Security Engineer II - Offensive Track

Flywire1

Boston (MA)

On-site

USD 110,000 - 150,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Flywire is seeking a Security Engineer II to join the Active Operational Defender track, building hands-on experience across penetration testing, threat detection, and incident response within a fintech environment.

You will work under the guidance of senior and lead engineers, developing the skills to take on more independent responsibility over time and to contribute to live security operations and detection engineering tasks.

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, or related discipline
  • 1 to 3 years hands-on experience in penetration testing, security operations, or closely related technical role

Responsibilities

  • Support penetration testing engagements across financial platforms under senior guidance, building practical exploit research experience.
  • Assist with manual security reviews including source code audits, API testing, and cloud configuration checks, working towards independent delivery of smaller engagements.
  • Contribute to adversarial testing of AI features where in scope, learning to identify prompt injection and related LLM-specific weaknesses.
  • Help design and tune detection rules and alert workflows within the enterprise SIEM, leveraging senior guidance and established detection frameworks.
  • Act as a first-line responder during active security incidents, carrying out evidence collection and initial triage under senior direction.
  • Support post-incident analysis by pulling together logs, timelines, and technical findings for senior review.
  • Communicate testing findings and incident metrics clearly to immediate team members and stakeholders.

Skills

Penetration testing
Security operations
Threat detection
Incident response
Python scripting
MITRE ATT&CK
AI security awareness

Education

Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, or related discipline

Tools

SIEM tools
EDR tooling
Cloud configuration checks
Python tooling

Job description

Role Focus

At this level, your focus sits within Offensive Penetration Testing and Security Operations, supporting the wider Active Operational Defender track under the guidance of senior engineers. You will assist with manual testing engagements, help tune SIEM detection rules, and support the team during live security incidents, building the operational depth needed to work independently over time.

Job Summary

As a Security Engineer II on the Active Operational Defender track, you will build hands‑on experience across penetration testing, threat detection, and incident response working under the direction of senior and lead engineers. You will support live operational work within a high‑velocity fintech environment, developing the manual testing and detection engineering skills needed to take on more independent responsibility over time.

Key Responsibilities & Tasks (by Priority)
Offensive Penetration Testing & Red Teaming
  • Support penetration testing engagements across financial platforms and product architectures under senior guidance, building practical exploit research experience.
  • Assist with manual security reviews including source code audits, API testing, and cloud configuration checks, working towards independent delivery of smaller engagements.
  • Contribute to adversarial testing of AI features where in scope, learning to identify prompt injection and related LLM‑specific weaknesses.
Threat Detection Engineering & SIEM
  • Help design and tune detection rules and alert workflows within the enterprise SIEM, leveraging senior guidance and established detection frameworks.
  • Support SecOps in reviewing detection coverage against current threats using frameworks such as MITRE ATT&CK.
Incident Response & Forensics
  • Act as a first‑line responder during active security incidents, carrying out evidence collection and initial triage under senior direction.
  • Support post‑incident analysis by pulling together logs, timelines, and technical findings for senior review.
Cross‑Functional Collaboration & Development
  • Participate in security operations and engineering planning to build a practical understanding of detection and response capabilities.
  • Communicate testing findings and incident metrics clearly to immediate team members and stakeholders.
  • Actively seek mentorship from senior and lead security engineers across offensive tooling, detection engineering, and incident response practices.
Minimum Requirements (Education & Experience)
  • Education: Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, a related technical discipline, or equivalent practical experience.
  • Core Experience: 1 to 3 years of hands‑on experience in penetration testing, security operations, or a closely related technical role.
Technical Skills & Knowledge
Foundational Offensive Skills

Hands‑on exposure to manual web application testing, CTF‑style exploitation, or vulnerability research (via work experience, personal projects, or study).

SecOps & Forensics

Working knowledge of SIEM concepts, EDR tooling, or network packet analysis, alongside familiarity with frameworks such as MITRE ATT&CK.

Scripting / Automation

Proficiency in reading and writing scripts (e.g., Python) to support security testing and automation workflows.

AI Security Awareness

Basic working interest in the OWASP Top 10 for LLMs and understanding of how adversarial AI testing differs from traditional app security.

Regulatory Context

General understanding of compliance frameworks such as PCI‑DSS, SOC 2, or DORA, with a willingness to expand practical knowledge on the job.

Preferred Certifications (Optional / Strongly Encouraged)
  • Offensive & Red Team: OSCP, OSCE, or SANS GXPN.
  • Incident Response & Defense: GCIH, GCFA, or specialized Blue Team certifications.
  • AI Security: OffSec OSAI (Offensive Security AI Red Teamer).
Soft Skills & Mindset
Dual Focus

Combines an attacker's drive to uncover vulnerabilities with a defender's discipline to build actionable SIEM detection rules.

Composure Under Pressure

Ability to stay calm and analytical during live security breaches or tight production release windows.

High-Impact Communication

Capable of translating technical exploit chains and log anomalies into plain language for executive and non‑technical stakeholders.

Business-Minded Security

Balances risk mitigation with business goals, helping position security as a driver for enterprise growth.

Equal Employment Opportunity

Flywire is an equal opportunity employer and follows a policy of administering all employment decisions and personnel actions without regard to race, color, religion, sex, pregnancy, gender identity, national origin, age, ancestry, physical or mental disability, sexual ori

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer II Offensive Track
Security Engineer II Offensive Track

Flywire • Boston (MA)

Hybrid
USD 99,000 - 120,000
Security Engineer – Offensive Security
Security Engineer – Offensive Security

Jobtailor • California (MO)

On-site
USD 180,000 - 280,000
Lead Security Engineer - AppSec / CloudSec & PenTest / SecOps
Lead Security Engineer - AppSec / CloudSec & PenTest / SecOps

Flywire1 • Boston (MA)

Hybrid
USD 180,000 - 240,000
Security Engineer
Security Engineer

Jobtailor • Denver (CO)

On-site
USD 140,000 - 180,000
Sr Application Security Engineer - AI-First Development
Sr Application Security Engineer - AI-First Development

Las Vegas Sands Corp. • United States

On-site
USD 120,000 - 150,000
Sr. IT Security Engineer (Hybrid)
Sr. IT Security Engineer (Hybrid)

Belk • Town of Charlotte (NY)

Hybrid
CAD 207,000 - 276,000
Senior System Security Specialist
Senior System Security Specialist

Compunnel, Inc. • Baltimore (MD)

On-site
USD 120,000 - 150,000
Senior Analyst, Cybersecurity Red Team – Offensive Security/Penetration Testing
Senior Analyst, Cybersecurity Red Team – Offensive Security/Penetration Testing

Jobtailor • Pennsylvania

On-site
USD 120,000 - 180,000
Security Engineer
Security Engineer

Insight Global • Naperville (IL)

On-site
USD 100,000 - 130,000
Offensive Security Engineer
Offensive Security Engineer

Casco (YC X25) • United States

On-site
USD 200,000
Competitive compensation
Equity package
Learning budget
+2