Security Engineer II (Defensive Operations)
Job Description
Flywire’s Security Engineering team is seeking a Security Engineer II focused on defensive operations, spanning secure software design, cloud-native infrastructure protection, and incident detection and response. This role supports a high-velocity engineering environment through automation, secure pipeline integration, and hands-on threat containment.
Role Overview
As a Security Engineer II, you will own the integration of security requirements and validation into engineering workflows, including cloud and CI/CD environments such as GitLab pipelines. You will also build internal tooling to reduce friction while strengthening guardrails across containerized systems and Infrastructure-as-Code. When threats arise, you will contribute to triage, containment, forensic collection, and rapid eradication efforts.
Key Responsibilities
- Design, own, and drive end-to-end integration of automated technical security requirements and validation tools into high-velocity engineering pipelines.
- Create custom internal tooling, wrappers, and automated controls to improve development velocity without adding friction.
- Partner with SRE and DevOps teams to define secure cloud architecture blueprints.
- Manage Infrastructure-as-Code security scans, including Terraform.
- Enforce Zero Trust boundaries in containerized environments using Docker and Kubernetes.
- Build and deploy automated security review workflows that leverage LLM APIs (for example, Claude).
- Implement protections for generative AI features against prompt injection, insecure output handling, model inversion, and data poisoning.
- Identify logic flaws, conduct exploit research, and emulate zero-day adversarial behavior across financial platforms through manual source code audits, API exploitation, and cloud penetration testing.
- Lead technical containment, forensic collection, and rapid threat eradication during active security incidents.
- Design high-fidelity detection rules and automated alert workflows within the SIEM environment.
- Embed security considerations into sprint planning for both software and infrastructure from inception.
- Provide actionable code changes and mentor junior engineers.
Required Qualifications
- Bachelor’s degree in Computer Science, Cyber Security, Software Engineering, or a related technical discipline (or equivalent experience).
- 3+ years of progressive engineering experience across Application Security, Cloud Architecture Defense, and Active Security Operations (SecOps, Incident Response, Penetration Testing).
- Demonstrated ability to perform deep manual penetration testing, web application exploitation, and incident containment without relying solely on commercial automated scanners.
- Practical knowledge of AWS or public cloud topologies, containerization (Docker, Kubernetes), network security, and building and maintaining GitLab CI pipelines.
- Foundational proficiency in modern web development frameworks and programming languages including Python, Ruby on Rails, Java, or Node.js.
- Strong understanding of the OWASP Top 10 for LLMs, applied cryptography, cloud network isolation, and federated authentication architectures (OAuth2, SAML, OIDC, Zero Trust IAM).
- Working proficiency with modern EDR platforms, SIEM systems, network packet analysis (PCAP), threat intelligence frameworks (MITRE ATT&CK), and forensic collection tools.
- Practical experience mapping technical software and infrastructure controls to standards such as PCI-DSS (v4.0), SOC 1, SOC 2, or DORA.
Preferred Certifications
- OSCP, OSCE, or SANS GXPN.
- AWS Certified Security - Specialty, CKS (Certified Kubernetes Security Specialist), or CISSP.
- GCIH, GCFA, or specialized Blue Team certifications.
- OffSec OSAI.
Location and Employment Information
- Location: Boston, MA (hybrid)
- Salary: USD 99,000 - 120,000 per year
Technologies
- Python, Ruby on Rails, Java, Node.js
- AWS
- Terraform, Docker, Kubernetes
- GitLab CI/CD
- LLM APIs (for example, Claude)
- SIEM, EDR
- PCAP
- MITRE ATT&CK
- OAuth2, SAML, OIDC, Zero Trust IAM
- OWASP Top 10 for LLMs
- PCI-DSS (v4.0), SOC 1, SOC 2, DORA