Security Engineer II (Defensive Operations)

Security Engineer II (Defensive Operations)

22 Sep 2026
Massachusetts, Boston, 02108 Boston USA

Security Engineer II (Defensive Operations)

At Flywire, we are looking for a Security Engineer II to join our global Security Engineering team. In this role, you will serve as a technical authority owning secure software design, cloud-native infrastructure defense, offensive penetration testing, and real-time incident detection across Flywire’s global footprint. You will combine a "breaker" mindset with a builder’s engineering empathy, operating fluidly across the entire product and infrastructure security lifecycle.This role demands an "automation-first" approach embedded within a high-velocity fintech ecosystem. You will actively partner with software engineering and SRE squads to integrate security controls directly into our public cloud and GitLab CI/CD pipelines using AI workflows. Simultaneously, you will serve as an operational responder for threat detection engineering, red team penetration testing, and live incident containment.Key Responsibilities:Secure SDLC & CI/CD Automation: Own, design, and drive the end-to-end integration of automated technical security requirements and validation tools into high-velocity engineering pipelines. Build custom internal tooling, wrappers, and automated controls to maximize development velocity without friction.SRE & Cloud Infrastructure Hardening: Partner directly with SRE and DevOps teams to establish secure cloud architecture blueprints, manage Infrastructure-as-Code (IaC) security scans (Terraform), and enforce Zero Trust boundaries in containerized environments (Docker/Kubernetes).AI-Driven Security & Governance: Design and deploy automated security review workflows using LLM APIs (e.g., Claude). Establish controls to protect generative AI features against prompt injection, insecure output handling, model inversion, and data poisoning.Offensive Penetration Testing & Red Teaming: Adopt an attacker's mindset to discover logic flaws, perform exploit research, and emulate zero-day adversarial behavior across financial platforms through manual source code audits, API exploitation, and cloud penetration testing.Incident Response & Threat Detection: Lead technical containment, forensic collection, and rapid threat eradication during active security incidents. Design and deploy high-fidelity detection rules and automated alert workflows within the SIEM environment.Cross-Functional Collaboration & Mentorship: Embed within software development and infrastructure sprint planning from inception to ensure security is built-in from day one. Provide actionable code modifications and mentor junior engineers.

Related jobs

Job Details

Jocancy Online Job Portal by jobSearchi.