Security Engineer II (Defensive Operations)

Flywire•Boston, MA
•$99,000 - $120,000•Hybrid

About The Position

At Flywire, we are looking for a Security Engineer II to join our global Security Engineering team. In this role, you will serve as a technical authority owning secure software design, cloud-native infrastructure defense, offensive penetration testing, and real-time incident detection across Flywire’s global footprint. You will combine a "breaker" mindset with a builder’s engineering empathy, operating fluidly across the entire product and infrastructure security lifecycle. This role demands an "automation-first" approach embedded within a high-velocity fintech ecosystem. You will actively partner with software engineering and SRE squads to integrate security controls directly into our public cloud and GitLab CI/CD pipelines using AI workflows. Simultaneously, you will serve as an operational responder for threat detection engineering, red team penetration testing, and live incident containment.

Requirements

  • Bachelor’s degree in Computer Science, Cyber Security, Software Engineering, or a related technical discipline (or equivalent experience).
  • 3+ years of progressive engineering experience moving fluidly between Application Security, Cloud Architecture Defense, and Active Security Operations (SecOps/Incident Response/Penetration Testing).
  • Proven track record of independently performing deep manual penetration testing, web application exploitation, and incident containment without relying solely on commercial automated scanners.
  • Strong practical knowledge of AWS or public cloud topologies, containerization (Docker, Kubernetes), network security, and building/maintaining GitLab CI pipelines.
  • Foundational proficiency with modern web development frameworks and programming languages including Python, Ruby on Rails, Java, or Node.js.
  • Solid understanding of the OWASP Top 10 for LLMs framework, applied cryptography, cloud network isolation, and federated authentication architectures (OAuth2, SAML, OIDC, Zero Trust IAM).
  • Working proficiency with modern EDR platforms, SIEM systems, network packet analysis (PCAP), threat intelligence frameworks (MITRE ATT&CK), and forensic collection tools.
  • Practical experience aligning technical software and infrastructure controls with standards like PCI-DSS (v4.0), SOC 1, SOC 2, or DORA.

Nice To Haves

  • OSCP, OSCE, or SANS GXPN.
  • AWS Certified Security - Specialty, CKS (Certified Kubernetes Security Specialist), or CISSP.
  • GCIH, GCFA, or specialized Blue Team certifications.
  • OffSec OSAI.

Responsibilities

  • Own, design, and drive the end-to-end integration of automated technical security requirements and validation tools into high-velocity engineering pipelines. Build custom internal tooling, wrappers, and automated controls to maximize development velocity without friction.
  • Partner directly with SRE and DevOps teams to establish secure cloud architecture blueprints, manage Infrastructure-as-Code (IaC) security scans (Terraform), and enforce Zero Trust boundaries in containerized environments (Docker/Kubernetes).
  • Design and deploy automated security review workflows using LLM APIs (e.g., Claude). Establish controls to protect generative AI features against prompt injection, insecure output handling, model inversion, and data poisoning.
  • Adopt an attacker's mindset to discover logic flaws, perform exploit research, and emulate zero-day adversarial behavior across financial platforms through manual source code audits, API exploitation, and cloud penetration testing.
  • Lead technical containment, forensic collection, and rapid threat eradication during active security incidents. Design and deploy high-fidelity detection rules and automated alert workflows within the SIEM environment.
  • Embed within software development and infrastructure sprint planning from inception to ensure security is built-in from day one. Provide actionable code modifications and mentor junior engineers.

Benefits

  • The US base salary range for this full-time position is $99,000 - 120,000 and benefits.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service