Security Engineer II – Offensive Track

Posted An Hour Ago
Be an Early Applicant
Boston, MA, USA
Hybrid
99K-120K Annually
Junior
Fintech • Payments • Software
Delivering the most important and complex payments.
The Role
Supports penetration testing, source code audits, API testing, cloud security reviews, SIEM detection tuning, incident response, and forensic evidence collection. The role combines offensive security, threat detection, and operational defense under senior guidance, with opportunities to assess AI features and communicate technical findings to stakeholders.
Summary Generated by Built In
Company Description

Are you ready to trade your job for a journey? Become a FlyMate!

Passion, excitement & global collaboration are all core to what it means to be a FlyMate. At Flywire, we’re on a mission to deliver the world’s most important and complex payments. We use our Flywire Advantage - the combination of our next-gen payments platform, proprietary payment network and vertical specific software, to help our clients get paid, and help their customers pay with ease - no matter where they are in the world.

What more do we need to truly be unstoppable? Perhaps, that is you! 

Who we are: 
Flywire is a global payments enablement and software company, founded more than a decade ago to solve high-stakes, high-value payments in higher education. We’ve since scaled into new regions and industry verticals and expanded our product offerings to deliver meaningful value to our clients around the world. 

Today we support more than 5,300 clients across the global education, healthcare, travel & B2B industries, with diverse payment methods across 240 countries & territories and more than 140 currencies.

With over 1,400 global FlyMates, representing more than 40 nationalities, and in 15 offices world-wide, we’re looking for FlyMates to join the next stage of our journey as we continue to grow.
 

Job Description

Role Focus

At this level, your focus sits within Offensive Penetration Testing and Security Operations, supporting the wider Active Operational Defender track under the guidance of senior engineers. You will assist with manual testing engagements, help tune SIEM detection rules, and support the team during live security incidents, building the operational depth needed to work independently over time.

Job Summary

As a Security Engineer II on the Active Operational Defender track, you will build hands-on experience across penetration testing, threat detection, and incident response working under the direction of senior and lead engineers. You will support live operational work within a high-velocity fintech environment, developing the manual testing and detection engineering skills needed to take on more independent responsibility over time.

Key Responsibilities & Tasks (by Priority)

  1. Offensive Penetration Testing & Red Teaming

    • Support penetration testing engagements across financial platforms and product architectures under senior guidance, building practical exploit research experience.

    • Assist with manual security reviews including source code audits, API testing, and cloud configuration checks, working towards independent delivery of smaller engagements.

    • Contribute to adversarial testing of AI features where in scope, learning to identify prompt injection and related LLM-specific weaknesses.

  2. Threat Detection Engineering & SIEM

    • Help design and tune detection rules and alert workflows within the enterprise SIEM, leveraging senior guidance and established detection frameworks.

    • Support SecOps in reviewing detection coverage against current threats using frameworks such as MITRE ATT&CK.

  3. Incident Response & Forensics

    • Act as a first-line responder during active security incidents, carrying out evidence collection and initial triage under senior direction.

    • Support post-incident analysis by pulling together logs, timelines, and technical findings for senior review.

  4. Cross-Functional Collaboration & Development

    • Participate in security operations and engineering planning to build a practical understanding of detection and response capabilities.

    • Communicate testing findings and incident metrics clearly to immediate team members and stakeholders.

    • Actively seek mentorship from senior and lead security engineers across offensive tooling, detection engineering, and incident response practices.

Qualifications

Minimum Requirements (Education & Experience)

  • Education: Bachelor’s degree in Computer Science, Cybersecurity, Software Engineering, a related technical discipline, or equivalent practical experience.

  • Core Experience: 1 to 3 years of hands-on experience in penetration testing, security operations, or a closely related technical role.

Technical Skills & Knowledge

  • Foundational Offensive Skills: Hands-on exposure to manual web application testing, CTF-style exploitation, or vulnerability research (via work experience, personal projects, or study).

  • SecOps & Forensics: Working knowledge of SIEM concepts, EDR tooling, or network packet analysis, alongside familiarity with frameworks such as MITRE ATT&CK.

  • Scripting / Automation: Proficiency in reading and writing scripts (e.g., Python) to support security testing and automation workflows.

  • AI Security Awareness: Basic working interest in the OWASP Top 10 for LLMs and understanding of how adversarial AI testing differs from traditional app security.

  • Regulatory Context: General understanding of compliance frameworks such as PCI-DSS, SOC 2, or DORA, with a willingness to expand practical knowledge on the job.

Preferred Certifications (Optional / Strongly Encouraged)

  • Offensive & Red Team: OSCP, OSCE, or SANS GXPN.

  • Incident Response & Defense: GCIH, GCFA, or specialized Blue Team certifications.

  • AI Security: OffSec OSAI (Offensive Security AI Red Teamer).

Soft Skills & Mindset

  • Dual Focus: Combines an attacker’s drive to uncover vulnerabilities with a defender's discipline to build actionable SIEM detection rules.

  • Composure Under Pressure: Ability to stay calm and analytical during live security breaches or tight production release windows.

  • High-Impact Communication: Capable of translating technical exploit chains and log anomalies into plain language for executive and non-technical stakeholders.

  • Business-Minded Security: Balances risk mitigation with business goals, helping position security as a driver for enterprise growth.

Additional Information

Submit today and get started!

We are excited to get to know you! Throughout our process you can expect to meet different FlyMates including the Hiring Manager and other Flymates. Your Talent Acquisition Partner will walk you through the steps and be your “go-to” person for questions.

Flywire is an equal opportunity employer and follows a policy of administering all employment decisions and personnel actions without regard to race, color, religion, sex, pregnancy, gender identity, national origin, age, ancestry, physical or mental disability, sexual orientation, genetic disposition or carrier status, veteran status, or any other category protected under applicable national, federal, state or local law.

The US base salary range for this full-time position is $99,000 - 120,000 and benefits. Our salary ranges are determined by role, position level, and location. The range displayed on this job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. Within the range, individual pay is determined by work location and several other factors, including job-related skills, experience, relevant education and training. 

#LI-Hybrid

Skills Required

  • Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, a related technical discipline, or equivalent practical experience
  • 1 to 3 years of hands-on experience in penetration testing, security operations, or a closely related technical role
  • Hands-on exposure to manual web application testing, CTF-style exploitation, or vulnerability research
  • Working knowledge of SIEM concepts, EDR tooling, or network packet analysis
  • Familiarity with MITRE ATT&CK
  • Proficiency in reading and writing scripts, such as Python, for security testing and automation
  • Basic working knowledge of the OWASP Top 10 for LLMs and adversarial AI testing
  • General understanding of PCI DSS, SOC 2, or DORA compliance frameworks
  • OSCP, OSCE, or SANS GXPN certification
  • GCIH, GCFA, or specialized Blue Team certification
  • OffSec OSAI certification

What the Team is Saying

Emma
Allison MacLeod
Annie
Maicol
Ilona
Chinwe
Lucy
Jarrod

Flywire Compensation & Benefits Highlights

  • Leave & Time Off Breadth Generous PTO, company-wide Digital Disconnect Days, and additional Fly Better Days for volunteering are highlighted, alongside paid holidays. These programs encourage unplugging and support work–life balance.
  • Equity Value & Accessibility Roles commonly include Restricted Stock Units, and an employee stock purchase plan is referenced in corporate filings, positioning employees as owners. Equity is presented as a meaningful part of total rewards beyond base pay.
  • Healthcare Strength Employer-verified benefits include medical, dental, vision, mental-health support, and FSA/HSA options, with notes of strong employer cost-sharing and relatively low U.S. premiums. This combination indicates robust core coverage.

Flywire Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Boston, MA
1,200 Employees
Year Founded: 2011

What We Do

Flywire is a global payments enablement and software company. We combine our proprietary global payments network, next-gen payments platform and vertical-specific software to deliver the most important and complex payments for our clients and their customers.

Why Work With Us

Global collaboration is at the heart of what we do at Flywire. We’re excited to watch our unique culture evolve with each new FlyMate; it's our differences as individuals that make us stronger as a team. With over 30 nationalities across 11 countries, we believe our FlyMates are our greatest asset.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Flywire Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

We are a remote first company, with 14 beautiful offices around the globe! There is no requirement to go into the office, however the option is there if that's what you prefer. At Flywire, we want you to chose what's best for your lifestyle.

Typical time on-site: Flexible
HQFlywire US HQ
Japan
Canada
Lithuania
Australia
Brisbane, AU
Chicago, IL
Cluj-Napoca, RO
Flywire UK
New Delhi, IN
Pune, IN
Flywire Singapore
Tel Aviv-Yafo, IL
Flywire Spain
Learn more

Similar Jobs

Flywire Logo Flywire

Security Engineer

Fintech • Payments • Software
Hybrid
Boston, MA, USA
1200 Employees
150K-180K Annually

Flywire Logo Flywire

Product Marketing Manager

Fintech • Payments • Software
Hybrid
Boston, MA, USA
1200 Employees
100K-120K Annually

Flywire Logo Flywire

Account Executive

Fintech • Payments • Software
Remote or Hybrid
Boston, MA, USA
1200 Employees
98K-130K Annually

Flywire Logo Flywire

Product Marketing Manager

Fintech • Payments • Software
Hybrid
Boston, MA, USA
1200 Employees
100K-120K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account