Security Engineer II (Offensive Operations)

Flywire•Boston, MA
•$99,000 - $120,000•Hybrid

About The Position

As a Security Engineer II on our Active Operational Offensive track, you’ll sit at the heart of Flywire’s security defenses under the guidance of senior engineers. You will bridge manual penetration testing with active security operations, building the technical depth needed to lead independent engagements over time.

Requirements

  • Bachelor of Science and at least 2+ years’ experience in IT security and Penetration Testing.
  • Demonstrated track record executing network, web application, and API penetration tests.
  • Proficiency with Kali Linux, commercial/open-source penetration tools, and active involvement on bug bounty platforms.
  • Experience with SAST/DAST tools, secure code reviews, and scripting knowledge in Python, Java, or Ruby.
  • Understanding of AWS Cloud infrastructure, Agile environments, CI/CD pipelines, and Infrastructure as Code (IaC).
  • Strong knowledge of OWASP methodologies, threat vectors (malware, intrusion, DoS), and platform security strategies.
  • Ability to write formal/informal technical reports and translate complex exploit chains to non-technical stakeholders.

Nice To Haves

  • OSCP, OSCE, or SANS GXPN certifications.
  • OffSec OSAI (Offensive Security AI Red Teamer) certification.
  • Combines an attacker’s drive to break systems with a defender's discipline to build actionable SIEM detection rules.
  • Analytical and calm during live security breaches or tight release windows.
  • Balances risk mitigation with organizational growth.

Responsibilities

  • Execute manual internal and external penetration testing across AWS/multicloud environments to identify vulnerabilities, misconfigurations, and privilege escalation paths.
  • Perform deep-dive testing on web applications and REST/GraphQL APIs, targeting complex business logic flaws, auth bypasses, and OWASP Top 10 risks.
  • Review SAST/DAST findings and conduct targeted code audits (Python, Java, Ruby) to eliminate false positives and prioritize high-risk fixes.
  • Partner with the Blue Team during adversary emulation exercises to validate security controls, refine enterprise SIEM detection rules, and optimize real-time alerting.
  • Participate in goal-oriented adversarial simulations evaluating Flywire’s physical/digital posture and incident response readiness.
  • Manage external vulnerability disclosure and bug bounty programs, triaging submissions, validating severity, and coordinating swift engineering fixes.
  • Apply emerging threat actor TTPs to continuously align testing methodologies with the MITRE ATT&CK framework.
  • Deliver actionable remediation guidance to Engineering, SRE, and IT teams, balancing robust security fixes with business velocity.

Benefits

  • US base salary range for this full-time position is $99,000 - 120,000 and benefits.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service