Security Engineer II
Boston, United States · Hybrid · Full-time
- Posted 2w ago
- From Flywire’s careers page
- Location
- Boston, United States
- Work mode
- Hybrid
- Type
- Full-time
- Level
- Senior
- Experience
- 2+ years
- Department
- Information Technology
Opens the listing on jobs.smartrecruiters.com
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
Job Description
Do you spend your free time figuring out how systems break? Are you driven by the thrill of discovering complex vulnerabilities before malicious actors do? If you’re a natural tinkerer who loves attacking systems to make them unshakeable, this role is built for you.
As a Security Engineer II on our Active Operational Offensive track, you’ll sit at the heart of Flywire’s security defenses under the guidance of senior engineers. You will bridge manual penetration testing with active security operations, building the technical depth needed to lead independent engagements over time.
Key Responsibilities & Impact
- Cloud Infrastructure PenTesting: Execute manual internal and external penetration testing across AWS/multicloud environments to identify vulnerabilities, misconfigurations, and privilege escalation paths.
- Web Application & API Assessment: Perform deep-dive testing on web applications and REST/GraphQL APIs, targeting complex business logic flaws, auth bypasses, and OWASP Top 10 risks.
- Source Code & Vulnerability Analysis: Review SAST/DAST findings and conduct targeted code audits (Python, Java, Ruby) to eliminate false positives and prioritize high-risk fixes.
- Purple Team Operations: Partner with the Blue Team during adversary emulation exercises to validate security controls, refine enterprise SIEM detection rules, and optimize real-time alerting.
- Red Team Engagements: Participate in goal-oriented adversarial simulations evaluating Flywire’s physical/digital posture and incident response readiness.
- Bug Bounty Operations: Manage external vulnerability disclosure and bug bounty programs, triaging submissions, validating severity, and coordinating swift engineering fixes.
- Threat Intelligence (MITRE ATT&CK): Apply emerging threat actor TTPs to continuously align testing methodologies with the MITRE ATT&CK framework.
- Collaborative Advisory: Deliver actionable remediation guidance to Engineering, SRE, and IT teams, balancing robust security fixes with business velocity.
Skills they ask for
Pick one to see other roles that ask for it.
About Flywire
Global payments and softwareFlywire provides payments and software for complex transactions in education, travel, business and healthcare.
See all 43 roles at FlywireMore roles at Flywire
See all 43- Product Marketing ManagerBoston · Senior · HybridMarketing · Senior · HybridBoston, United States6h
- Technical Implementation ManagerChicago · HybridCustomer Service · HybridChicago, United States10h
- Payment Operations Specialist, Infrastructure & Network EnablementBoston · Senior · HybridBusiness Operations · Senior · HybridBoston, United States10h
- Technical Implementation ManagerBoston · HybridProject and Program Management · HybridBoston, United States10h
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.