About this opportunity
Flywire lists this Security Engineer (Offensive Operations) opportunity in boston, Massachusetts. Review the employer’s description below for duties, qualifications and application requirements.
Job description
As a Security Engineer II on our Active Operational Offensive track, you’ll sit at the heart of Flywire’s security defenses under the guidance of senior engineers. You will bridge manual penetration testing with active security operations, building the technical depth needed to lead independent engagements over time
Cloud Infrastructure PenTesting: Execute manual internal and external penetration testing across AWS/multicloud environments to identify vulnerabilities, misconfigurations, and privilege escalation paths
Web Application & API Assessment: Perform deep-dive testing on web applications and REST/GraphQL APIs, targeting complex business logic flaws, auth bypasses, and OWASP Top 10 risks
Source Code & Vulnerability Analysis: Review SAST/DAST findings and conduct targeted code audits (Python, Java, Ruby) to eliminate false positives and prioritize high-risk fixes
Purple Team Operations: Partner with the Blue Team during adversary emulation exercises to validate security controls, refine enterprise SIEM detection rules, and optimize real-time alerting
Red Team Engagements: Participate in goal-oriented adversarial simulations evaluating Flywire’s physical/digital posture and incident response readiness
Bug Bounty Operations: Manage external vulnerability disclosure and bug bounty programs, triaging submissions, validating severity, and coordinating swift engineering fixes
Threat Intelligence (MITRE ATT&CK): Apply emerging threat actor TTPs to continuously align testing methodologies with the MITRE ATT&CK framework
Collaborative Advisory: Deliver actionable remediation guidance to Engineering, SRE, and IT teams, balancing robust security fixes with business velocity
Do you spend your free time figuring out how systems break? Are you driven by the thrill of discovering complex vulnerabilities before malicious actors do? If you’re a natural tinkerer who loves attacking systems to make them unshakeable, this role is built for youDual Focus: Combines an attacker’s drive to break systems with a defender’s discipline to build actionable SIEM detection rulesHigh-Impact Communication: Ability to write formal/informal technical reports and translate complex exploit chains to non-technical stakeholdersHands-on PenTesting: Demonstrated track record executing network, web application, and API penetration testsCode & Automation: Experience with SAST/DAST tools, secure code reviews, and scripting knowledge in Python, Java, or RubyComposure Under Pressure: Analytical and calm during live security breaches or tight release windowsEducation & Experience: Bachelor of Science and at least 2+ years’ experience in IT security and Penetration TestingModern Stack Exposure: Understanding of AWS Cloud infrastructure, Agile environments, CI/CD pipelines, and Infrastructure as Code (IaC)Security Frameworks: Strong knowledge of OWASP methodologies, threat vectors (malware, intrusion, DoS), and platform security strategiesBusiness-Minded Security: Balances risk mitigation with organizational growthOffensive Toolset: Proficiency with Kali Linux, commercial/open-source penetration tools, and active involvement on bug bounty platformsOffensive & Red Team: OSCP, OSCE, or SANS GXPNAI Security: OffSec OSAI (Offensive Security AI Red Teamer)
#J-18808-Ljbffr
Worksite address
boston, MA, 02298, US
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.