Security Engineer II (Defensive Operations)
Job Description
Flywire is seeking a Security Engineer II (Defensive Operations) to join its global Security Engineering team. This hybrid role in Boston focuses on embedding security into engineering workflows, defending cloud-native systems, and leading incident response and detection engineering.
Role Overview
In this position, you will own secure software design and contribute to cloud-native infrastructure defense. You will combine an automation-first approach with practical offensive security work, including penetration testing and exploit research, while also driving real-time incident detection and containment. A key part of the role involves integrating security controls into public cloud environments and GitLab CI/CD pipelines.
Key Responsibilities
- Own and drive end-to-end integration of automated technical security requirements and validation tools into high-velocity engineering pipelines.
- Build custom internal tooling, wrappers, and automated controls that improve development velocity without adding friction.
- Partner with SRE and DevOps teams to establish secure cloud architecture blueprints.
- Manage Infrastructure-as-Code (IaC) security scans, including Terraform.
- Enforce Zero Trust boundaries in containerized environments using Docker and Kubernetes.
- Design and deploy automated security review workflows using LLM APIs (for example, Claude).
- Establish controls to protect generative AI features against prompt injection, insecure output handling, model inversion, and data poisoning.
- Discover logic flaws through manual source code audits, perform API exploitation, and run cloud penetration testing to emulate zero-day adversarial behavior across financial platforms.
- Lead technical containment, forensic collection, and rapid threat eradication during active security incidents.
- Design and deploy high-fidelity detection rules and automated alert workflows within the SIEM environment.
- Embed into software development and infrastructure sprint planning to ensure security is built in from the start.
- Provide actionable code modifications and mentor junior engineers.
Required Qualifications
- Bachelor’s degree in Computer Science, Cyber Security, Software Engineering, or a related technical discipline (or equivalent experience).
- 3+ years of progressive engineering experience spanning Application Security, Cloud Architecture Defense, and Active Security Operations (SecOps, Incident Response, Penetration Testing).
- Demonstrated ability to conduct deep manual penetration testing, web application exploitation, and incident containment without relying solely on commercial automated scanners.
- Strong practical knowledge of AWS or public cloud topologies, containerization (Docker, Kubernetes), network security, and maintaining GitLab CI pipelines.
- Foundational proficiency with modern web development frameworks and programming languages including Python, Ruby on Rails, Java, or Node.js.
- Solid understanding of OWASP Top 10 for LLMs, applied cryptography, cloud network isolation, and federated authentication architectures (OAuth2, SAML, OIDC, Zero Trust IAM).
- Working proficiency with modern EDR platforms, SIEM systems, network packet analysis (PCAP), threat intelligence frameworks (MITRE ATT&CK), and forensic collection tools.
- Practical experience mapping technical software and infrastructure controls to standards such as PCI-DSS (v4.0), SOC 1, SOC 2, or DORA.
Preferred Qualifications
- OSCP, OSCE, or SANS GXPN.
- AWS Certified Security - Specialty, CKS (Certified Kubernetes Security Specialist), or CISSP.
- GCIH, GCFA, or specialized Blue Team certifications.
- OffSec OSAI.
Technologies
- Python, Ruby on Rails, Java, Node.js
- AWS, Terraform
- Docker, Kubernetes
- GitLab CI/CD
- LLM APIs (for example, Claude)
- SIEM, EDR, PCAP
- MITRE ATT&CK
- OAuth2, SAML, OIDC, Zero Trust IAM
- OWASP Top 10 for LLMs
- PCI-DSS (v4.0), SOC 1, SOC 2, DORA
Location and Compensation
- Location: Boston, MA (hybrid)
- Salary: USD 99,000 - 120,000 per year