Security Engineer II Offensive Track

Flywire

Boston (MA)

Hybrid

USD 99,000 - 120,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Flywire seeks a Security Engineer II to advance in offensive testing, threat detection, and incident response within a fintech environment. You will work under senior engineers, building hands-on testing and detection engineering skills while handling live operational work.

Responsibilities include manual testing, API and cloud checks, tuning SIEM rules, and contributing to incident handling. Collaboration and mentorship are emphasized for growth into independent delivery over time.

Qualifications

  • Education: Bachelor's degree in CS, cybersecurity, software engineering, or equivalent.
  • Core experience: 1–3 years in penetration testing, security operations, or related role.
  • Foundational offensive, SecOps, and scripting skills required.

Responsibilities

  • Support penetration testing engagements and assist with manual security reviews.
  • Tune detection rules and SIEM alert workflows with guidance.
  • Act as first-line responder during incidents and assist in forensics.
  • Collaborate across teams and communicate findings clearly.

Skills

Offensive testing
SecOps & Forensics
Scripting (Python)
AI security awareness
Regulatory context

Education

Bachelor's degree in CS / Cybersecurity

Tools

SIEM
EDR tooling
Python

Job description

Job Description

Role Focus

At this level, your focus sits within Offensive Penetration Testing and Security Operations, supporting the wider Active Operational Defender track under the guidance of senior engineers. You will assist with manual testing engagements, help tune SIEM detection rules, and support the team during live security incidents, building the operational depth needed to work independently over time.

Job Summary

As a Security Engineer II on the Active Operational Defender track, you will build hands-on experience across penetration testing, threat detection, and incident response working under the direction of senior and lead engineers. You will support live operational work within a high-velocity fintech environment, developing the manual testing and detection engineering skills needed to take on more independent responsibility over time.

Key Responsibilities & Tasks (by Priority)
Offensive Penetration Testing & Red Teaming
  • Support penetration testing engagements across financial platforms and product architectures under senior guidance, building practical exploit research experience.
  • Assist with manual security reviews including source code audits, API testing, and cloud configuration checks, working towards independent delivery of smaller engagements.
  • Contribute to adversarial testing of AI features where in scope, learning to identify prompt injection and related LLM-specific weaknesses.
Threat Detection Engineering & SIEM
  • Help design and tune detection rules and alert workflows within the enterprise SIEM, leveraging senior guidance and established detection frameworks.
  • Support SecOps in reviewing detection coverage against current threats using frameworks such as MITRE ATT&CK.
Incident Response & Forensics
  • Act as a first-line responder during active security incidents, carrying out evidence collection and initial triage under senior direction.
  • Support post-incident analysis by pulling together logs, timelines, and technical findings for senior review.
Cross-Functional Collaboration & Development
  • Participate in security operations and engineering planning to build a practical understanding of detection and response capabilities.
  • Communicate testing findings and incident metrics clearly to immediate team members and stakeholders.
  • Actively seek mentorship from senior and lead security engineers across offensive tooling, detection engineering, and incident response practices.
Qualifications
Minimum Requirements (Education & Experience)
  • Education: Bachelor’s degree in Computer Science, Cybersecurity, Software Engineering, a related technical discipline, or equivalent practical experience.
  • Core Experience: 1 to 3 years of hands-on experience in penetration testing, security operations, or a closely related technical role.
Technical Skills & Knowledge
  • Foundational Offensive Skills: Hands-on exposure to manual web application testing, CTF-style exploitation, or vulnerability research (via work experience, personal projects, or study).
  • SecOps & Forensics: Working knowledge of SIEM concepts, EDR tooling, or network packet analysis, alongside familiarity with frameworks such as MITRE ATT&CK.
  • Scripting / Automation: Proficiency in reading and writing scripts (e.g., Python) to support security testing and automation workflows.
  • AI Security Awareness: Basic working interest in the OWASP Top 10 for LLMs and understanding of how adversarial AI testing differs from traditional app security.
  • Regulatory Context: General understanding of compliance frameworks such as PCI-DSS, SOC 2, or DORA, with a willingness to expand practical knowledge on the job.
Preferred Certifications (Optional / Strongly Encouraged)
  • Offensive & Red Team: OSCP, OSCE, or SANS GXPN.
  • Incident Response & Defense: GCIH, GCFA, or specialized Blue Team certifications.
  • AI Security: OffSec OSAI (Offensive Security AI Red Teamer).
Soft Skills & Mindset
  • Dual Focus: Combines an attacker’s drive to uncover vulnerabilities with a defender's discipline to build actionable SIEM detection rules.
  • Composure Under Pressure: Ability to stay calm and analytical during live security breaches or tight production release windows.
  • High-Impact Communication: Capable of translating technical exploit chains and log anomalies into plain language for executive and non-technical stakeholders.
  • Business-Minded Security: Balances risk mitigation with business goals, helping position security as a driver for enterprise growth.

Additional Information

We are excited to get to know you! Throughout our process you can expect to meet different FlyMates including the Hiring Manager and other Flymates. Your Talent Acquisition Partner will walk you through the steps and be your “go-to” person for questions.

Flywire is an equal opportunity employer and follows a policy of administering all employment decisions and personnel actions without regard to race, color, religion, sex, pregnancy, gender identity, national origin, age, ancestry, physical or mental disability, sexual orientation, genetic disposition or carrier status, veteran status, or any other category protected under applicable national, federal, state or local law.

The US base salary range for this full-time position is $99,000 - 120,000 and benefits. Our salary ranges are determined by role, position level, and location. The range displayed on this job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. Within the range, individual pay is determined by work location and several other factors, including job-related skills, experience, relevant education and training.

#LI-Hybrid

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer II - Offensive Track
Security Engineer II - Offensive Track

Flywire1 • Boston (MA)

On-site
USD 110,000 - 150,000
Lead Security Engineer – AppSec / CloudSec & PenTest / SecOps
Lead Security Engineer – AppSec / CloudSec & PenTest / SecOps

Flywire • Boston (MA), Northern (KY)

On-site
USD 150,000 - 180,000
Security Technical Program Manager
Security Technical Program Manager

Flywire • Boston (MA)

On-site
USD 97,000 - 120,000
Lead Security Engineer - AppSec / CloudSec & PenTest / SecOps
Lead Security Engineer - AppSec / CloudSec & PenTest / SecOps

Flywire1 • Boston (MA)

Hybrid
USD 180,000 - 240,000
Security Engineer II: Offensive Testing & SIEM
Security Engineer II: Offensive Testing & SIEM

Flywire • Boston (MA)

Hybrid
USD 99,000 - 120,000
Security Engineer II: PenTesting, SIEM & Incident Response
Security Engineer II: PenTesting, SIEM & Incident Response

Flywire1 • Boston (MA)

On-site
USD 110,000 - 150,000
Technical Support Engineer II
Technical Support Engineer II

Flywire • Town of Texas (WI)

Hybrid
USD 81,000 - 101,000
Hybrid work model
Global team
Offensive Security Engineer
Offensive Security Engineer

Casco (YC X25) • United States

On-site
USD 200,000
Competitive compensation
Equity package
Learning budget
+2
Senior Staff Software Security Engineer
Senior Staff Software Security Engineer

United States Digital Space LLC • Bellevue (CA)

On-site
USD 247,000 - 290,000
Health insurance
Equity
401(k) matching
+2
Offensive Security Engineer
Offensive Security Engineer

J.P. Morgan • New York (NY)

On-site
USD 130,000 - 180,000
Comprehensive health care coverage
Retirement savings plan
Tuition reimbursement
+1