years of progressive engineering experience across Application Security and Cloud Architecture Defence
- Advanced Defensive Depth: Proven track record of independently running deep manual code and configuration reviews, not relying solely on commercial automated scanning platforms
- Cloud & DevOps Engineering Stack: Deep practical knowledge of AWS or similar public cloud topologies, containerization and orchestration (Docker, Kubernetes), network security controls, and high-velocity GitLab CI pipelines
- Technical Language Depth: Solid proficiency with modern web development frameworks and languages including Python, Ruby on Rails, Java, and Node.js
- AI & Cryptographic Domain Mastery: Expert-level understanding of OWASP Top 10 for LLMs, prompt engineering wrappers, applied cryptography, cloud network isolation, and federated authentication architectures (OAuth2, SAML, OIDC, Zero Trust IAM)
- Regulatory & Compliance Competency: Practical experience aligning technical software and infrastructure controls with standards such as PCI-DSS (v4.0), SOC 1, SOC 2, and DORA
Highly Preferred Certifications:
- AWS Certified Security – Specialty, Certified Kubernetes Security Specialist (CKS), or CISSP
- OffSec OSAI (Offensive Security AI Red Teamer)
- OSCP or GCIH (with exposure to offensive or incident response work)