Security Engineer (Offensive Operations)

Flywire

Boston (MA)

On-site

USD 90,000 - 120,000

Full time

7 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Flywire is seeking a Security Engineer II to join our Active Operational Offensive track in Boston. You will bridge manual penetration testing with active security operations, driving hands-on assessments across cloud, web, and API surfaces.

You will partner with engineering and IT teams to prioritize fixes, improve detections, and lead engagements that validate security controls in real-time.

Qualifications

  • Bachelor’s degree in IT security or related field; 2+ years in IT security/pen testing.
  • Experience conducting network, web, and API penetration tests.
  • Familiarity with security frameworks and vulnerability remediation.

Responsibilities

  • Perform manual internal and external penetration testing across AWS/multicloud environments to identify vulnerabilities.
  • Test web applications and REST/GraphQL APIs for complex logic flaws and auth bypasses.
  • Review SAST/DAST findings and conduct targeted code audits in Python, Java, or Ruby.
  • Collaborate with the Blue Team to refine SIEM detection rules and threat intel usage.
  • Support Red Team engagements and bug bounty triage and coordination.
  • Apply MITRE ATT&CK to testing methodologies and improve coverage.
  • Provide remediation guidance to Engineering, SRE, and IT teams.

Skills

Penetration testing
Blue team collaboration
Threat intelligence
Python/Java/Ruby
OWASP
AWS
SAST/DAST
Kali Linux
Bug bounty
Adversary emulation

Education

Bachelor’s degree in IT security

Tools

?

Job description

  • As a Security Engineer II on our Active Operational Offensive track, you’ll sit at the heart of Flywire’s security defenses under the guidance of senior engineers. You will bridge manual penetration testing with active security operations, building the technical depth needed to lead independent engagements over time
  • Cloud Infrastructure PenTesting: Execute manual internal and external penetration testing across AWS/multicloud environments to identify vulnerabilities, misconfigurations, and privilege escalation paths
  • Web Application & API Assessment: Perform deep-dive testing on web applications and REST/GraphQL APIs, targeting complex business logic flaws, auth bypasses, and OWASP Top 10 risks
  • Source Code & Vulnerability Analysis: Review SAST/DAST findings and conduct targeted code audits (Python, Java, Ruby) to eliminate false positives and prioritize high-risk fixes
  • Purple Team Operations: Partner with the Blue Team during adversary emulation exercises to validate security controls, refine enterprise SIEM detection rules, and optimize real-time alerting
  • Red Team Engagements: Participate in goal-oriented adversarial simulations evaluating Flywire’s physical/digital posture and incident response readiness
  • Bug Bounty Operations: Manage external vulnerability disclosure and bug bounty programs, triaging submissions, validating severity, and coordinating swift engineering fixes
  • Threat Intelligence (MITRE ATT&CK): Apply emerging threat actor TTPs to continuously align testing methodologies with the MITRE ATT&CK framework
  • Collaborative Advisory: Deliver actionable remediation guidance to Engineering, SRE, and IT teams, balancing robust security fixes with business velocity

Do you spend your free time figuring out how systems break? Are you driven by the thrill of discovering complex vulnerabilities before malicious actors do? If you’re a natural tinkerer who loves attacking systems to make them unshakeable, this role is built for youDual Focus: Combines an attacker’s drive to break systems with a defender’s discipline to build actionable SIEM detection rulesHigh-Impact Communication: Ability to write formal/informal technical reports and translate complex exploit chains to non-technical stakeholdersHands-on PenTesting: Demonstrated track record executing network, web application, and API penetration testsCode & Automation: Experience with SAST/DAST tools, secure code reviews, and scripting knowledge in Python, Java, or RubyComposure Under Pressure: Analytical and calm during live security breaches or tight release windowsEducation & Experience: Bachelor of Science and at least 2+ years’ experience in IT security and Penetration TestingModern Stack Exposure: Understanding of AWS Cloud infrastructure, Agile environments, CI/CD pipelines, and Infrastructure as Code (IaC)Security Frameworks: Strong knowledge of OWASP methodologies, threat vectors (malware, intrusion, DoS), and platform security strategiesBusiness-Minded Security: Balances risk mitigation with organizational growthOffensive Toolset: Proficiency with Kali Linux, commercial/open-source penetration tools, and active involvement on bug bounty platformsOffensive & Red Team: OSCP, OSCE, or SANS GXPNAI Security: OffSec OSAI (Offensive Security AI Red Teamer)

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer II: Offensive Operations & PenTesting
Security Engineer II: Offensive Operations & PenTesting

Flywire • Massachusetts

Hybrid
USD 99,000 - 120,000
Security Engineer II - Offensive Track
Security Engineer II - Offensive Track

Flywire1 • Boston (MA)

On-site
USD 110,000 - 150,000
Security Engineer II: Offensive Operations (Hybrid)
Security Engineer II: Offensive Operations (Hybrid)

Flywire • Boston (MA)

Hybrid
USD 99,000 - 120,000
Security Engineer II (Offensive Operations)
Security Engineer II (Offensive Operations)

Flywire • Massachusetts

Hybrid
USD 99,000 - 120,000
Security Engineer II (Offensive Operations)
Security Engineer II (Offensive Operations)

Flywire • Boston (MA)

Hybrid
USD 99,000 - 120,000
Offensive Security Engineer: Pen-Testing & Red Team Ops
Offensive Security Engineer: Pen-Testing & Red Team Ops

Flywire • Boston (MA)

On-site
USD 90,000 - 120,000
Security Engineer II Offensive Track
Security Engineer II Offensive Track

Flywire • Boston (MA)

On-site
USD 99,000 - 120,000
Security Engineer II: Offensive Pen Testing & SIEM
Security Engineer II: Offensive Pen Testing & SIEM

CyberJobs.Com • Boston (MA)

On-site
USD 99,000 - 120,000
Security Engineer, Offensive Security
Security Engineer, Offensive Security

Anthropic • United States

Remote
USD 150,000 - 210,000
Cybersecurity Engineer
Cybersecurity Engineer

CyberJobs.Com • Boston (MA)

On-site
USD 99,000 - 120,000