Senior Security Engineer (Defensive)

Flywire1

Bengaluru

On-site

INR 300,000 - 500,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Flywire is seeking a Senior Security Engineer on the Defensive Platform Builder track to act as a technical authority for secure software design and cloud-native infrastructure defence across its global footprint.

You will bring an automation-first mindset to a high-velocity fintech environment, partnering with software engineering and SRE squads to embed security controls into public cloud and GitLab CI/CD pipelines using AI workflows.

Qualifications

  • 5–8 years of progressive engineering experience across Application Security and Cloud Architecture Defence.
  • Experience with AWS, Docker, Kubernetes, and CI pipelines.
  • Strong knowledge of secure SDLC and AI-driven security reviews.
  • Experience with PCI-DSS, SOC 1/2, and DORA compliance.
  • Certifications such as AWS Certified Security, CKS, CISSP are preferred.

Responsibilities

  • Own end-to-end integration of automated security requirements into high-velocity pipelines.
  • Hardening cloud and IaC, IAM and Zero Trust enforcement.
  • Design AI-powered security reviews and live code analysis.
  • Mentor engineers and collaborate with SRE/DevOps from inception.
  • Guide risk-based decisions during security incidents and launches.

Skills

Security engineering
Cloud security
CI/CD automation
Python
Node.js
AWS
Docker
Kubernetes
GitLab CI

Education

Bachelor's degree in Computer Science or related field
Master's degree preferred

Tools

AWS
Docker
Kubernetes
GitLab CI

Job description

Job Summary

As a Senior Security Engineer on the Defensive Platform Builder track you will act as a technical authority for secure software design and cloud native infrastructure defence across Flywire's global footprint. You will bring an automation first mindset to a high velocity fintech environment, partnering with software engineering and SRE squads to embed security controls directly into our public cloud and GitLab CI/CD pipelines using AI workflows, so that our global payment systems stay secure by design and resilient in production.



Responsibilities and Tasks


Secure SDLC & CI/CD Automation Ownership

Own, design and drive the end to end integration of automated security requirements and validation tooling into high velocity engineering pipelines.


Build custom internal tooling, wrappers and automated controls to replace manual security checkpoints, protecting development velocity while removing friction.



Cloud & Infrastructure Hardening

Partner directly with SRE and DevOps teams to establish secure public cloud architecture blueprints, manage Infrastructure as Code security scanning (for example Terraform) and enforce strict network isolation.


Architect and maintain cloud Identity and Access Management controls and enforce Zero Trust boundaries within containerised environments such as Docker and Kubernetes.



AI Driven Security & Application Reviews

Design, prompt engineer and deploy automated security review workflows using LLM APIs to run real time code analysis and give context aware feedback on pull requests.


Establish and enforce technical controls that protect internal and external generative AI features against LLM specific risks, including prompt injection, insecure output handling, model inversion and data poisoning.


Run deep dive source code audits and API security reviews that go beyond automated scanning, surfacing complex logic flaws before they reach production.



Cross Functional Collaboration & Technical Mentorship

Embed within software development and infrastructure sprint planning from the inception phase so that security is built in from day one rather than bolted on.


Provide expert level, actionable code and configuration guidance directly to software and SRE engineers.


Mentor junior security, software and SRE engineers to raise technical resilience across the wider organisation.



Education

Bachelor's degree required in Computer Science, Cyber Security, Software Engineering or a related technical discipline. A Master's degree is preferred.



Core Experience

indicative range [5 to 8 years] of progressive engineering experience across Application Security and Cloud Architecture Defence.



Advanced Defensive Depth

a proven track record of independently running deep manual code and configuration reviews rather than relying solely on commercial automated scanning platforms.



Cloud & DevOps Engineering Stack

deep practical knowledge of AWS or similar public cloud topologies, containerisation and orchestration (Docker, Kubernetes), network security controls and high velocity GitLab CI pipelines.



Technical Language Depth

solid proficiency with modern web development frameworks and languages including Python, Ruby on Rails, Java and Node.js.



AI & Cryptographic Domain Mastery

expert level understanding of the OWASP Top 10 for LLMs, prompt engineering wrappers, applied cryptography, cloud network isolation and federated authentication architectures (OAuth2, SAML, OIDC, Zero Trust IAM).



Regulatory & Compliance Competency

practical experience aligning technical software and infrastructure controls with standards such as PCI-DSS (v4.0), SOC 1, SOC 2 and DORA.



Highly Preferred Certifications


  • Cloud & Architecture: AWS Certified Security - Specialty, Certified Kubernetes Security Specialist (CKS) or CISSP.

  • Modern AI Security: OffSec OSAI (Offensive Security AI Red Teamer).

  • Broader Depth: OSCP or GCIH, where candidates bring exposure to offensive or incident response work as a secondary strength.



Skills and Abilities


  • Balances a builder's engineering empathy with a security first mindset, treating software, SRE and product teams as operational allies rather than a source of friction.

  • Communicates clearly under pressure, able to distill cloud configuration drift or a live vulnerability into a plain, high impact risk summary for non-technical stakeholders.

  • Shows creative, novel problem solving across complex, non-standard application and cloud infrastructure challenges within a distributed financial microservices environment.

  • Resilience and analytical clarity in high-pressure scenarios, with the ability to manage transparency and guide risk-based decisions during active security incidents or compressed financial product launch windows.

  • Balances technical risk reduction with business enablement, ensuring security infrastructure serves as a competitive advantage that unblocks global revenue and enterprise-client acquisition.



What We Offer

Competitive compensation Em

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer II (Defensive)
Security Engineer II (Defensive)

Flywire1 • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Competitive compensation
Employee Stock Purchase Plan (ESPP)
Digital Disconnect and FlyBetter Days
Senior Security Engineer (Offensive)
Senior Security Engineer (Offensive)

Flywire1 • Bengaluru

On-site
INR 3,500,000 - 7,000,000
Competitive compensation
Employee Stock Purchase Plan (ESPP)
Digital Disconnect / FlyBetter Days
Lead Security Engineer
Lead Security Engineer

Flywire1 • Bengaluru

On-site
INR 3,500,000 - 7,000,000
Competitive compensation
Employee Stock Purchase Plan (ESPP)
Digital Disconnect & FlyBetter Days to
+3
Security Engineer II (Defensive)
Security Engineer II (Defensive)

Flywire • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Competitive compensation
ESPP
Digital Disconnect & FlyBetter Days
+3
Cybersecurity Engineer – Engineering
Cybersecurity Engineer – Engineering

JobCubby • Kolkata District

On-site
INR 2,400,000 - 3,600,000
Security & Compliance Engineer Intern
Security & Compliance Engineer Intern

AI Prof • Hyderabad

On-site
INR 1,500,000 - 2,100,000
Security Architect
Security Architect

ValueLabs • Hyderabad

On-site
INR 3,000,000 - 5,000,000
Senior Security Engineer (Defensive)
Senior Security Engineer (Defensive)

Flywire • Bengaluru

Hybrid
INR 3,000,000 - 6,000,000
Employee Stock Purchase Plan (ESPP)
Competitive time off
Digital Disconnect and FlyBetter Days
+3
Security Engineer II (Offensive)
Security Engineer II (Offensive)

Flywire1 • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Competitive compensation
ESPP
Digital Disconnect & FlyBetter Days
+3
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 3,000,000