NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Security Engineer in India
22 hours agoBe an early applicant
Apply with autofill
Apply with autofill
Flywire·Fintech·22 hours ago
22 hours agoBe an early applicant

Senior Security Engineer (Offensive)

Bengaluru, IndiaFull-timeMid · 5-8 yearsSecurity Engineer

Sign up free to see how well your resume matches this role.

Boost your chances at Flywire

How you compare FREE

?
Your scoreYour score: not yet known
→
56
Top 10%Top 10%: 56 out of 100

Top 10% of NextRaise users matched against Security Engineer roles in India.

Must-have skills for this role

  • penetration testing
  • siem
  • detection engineering
  • incident response

PDF or DOCX · no account needed

Apply faster with autofill FREEFlywire uses SmartRecruiters - autofill it instead of retyping.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Personally adopt an attacker's mindset to uncover complex logic flaws, carry out exploit research and emulate adversarial behaviour across financial platforms and product architectures.
  • Run full spectrum manual security reviews that go beyond automated scanning, including source code audits, API exploitation and cloud configuration penetration testing.
  • Where in scope, extend adversarial testing to internal and external AI features, probing for prompt injection and other LLM specific weaknesses.
  • Design, build and deploy high fidelity detection rules, behavioural analytics and automated alert workflows within the enterprise SIEM to catch anomalous activity at scale.
  • Partner with SecOps to continuously tune detection coverage against the current threat landscape, referencing frameworks such as MITRE ATT&CK.
  • Lead technical containment, forensic collection and rapid threat eradication during active, critical security incidents.
  • Orchestrate post incident root cause analysis and translate findings into concrete engineering and detection improvements.
  • Embed within security operations and engineering planning to ensure detection and response capability keeps pace with the platform.
  • Provide expert level guidance on exploit chains and incident findings to engineering and leadership stakeholders.
  • Mentor junior security engineers on offensive tooling, detection engineering and incident response practice.

What they're looking for

  • Bachelor's degree required in Computer Science, Cyber Security, Software Engineering or a related technical discipline.
  • Indicative range [5 to 8 years] of progressive engineering experience across Security Operations, Incident Response and Penetration Testing.
  • A proven track record of independently performing deep manual penetration testing, web application exploitation and incident containment rather than relying solely on commercial automated scanning platforms.
  • Advanced working proficiency with modern EDR platforms, SIEM systems, network packet analysis (PCAP), threat intelligence frameworks (MITRE ATT&CK) and forensic collection tools.
  • Solid proficiency with a language such as Python, together with practical familiarity with common web and API technologies used to build exploit tooling.
  • Expert level understanding of the OWASP Top 10 for LLMs and how to apply an attacker's mindset to generative AI features, including prompt injection and insecure output handling.
  • Practical experience aligning technical testing and logging outputs with standards such as PCI-DSS (v4.0), SOC 1, SOC 2 and DORA.

Nice to have

  • A Master's degree is preferred.
  • Hands-On Offensive & Red Team: OSCP, OSCE or SANS GXPN (GIAC Exploit Researcher and Advanced Penetration Tester).
  • Incident Response & Defence: GCIH (GIAC Certified Incident Handler), GCFA (GIAC Certified Forensic Analyst) or a specialised Blue Team certification.
  • Modern AI Security: OffSec OSAI (Offensive Security AI Red Teamer).

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

Company Description

Are you ready to trade your job for a journey? Become a FlyMate!

Passion, excitement & global collaboration are all core to what it means to be a FlyMate. At Flywire, we’re on a mission to deliver the world’s most important and complex payments. We use our Flywire Advantage - the combination of our next-gen payments platform, proprietary payment network and vertical specific software, to help our clients get paid, and help their customers pay with ease - no matter where they are in the world.

What more do we need to truly be unstoppable? Perhaps, that is you! 

Who we are: 

Flywire is a global payments enablement and software company, founded more than a decade ago to solve high-stakes, high-value payments. We’ve scaled into new regions and industry verticals and expanded our product offerings to deliver meaningful value to our clients around the world. 

Today we support more than 5,300 clients across the global education, healthcare, travel & B2B industries, with diverse payment methods across 240 countries & territories and more than 140 currencies.

With over 1,400+ global FlyMates, representing more than 40 nationalities, and in 15 offices world-wide, we’re looking for FlyMates to join the next stage of our journey as we continue to grow.

 

Job Description

Job Summary

As a Senior Security Engineer on the Active Operational Defender track you will act as a core operational lead for threat detection, penetration testing and incident containment across Flywire's global footprint. You will combine an aggressive attacker's mindset with the analytical rigour needed to build high fidelity detection engineering, serving as a primary responder when live incidents put our global payment networks at risk.

Responsibilities and Tasks:

1. Offensive Penetration Testing & Red Teaming

  • Personally adopt an attacker's mindset to uncover complex logic flaws, carry out exploit research and emulate adversarial behaviour across financial platforms and product architectures.

  • Run full spectrum manual security reviews that go beyond automated scanning, including source code audits, API exploitation and cloud configuration penetration testing.

  • Where in scope, extend adversarial testing to internal and external AI features, probing for prompt injection and other LLM specific weaknesses.

2. Threat Detection Engineering & SIEM

  • Design, build and deploy high fidelity detection rules, behavioural analytics and automated alert workflows within the enterprise SIEM to catch anomalous activity at scale.

  • Partner with SecOps to continuously tune detection coverage against the current threat landscape, referencing frameworks such as MITRE ATT&CK.

3. Incident Response & Forensics

  • Lead technical containment, forensic collection and rapid threat eradication during active, critical security incidents.

  • Orchestrate post incident root cause analysis and translate findings into concrete engineering and detection improvements.

4. Cross Functional Collaboration & Technical Mentorship

  • Embed within security operations and engineering planning to ensure detection and response capability keeps pace with the platform.

  • Provide expert level guidance on exploit chains and incident findings to engineering and leadership stakeholders.

  • Mentor junior security engineers on offensive tooling, detection engineering and incident response practice.
     

Qualifications

  • Education: Bachelor's degree required in Computer Science, Cyber Security, Software Engineering or a related technical discipline. A Master's degree is preferred.

  • Core Experience:  Indicative range [5 to 8 years] of progressive engineering experience across Security Operations, Incident Response and Penetration Testing.

  • Advanced Exploitation Depth: a proven track record of independently performing deep manual penetration testing, web application exploitation and incident containment rather than relying solely on commercial automated scanning platforms.

  • SecOps & Forensics Tool Stack: advanced working proficiency with modern EDR platforms, SIEM systems, network packet analysis (PCAP), threat intelligence frameworks (MITRE ATT&CK) and forensic collection tools.

  • Technical Language Depth: solid proficiency with a language such as Python, together with practical familiarity with common web and API technologies used to build exploit tooling.

  • AI & Adversarial Testing Mastery: expert level understanding of the OWASP Top 10 for LLMs and how to apply an attacker's mindset to generative AI features, including prompt injection and insecure output handling.

  • Regulatory & Compliance Competency: practical experience aligning technical testing and logging outputs with standards such as PCI-DSS (v4.0), SOC 1, SOC 2 and DORA.

Highly Preferred Certifications:

  • Hands-On Offensive & Red Team: OSCP, OSCE or SANS GXPN (GIAC Exploit Researcher and Advanced Penetration Tester).

  • Incident Response & Defence: GCIH (GIAC Certified Incident Handler), GCFA (GIAC Certified Forensic Analyst) or a specialised Blue Team certification.

  • Modern AI Security: OffSec OSAI (Offensive Security AI Red Teamer).

Skills and Abilities:

  • Combines an aggressive, attacker's mindset used to find vulnerabilities with the analytical discipline required to write clear, actionable detection rules.

  • Stays calm and analytically clear under intense pressure during active, live breach events or business critical system failures.

  • Communicates exploit chains and log anomalies clearly, turning technical detail into a plain, high impact risk profile for non-technical leadership.

  • Resilience and analytical clarity in high-pressure scenarios, with the ability to manage transparency and guide risk-based decisions during active security incidents or compressed financial product launch windows.

  • Balances technical risk reduction with business enablement, ensuring security infrastructure serves as a competitive advantage that unblocks global revenue and enterprise-client acquisition.
     

Additional Information

What We Offer:

  • Competitive compensation
  • Employee Stock Purchase Plan (ESPP)
  • Competitive time off, including Digital Disconnect and FlyBetter Days to volunteer in a cause you believe in.
  • Flying Start - Our immersive Global Induction Program (Meet our Execs & Global Teams)
  • Work with brilliant people globally  Learn more about their journeys by checking out #InsideFlywire on social media
  • Wellbeing Programs (Mental Health, Wellness, Yoga/Pilates/HIIT Classes) with Global FlyMates 
  • Be a meaningful part in our success - every FlyMate makes an impact
  • Great Talent & Development Programs (Managers Taking Flight – for new or aspiring managers, OneFlywire Career Mobility)

Submit today and get started!

We are excited to get to know you! Throughout our process you can expect to meet with different FlyMates including the Hiring Manager, Peers on the team, the VP of the department, and a skills assessment. Your Talent Acquisition Partner will walk you through the steps and be your “go-to” person for any questions.


#LI-Hybrid

Fintech

Company

FlywireFintech
Bengaluru, India

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Flywire's careers site·first seen 8 Sept 2026·last verified 8 Sept 2026·How we source jobs

Similar jobs

  • Lead Security Engineer at FlywireBengaluru, India–match not yet calculated
  • Infrastructure and Email Security Engineer at MarvellBengaluru, India–match not yet calculated
  • Application Security Engineer (AppSec Engineer) - Bengaluru at omnissaBengaluru, India–match not yet calculated
  • Senior Security Engineer (Defensive) at FlywireBengaluru, India–match not yet calculated
  • Security Engineer II (Offensive) at FlywireBengaluru, India–match not yet calculated

Browse more jobs

  • Security Engineer jobs in India
  • Security Analyst jobs in India
  • Cloud Security Engineer jobs in India
  • Penetration Tester jobs in India
  • Security Engineer jobs in United States
  • Security Engineer jobs in United Kingdom