Security Engineer II (Offensive Operations)

Flywire1

Boston (MA)

Hybrid

USD 99,000 - 120,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Flywire is seeking a Security Engineer II on the Active Operational Offensive track to join our security team in Boston. You will bridge manual penetration testing with active security operations, building depth to lead engagements.

The role requires hands-on pentesting across AWS/multicloud, web apps, APIs, code reviews, and collaboration with Blue/Red teams to improve detections and incident readiness. You will triage bug bounties, apply MITRE ATT&CK, and translate complex exploits into

Qualifications

  • Bachelor of Science and 2+ years' IT security and penetration testing experience.
  • Hands-on pen-testing across network, web app, and API.
  • Experience with offensive toolsets and bug bounty platforms.
  • Scripting knowledge in Python/Java/Ruby.
  • Familiar with AWS and CI/CD/IaC.
  • Knowledge of OWASP and threat vectors.
  • Strong written and verbal communication.

Responsibilities

  • Perform manual internal and external penetration testing across AWS/multicloud.
  • Assess web applications and REST/GraphQL APIs for logic flaws and auth bypasses.
  • Review SAST/DAST findings and perform targeted code audits.
  • Collaborate with the Blue Team during purple team exercises.
  • Participate in red team engagements and bug bounty triage.
  • Apply MITRE ATT&CK to testing methodologies.
  • Provide remediation guidance to Engineering, SRE, and IT teams.

Skills

Penetration Testing
Kali Linux
Scripting (Python/Java/Ruby)
Cloud & Multi-cloud
OWASP & Security Frameworks
Threat Communication

Education

Bachelor's degree in IT security

Tools

Penetration testing tools
SAST/DAST tools

Job description

Do you spend your free time figuring out how systems break? Are you driven by the thrill of discovering complex vulnerabilities before malicious actors do? If you're a natural tinkerer who loves attacking systems to make them unshakeable, this role is built for you.

As a Security Engineer II on our Active Operational Offensive track, you'll sit at the heart of Flywire's security defenses under the guidance of senior engineers. You will bridge manual penetration testing with active security operations, building the technical depth needed to lead independent engagements over time.

Key Responsibilities & Impact
  • Cloud Infrastructure PenTesting: Execute manual internal and external penetration testing across AWS/multicloud environments to identify vulnerabilities, misconfigurations, and privilege escalation paths.
  • Web Application & API Assessment: Perform deep-dive testing on web applications and REST/GraphQL APIs, targeting complex business logic flaws, auth bypasses, and OWASP Top 10 risks.
  • Source Code & Vulnerability Analysis: Review SAST/DAST findings and conduct targeted code audits (Python, Java, Ruby) to eliminate false positives and prioritize high-risk fixes.
  • Purple Team Operations: Partner with the Blue Team during adversary emulation exercises to validate security controls, refine enterprise SIEM detection rules, and optimize real-time alerting.
  • Red Team Engagements: Participate in goal-oriented adversarial simulations evaluating Flywire's physical/digital posture and incident response readiness.
  • Bug Bounty Operations: Manage external vulnerability disclosure and bug bounty programs, triaging submissions, validating severity, and coordinating swift engineering fixes.
  • Threat Intelligence (MITRE ATT&CK): Apply emerging threat actor TTPs to continuously align testing methodologies with the MITRE ATT&CK framework.
  • Collaborative Advisory: Deliver actionable remediation guidance to Engineering, SRE, and IT teams, balancing robust security fixes with business velocity.
Here’s What We’re Looking For:
  • Education & Experience: Bachelor of Science and at least 2+ years' experience in IT security and Penetration Testing.
  • Hands-on PenTesting: Demonstrated track record executing network, web application, and API penetration tests.
  • Offensive Toolset: Proficiency with Kali Linux, commercial/open-source penetration tools, and active involvement on bug bounty platforms.
  • Code & Automation: Experience with SAST/DAST tools, secure code reviews, and scripting knowledge in Python, Java, or Ruby.
  • Modern Stack Exposure: Understanding of AWS Cloud infrastructure, Agile environments, CI/CD pipelines, and Infrastructure as Code (IaC).
  • Security Frameworks: Strong knowledge of OWASP methodologies, threat vectors (malware, intrusion, DoS), and platform security strategies.
  • High-Impact Communication: Ability to write formal/informal technical reports and translate complex exploit chains to non-technical stakeholders.
Preferred Certifications (Nice-to-Have):
  • Offensive & Red Team: OSCP, OSCE, or SANS GXPN.
  • AI Security: OffSec OSAI (Offensive Security AI Red Teamer).
Mindset & Soft Skills:
  • Dual Focus: Combines an attacker's drive to break systems with a defender's discipline to build actionable SIEM detection rules.
  • Composure Under Pressure: Analytical and calm during live security breaches or tight release windows.
  • Business-Minded Security: Balances risk mitigation with organizational growth.

We are excited to get to know you! Throughout our process you can expect to meet different FlyMates including the Hiring Manager and other Flymates. Your Talent Acquisition Partner will walk you through the steps and be your "go-to" person for questions.

Flywire is an equal opportunity employer and follows a policy of administering all employment decisions and personnel actions without regard to race, color, religion, sex, pregnancy, gender identity, national origin, age, ancestry, physical or mental disability, sexual orientation, genetic disposition or carrier status, veteran status, or any other category protected under applicable national, federal, state or local law.

The US base salary range for this full-time position is $99,000 - 120,000 and benefits. Our salary ranges are determined by role, position level, and location. The range displayed on this job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. Within the range, individual pay is determined by work location and several other factors, including job-…

#LI-Hybrid

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer II (Offensive Operations)
Security Engineer II (Offensive Operations)

Flywire • Boston (MA), Northern (KY)

Hybrid
USD 99,000 - 120,000
Security Engineer II (Offensive Operations)
Security Engineer II (Offensive Operations)

JobCubby • Boston (MA), Northern (KY)

Hybrid
USD 99,000 - 120,000
Security Engineer II Offensive Track
Security Engineer II Offensive Track

Flywire • Boston (MA)

Hybrid
USD 99,000 - 120,000
Lead Security Engineer – AppSec / CloudSec & PenTest / SecOps
Lead Security Engineer – AppSec / CloudSec & PenTest / SecOps

Flywire • Boston (MA), Northern (KY)

On-site
USD 150,000 - 180,000
Security Technical Program Manager
Security Technical Program Manager

Flywire • Boston (MA)

On-site
USD 97,000 - 120,000
Security Engineer II - Offensive Track
Security Engineer II - Offensive Track

Flywire1 • Boston (MA)

On-site
USD 110,000 - 150,000
Offensive Security Engineer II - Penetration Testing
Offensive Security Engineer II - Penetration Testing

Flywire • Boston (MA), Northern (KY)

Hybrid
USD 99,000 - 120,000
Technical Support Engineer II
Technical Support Engineer II

Flywire • Boston (MA)

On-site
USD 81,000 - 101,000
Security Engineer II: Offensive Pen Testing & Purple Team
Security Engineer II: Offensive Pen Testing & Purple Team

Flywire1 • Boston (MA)

Hybrid
USD 99,000 - 120,000
Senior Payments Strategy & Operations Manager
Senior Payments Strategy & Operations Manager

Flywire • Boston (MA)

On-site
USD 140,000 - 175,000
Competitive compensation
Employee Stock Purchase Plan (ESPP)
Wellbeing Programs