NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Security Engineer in United States of America
9 days ago
Apply with autofill
Apply with autofill
Flywire·Fintech·9 days ago
9 days ago

Security Engineer II (Offensive Operations)

Boston, United States of AmericaFull-timeMid · 2-5 yearsSecurity Engineer

Sign up free to see how well your resume matches this role.

Boost your chances at Flywire

How you compare FREE

?
Your scoreYour score: not yet known
→
49
Top 10%Top 10%: 49 out of 100

Top 10% of NextRaise users matched against Security Engineer roles in United States.

Must-have skills for this role

  • penetration testing
  • owasp
  • aws
  • python

PDF or DOCX · no account needed

Apply faster with autofill FREEFlywire uses SmartRecruiters - autofill it instead of retyping.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Cloud Infrastructure PenTesting: Execute manual internal and external penetration testing across AWS/multicloud environments to identify vulnerabilities, misconfigurations, and privilege escalation paths.
  • Web Application & API Assessment: Perform deep-dive testing on web applications and REST/GraphQL APIs, targeting complex business logic flaws, auth bypasses, and OWASP Top 10 risks.
  • Source Code & Vulnerability Analysis: Review SAST/DAST findings and conduct targeted code audits (Python, Java, Ruby) to eliminate false positives and prioritize high-risk fixes.
  • Purple Team Operations: Partner with the Blue Team during adversary emulation exercises to validate security controls, refine enterprise SIEM detection rules, and optimize real-time alerting.
  • Red Team Engagements: Participate in goal-oriented adversarial simulations evaluating Flywire’s physical/digital posture and incident response readiness.
  • Bug Bounty Operations: Manage external vulnerability disclosure and bug bounty programs, triaging submissions, validating severity, and coordinating swift engineering fixes.
  • Threat Intelligence (MITRE ATT&CK): Apply emerging threat actor TTPs to continuously align testing methodologies with the MITRE ATT&CK framework.
  • Collaborative Advisory: Deliver actionable remediation guidance to Engineering, SRE, and IT teams, balancing robust security fixes with business velocity.

What they're looking for

  • Bachelor of Science and at least 2+ years’ experience in IT security and Penetration Testing.
  • Demonstrated track record executing network, web application, and API penetration tests.
  • Proficiency with Kali Linux, commercial/open-source penetration tools, and active involvement on bug bounty platforms.
  • Experience with SAST/DAST tools, secure code reviews, and scripting knowledge in Python, Java, or Ruby.
  • Understanding of AWS Cloud infrastructure, Agile environments, CI/CD pipelines, and Infrastructure as Code (IaC).
  • Strong knowledge of OWASP methodologies, threat vectors (malware, intrusion, DoS), and platform security strategies.
  • Ability to write formal/informal technical reports and translate complex exploit chains to non-technical stakeholders.

Nice to have

  • Offensive & Red Team: OSCP, OSCE, or SANS GXPN.
  • AI Security: OffSec OSAI (Offensive Security AI Red Teamer).

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

Company Description

Are you ready to trade your job for a journey? Become a FlyMate!

Passion, excitement & global collaboration are all core to what it means to be a FlyMate. At Flywire, we’re on a mission to deliver the world’s most important and complex payments. We use our Flywire Advantage - the combination of our next-gen payments platform, proprietary payment network and vertical specific software, to help our clients get paid, and help their customers pay with ease - no matter where they are in the world.

What more do we need to truly be unstoppable? Perhaps, that is you! 

Who we are: 
Flywire is a global payments enablement and software company, founded more than a decade ago to solve high-stakes, high-value payments in higher education. We’ve since scaled into new regions and industry verticals and expanded our product offerings to deliver meaningful value to our clients around the world. 

Today we support more than 5,300 clients across the global education, healthcare, travel & B2B industries, with diverse payment methods across 240 countries & territories and more than 140 currencies.

With over 1,400 global FlyMates, representing more than 40 nationalities, and in 15 offices world-wide, we’re looking for FlyMates to join the next stage of our journey as we continue to grow.
 

Job Description

Do you spend your free time figuring out how systems break? Are you driven by the thrill of discovering complex vulnerabilities before malicious actors do? If you’re a natural tinkerer who loves attacking systems to make them unshakeable, this role is built for you.

As a Security Engineer II on our Active Operational Offensive track, you’ll sit at the heart of Flywire’s security defenses under the guidance of senior engineers. You will bridge manual penetration testing with active security operations, building the technical depth needed to lead independent engagements over time.

Key Responsibilities & Impact

  • Cloud Infrastructure PenTesting: Execute manual internal and external penetration testing across AWS/multicloud environments to identify vulnerabilities, misconfigurations, and privilege escalation paths.

  • Web Application & API Assessment: Perform deep-dive testing on web applications and REST/GraphQL APIs, targeting complex business logic flaws, auth bypasses, and OWASP Top 10 risks.

  • Source Code & Vulnerability Analysis: Review SAST/DAST findings and conduct targeted code audits (Python, Java, Ruby) to eliminate false positives and prioritize high-risk fixes.

  • Purple Team Operations: Partner with the Blue Team during adversary emulation exercises to validate security controls, refine enterprise SIEM detection rules, and optimize real-time alerting.

  • Red Team Engagements: Participate in goal-oriented adversarial simulations evaluating Flywire’s physical/digital posture and incident response readiness.

  • Bug Bounty Operations: Manage external vulnerability disclosure and bug bounty programs, triaging submissions, validating severity, and coordinating swift engineering fixes.

  • Threat Intelligence (MITRE ATT&CK): Apply emerging threat actor TTPs to continuously align testing methodologies with the MITRE ATT&CK framework.

  • Collaborative Advisory: Deliver actionable remediation guidance to Engineering, SRE, and IT teams, balancing robust security fixes with business velocity.

Qualifications

Here’s What We’re Looking For:

  • Education & Experience: Bachelor of Science and at least 2+ years’ experience in IT security and Penetration Testing.

  • Hands-on PenTesting: Demonstrated track record executing network, web application, and API penetration tests.

  • Offensive Toolset: Proficiency with Kali Linux, commercial/open-source penetration tools, and active involvement on bug bounty platforms.

  • Code & Automation: Experience with SAST/DAST tools, secure code reviews, and scripting knowledge in Python, Java, or Ruby.

  • Modern Stack Exposure: Understanding of AWS Cloud infrastructure, Agile environments, CI/CD pipelines, and Infrastructure as Code (IaC).

  • Security Frameworks: Strong knowledge of OWASP methodologies, threat vectors (malware, intrusion, DoS), and platform security strategies.

  • High-Impact Communication: Ability to write formal/informal technical reports and translate complex exploit chains to non-technical stakeholders.

Preferred Certifications (Nice-to-Have):

  • Offensive & Red Team: OSCP, OSCE, or SANS GXPN.

  • AI Security: OffSec OSAI (Offensive Security AI Red Teamer).

Mindset & Soft Skills:

  • Dual Focus: Combines an attacker’s drive to break systems with a defender's discipline to build actionable SIEM detection rules.

  • Composure Under Pressure: Analytical and calm during live security breaches or tight release windows.

  • Business-Minded Security: Balances risk mitigation with organizational growth.

Additional Information

Submit today and get started!

We are excited to get to know you! Throughout our process you can expect to meet different FlyMates including the Hiring Manager and other Flymates. Your Talent Acquisition Partner will walk you through the steps and be your “go-to” person for questions.

Flywire is an equal opportunity employer and follows a policy of administering all employment decisions and personnel actions without regard to race, color, religion, sex, pregnancy, gender identity, national origin, age, ancestry, physical or mental disability, sexual orientation, genetic disposition or carrier status, veteran status, or any other category protected under applicable national, federal, state or local law.

The US base salary range for this full-time position is $99,000 - 120,000 and benefits. Our salary ranges are determined by role, position level, and location. The range displayed on this job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. Within the range, individual pay is determined by work location and several other factors, including job-related skills, experience, relevant education and training. 

#LI-Hybrid

Fintech

Company

FlywireFintech
Boston, United States of America

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Flywire's careers site·first seen 11 Sept 2026·last verified 11 Sept 2026·How we source jobs

Similar jobs

  • Staff Security Engineer at robotsandpencilsUS - Remote–match not yet calculated
  • IT Security Engineer at zollChelmsford, United States of America–match not yet calculated
  • Cybersecurity Summer 2027 Intern (Undergraduate) at centeneRemote-MO–match not yet calculated
  • AI Security Engineer at trimbleUS - Remote, CO–match not yet calculated
  • Medical Device Cybersecurity Co-Op at Johnson & JohnsonDanvers, United States of America–match not yet calculated

Browse more jobs

  • Security Engineer jobs in United States
  • Security Analyst jobs in United States
  • Cloud Security Engineer jobs in United States
  • Penetration Tester jobs in United States
  • Security Engineer jobs in India
  • Security Engineer jobs in United Kingdom