Enter a job title or keyword

Security Engineer II (Offensive Operations)

Flywire


Job Location:

Boston, NH - USA

Monthly Salary: Not provided by the employer
Posted: 12 September 2026 (2 days ago)
Application Deadline: 10 December 2026
Vacancies: 1 Vacancy

Department:

Security

Job Summary

Do you spend your free time figuring out how systems break Are you driven by the thrill of discovering complex vulnerabilities before malicious actors do If youre a natural tinkerer who loves attacking systems to make them unshakeable this role is built for you.

As a Security Engineer II on our Active Operational Offensive track youll sit at the heart of Flywires security defenses under the guidance of senior engineers. You will bridge manual penetration testing with active security operations building the technical depth needed to lead independent engagements over time.

Key Responsibilities & Impact

  • Cloud Infrastructure PenTesting: Execute manual internal and external penetration testing across AWS/multicloud environments to identify vulnerabilities misconfigurations and privilege escalation paths.

  • Web Application & API Assessment: Perform deep-dive testing on web applications and REST/GraphQL APIs targeting complex business logic flaws auth bypasses and OWASP Top 10 risks.

  • Source Code & Vulnerability Analysis: Review SAST/DAST findings and conduct targeted code audits (Python Java Ruby) to eliminate false positives and prioritize high-risk fixes.

  • Purple Team Operations: Partner with the Blue Team during adversary emulation exercises to validate security controls refine enterprise SIEM detection rules and optimize real-time alerting.

  • Red Team Engagements: Participate in goal-oriented adversarial simulations evaluating Flywires physical/digital posture and incident response readiness.

  • Bug Bounty Operations: Manage external vulnerability disclosure and bug bounty programs triaging submissions validating severity and coordinating swift engineering fixes.

  • Threat Intelligence (MITRE ATT&CK): Apply emerging threat actor TTPs to continuously align testing methodologies with the MITRE ATT&CK framework.

  • Collaborative Advisory: Deliver actionable remediation guidance to Engineering SRE and IT teams balancing robust security fixes with business velocity.


Qualifications :

Heres What Were Looking For:

  • Education & Experience: Bachelor of Science and at least 2 years experience in IT security and Penetration Testing.

  • Hands-on PenTesting: Demonstrated track record executing network web application and API penetration tests.

  • Offensive Toolset: Proficiency with Kali Linux commercial/open-source penetration tools and active involvement on bug bounty platforms.

  • Code & Automation: Experience with SAST/DAST tools secure code reviews and scripting knowledge in Python Java or Ruby.

  • Modern Stack Exposure: Understanding of AWS Cloud infrastructure Agile environments CI/CD pipelines and Infrastructure as Code (IaC).

  • Security Frameworks: Strong knowledge of OWASP methodologies threat vectors (malware intrusion DoS) and platform security strategies.

  • High-Impact Communication: Ability to write formal/informal technical reports and translate complex exploit chains to non-technical stakeholders.

Preferred Certifications (Nice-to-Have):

  • Offensive & Red Team: OSCP OSCE or SANS GXPN.

  • AI Security: OffSec OSAI (Offensive Security AI Red Teamer).

Mindset & Soft Skills:

  • Dual Focus: Combines an attackers drive to break systems with a defenders discipline to build actionable SIEM detection rules.

  • Composure Under Pressure: Analytical and calm during live security breaches or tight release windows.

  • Business-Minded Security: Balances risk mitigation with organizational growth.


Additional Information :

Submit today and get started!

We are excited to get to know you! Throughout our process you can expect to meet different FlyMates including the Hiring Manager and other Flymates. Your Talent Acquisition Partner will walk you through the steps and be your go-to person for questions.

Flywire is an equal opportunity employer and follows a policy of administering all employment decisions and personnel actions without regard to race color religion sex pregnancy gender identity national origin age ancestry physical or mental disability sexual orientation genetic disposition or carrier status veteran status or any other category protected under applicable national federal state or local law.

The US base salary range for this full-time position is $99000 - 120000 and benefits. Our salary ranges are determined by role position level and location. The range displayed on this job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. Within the range individual pay is determined by work location and several other factors including job-related skills experience relevant education and training. 

#LI-Hybrid


Remote Work :

No


Employment Type :

Full-time


About Company

Company Logo

Flywire is a global payments enablement and software company, delivering high-stakes, high-value payments across the global education, healthcare, travel and B2B industries. Today, we’ve digitized payments for more than 4,000+ global clients in more than 140 currencies across 240 cou ... View more

View Profile View Profile