Lead Security Engineer - AppSec / CloudSec & PenTest / SecOps

Flywire1

Boston (MA)

Hybrid

USD 180,000 - 240,000

Full time

7 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Flywire is seeking a Lead Security Engineer to define the technical strategy across defensive platform building and offensive assurance. You will act as the senior technical authority, mentoring engineers and aligning security roadmaps with Cyber leadership and business priorities.

You will own escalation and final sign-off on complex cloud architectures, IAM and Zero Trust, while guiding incident response, red team exercises, and continuous integration of security controls.

Qualifications

  • 8+ years of progressive security engineering experience across defensive and/or offensive domains.

Responsibilities

  • Define and own the technical strategy across secure software design and cloud defense.
  • Direct penetration testing, red team simulations, and detection engineering.
  • Escalate and sign-off on complex cloud architecture and IAM decisions.
  • Mentor engineers and shape the security engineering career ladder.

Skills

Security engineering
Cloud security
Penetration testing
Incident response
Leadership
Mentorship
Executive communication

Education

Bachelor's degree in Computer Science or related
Master's degree preferred

Tools

AWS
Azure
GCP
GitLab CI
IAM & Zero Trust

Job description

Role Focus

This is a blended role spanning both the Defensive Platform Builder (AppSec & CloudSec) and Active Operational Defender (PenTest & SecOps) disciplines. You will set the technical direction across both areas, with the opportunity for the scope to adapt based on organizational priorities.

Job Summary

As Lead Security Engineer, you will set the technical direction for security engineering across both defensive and offensive disciplines, acting as the senior technical authority for the wider team. You will combine deep hands‑on credibility with the ability to prioritize, resource, and represent the security engineering roadmap to Cyber leadership and the broader business, while directly mentoring senior and junior engineers across the function.

Key Responsibilities & Tasks (by Priority)
Technical Strategy & Roadmap

Define and own the technical strategy across secure software design, cloud infrastructure defense, offensive testing, and incident detection, aligning priorities with Cyber leadership's wider goals.

Represent the security engineering function in cross‑functional and executive forums, translating technical risk into clear business impact for non‑technical stakeholders.

Secure Engineering & Cloud Defense

Direct the integration of automated security controls into engineering pipelines and cloud infrastructure, setting the standard that senior and junior engineers build against.

Own escalation and final sign‑off on complex cloud architecture, Identity and Access Management (IAM), and Zero Trust design decisions.

Offensive Assurance & Incident Leadership

Set the standard and cadence for penetration testing, red team simulations, and detection engineering across the enterprise estate.

Act as the senior technical escalation point during critical security incidents, directing containment and post‑incident review efforts.

Team Leadership & Mentorship

Mentor senior and junior security engineers across both tracks, shaping career development and technical growth within the team.

Partner with Talent Acquisition and Cyber leadership on hiring, structuring the security engineering career ladder, and making key resourcing decisions.

Minimum Requirements (Education & Experience)

Education: Bachelor's degree in Computer Science, Cyber Security, Software Engineering, or a related technical discipline required. Master's degree preferred.

Core Experience: 8+ years of progressive security engineering experience, demonstrating deep expertise in either the defensive or offensive discipline alongside strong working fluency across both.

Technical Expertise & Core Competencies

Cross‑Discipline Credibility: Deep hands‑on seniority in application security, cloud architecture defense, penetration testing, or security operations, with the breadth to speak authoritatively across the entire function.

Cloud, DevOps & Tooling Stack: Deep practical knowledge spanning public cloud topologies (AWS/Azure/GCP), containerization/orchestration, CI/CD pipelines (GitLab CI), manual penetration testing, and forensic analysis tools.

AI Security & Cryptography: Expert‑level understanding of the OWASP Top 10 for LLMs, applied cryptography, and federated authentication architectures.

Regulatory Compliance: Practical experience aligning security controls with PCI‑DSS v4.0, SOC 1, SOC 2, and DORA standards.

Leadership Track Record: Proven background mentoring engineers, shaping technical roadmaps, and influencing hiring and resourcing decisions.

Preferred Certifications

Cloud & Architecture: AWS Certified Security - Specialty, CKS (Certified Kubernetes Security Specialist), or CISSP.

Offensive & Red Team: OSCP, OSCE, or SANS GXPN.

Incident Response & Defense: GCIH or GCFA.

Modern AI Security: OffSec OSAI (Offensive Security AI Red Teamer).

Soft Skills & Core Mindset

Dual Builder/Breaker Mindset: Transitions seamlessly between establishing defensive architecture standards and directing offensive assurance operations.

Executive Influence: Leads with influence, skillfully prioritizing competing business priorities and presenting high‑impact risks to executive leadership.

Crisis Management & Mentorship: Displays calm, analytical decision‑making under intense pressure, leveraging crisis scenarios to coach and guide engineers.

Commercial Drive: Balances technical risk reduction with enterprise enablement, positioning security as a revenue driver and business differentiator.

Company Culture & Process

We are excited to get to know you! Throughout our process you can expect to meet different FlyMates including the Hiring Manager and other Flymates. Your Talent Acquisition Partner will walk you through the steps and be your "go-to" person for questions.

Flywire is an equal opportunity employer and follows a policy of administering all employment decisions and personnel actions without regard to race, color, religion, sex, pregnancy, gender identity, national origin, age, ancestry, physical or mental disability, sexual ori

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security Engineer – AppSec / CloudSec & PenTest / SecOps
Lead Security Engineer – AppSec / CloudSec & PenTest / SecOps

Flywire • Boston (MA), Northern (KY)

On-site
USD 150,000 - 180,000
Lead Security Engineer: AppSec, CloudSec & PenTest
Lead Security Engineer: AppSec, CloudSec & PenTest

Flywire1 • Boston (MA)

Hybrid
USD 180,000 - 240,000
Security Engineering Lead: AppSec, CloudSec & PenTest
Security Engineering Lead: AppSec, CloudSec & PenTest

Flywire • Boston (MA), Northern (KY)

Hybrid
USD 150,000 - 180,000
Security Engineer II - Offensive Track
Security Engineer II - Offensive Track

Flywire1 • Boston (MA)

On-site
USD 110,000 - 150,000
Security Engineer II Offensive Track
Security Engineer II Offensive Track

Flywire • Boston (MA)

Hybrid
USD 99,000 - 120,000
Lead Security Engineer
Lead Security Engineer

Thomson Reuters • Frisco (TX)

Hybrid
USD 140,000 - 190,000
Cyber Security Engineer—Technical Lead
Cyber Security Engineer—Technical Lead

Leidos • Bethesda (MD)

On-site
USD 150,000 - 180,000
Lead Cloud Engineer
Lead Cloud Engineer

Cloud Software Group Career Center • Raleigh (NC)

On-site
USD 130,000 - 180,000
Security Engineer
Security Engineer

Insight Global • Naperville (IL)

On-site
USD 100,000 - 130,000
Senior Security Engineer
Senior Security Engineer

Chris Baily • New York (NY)

On-site
USD 150,000 - 190,000
On-site in NYC
Competitive salary