Flywire Logo

Flywire

Lead Security Engineer

Posted An Hour Ago
Be an Early Applicant
Hybrid
Bengaluru, Bengaluru Urban, Karnataka
Senior level
Hybrid
Bengaluru, Bengaluru Urban, Karnataka
Senior level
Leads security engineering strategy across application security, cloud security, penetration testing, red teaming, and security operations. Establishes secure engineering and cloud defense standards, oversees IAM and Zero Trust architecture, directs offensive testing and incident response, and mentors security engineers. Represents security priorities to executives, aligns controls with regulatory frameworks, and supports hiring, career development, roadmap planning, and resource allocation.
The summary above was generated by AI
Company Description

Are you ready to trade your job for a journey? Become a FlyMate!

Passion, excitement & global collaboration are all core to what it means to be a FlyMate. At Flywire, we’re on a mission to deliver the world’s most important and complex payments. We use our Flywire Advantage - the combination of our next-gen payments platform, proprietary payment network and vertical specific software, to help our clients get paid, and help their customers pay with ease - no matter where they are in the world.

What more do we need to truly be unstoppable? Perhaps, that is you! 

Who we are: 

Flywire is a global payments enablement and software company, founded more than a decade ago to solve high-stakes, high-value payments. We’ve scaled into new regions and industry verticals and expanded our product offerings to deliver meaningful value to our clients around the world. 

Today we support more than 5,300 clients across the global education, healthcare, travel & B2B industries, with diverse payment methods across 240 countries & territories and more than 140 currencies.

With over 1,400+ global FlyMates, representing more than 40 nationalities, and in 15 offices world-wide, we’re looking for FlyMates to join the next stage of our journey as we continue to grow.

 

Job Description

Job Summary:

As Lead Security Engineer you will set the technical direction for security engineering across both the defensive, AppSec and CloudSec, and offensive, PenTest and SecOps, disciplines, acting as the senior technical authority for the wider team. You will combine deep hands on credibility with the ability to prioritise, resource and represent the security engineering roadmap to Cyber leadership and the broader business, while directly mentoring senior and junior engineers across the function.

Responsibilities and Tasks:

1. Technical Strategy & Roadmap

  • Define and own the technical strategy across secure software design, cloud infrastructure defence, offensive testing and incident detection, aligning priorities with Cyber leadership's wider goals.

  • Represent the security engineering function in cross functional and executive forums, translating technical risk into business impact for non-technical stakeholders.

2. Secure Engineering & Cloud Defence

  • Direct the integration of automated security controls into engineering pipelines and cloud infrastructure, setting the standard that senior and junior engineers build against.

  • Own escalation and final sign off on complex cloud architecture, Identity and Access Management and Zero Trust design decisions.

3. Offensive Assurance & Incident Leadership

  • Set the standard and cadence for penetration testing, red team simulations and detection engineering across the estate.

  • Act as the senior technical escalation point during critical security incidents, directing containment and post incident review.

4. Team Leadership & Mentorship

  • Mentor senior and junior security engineers across both tracks, shaping career development and technical growth within the team.

  • Partner with Talent Acquisition and Cyber leadership on hiring, structuring the security engineering career ladder and resourcing decisions.
     

Qualifications

  • Education: Bachelor's degree required in Computer Science, Cyber Security, Software Engineering or a related technical discipline. A Master's degree is preferred.

  • Core Experience:  Indicative range [8 or more years] of progressive engineering experience, with demonstrated depth in either the defensive or offensive discipline and strong working fluency across both.

  • Cross Discipline Credibility: hands on seniority in application security, cloud architecture defence, penetration testing or security operations, with the range to speak authoritatively across the wider function.

  • Cloud, DevOps & Exploitation Stack: deep practical knowledge spanning public cloud topologies, containerisation and orchestration, GitLab CI pipelines, and manual testing and forensic tooling.

  • AI & Regulatory Mastery: expert level understanding of the OWASP Top 10 for LLMs, applied cryptography and federated authentication architectures, together with practical experience aligning controls to PCI-DSS (v4.0), SOC 1, SOC 2 and DORA.

  • Leadership Track Record: prior experience mentoring engineers, shaping technical roadmaps or influencing hiring and resourcing decisions within a security or engineering function.

Highly Preferred Certifications:

  • Cloud & Architecture: AWS Certified Security - Specialty, CKS or CISSP.

  • Hands-On Offensive & Red Team: OSCP, OSCE or SANS GXPN.

  • Incident Response & Defence: GCIH or GCFA.

  • Modern AI Security: OffSec OSAI (Offensive Security AI Red Teamer).

Skills and Abilities:

  • Moves credibly between builder and breaker mindsets, equally comfortable setting defensive architecture standards and directing offensive assurance work.

  • Leads with influence rather than authority alone, able to prioritise competing security priorities and represent them clearly to executive stakeholders.

  • Brings calm, analytically clear decision making under pressure and uses that same clarity to coach senior and junior engineers through complex incidents.

  • Resilience and analytical clarity in high-pressure scenarios, setting the standard for transparent communication and directing risk-based decisions across the team during active security incidents or compressed financial product launch windows.

  • Balances technical risk reduction with business enablement, owning security infrastructure as a competitive advantage that unblocks global revenue and enterprise-client acquisition across the wider business.
     

Additional Information

What We Offer:

  • Competitive compensation
  • Employee Stock Purchase Plan (ESPP)
  • Competitive time off, including Digital Disconnect and FlyBetter Days to volunteer in a cause you believe in.
  • Flying Start - Our immersive Global Induction Program (Meet our Execs & Global Teams)
  • Work with brilliant people globally  Learn more about their journeys by checking out #InsideFlywire on social media
  • Wellbeing Programs (Mental Health, Wellness, Yoga/Pilates/HIIT Classes) with Global FlyMates 
  • Be a meaningful part in our success - every FlyMate makes an impact
  • Great Talent & Development Programs (Managers Taking Flight – for new or aspiring managers, OneFlywire Career Mobility)

Submit today and get started!

We are excited to get to know you! Throughout our process you can expect to meet with different FlyMates including the Hiring Manager, Peers on the team, the VP of the department, and a skills assessment. Your Talent Acquisition Partner will walk you through the steps and be your “go-to” person for any questions.

 

Similar Jobs at Flywire

Yesterday
Hybrid
Senior level
Senior level
Fintech • Payments • Software
Designs and implements defensive security controls across cloud infrastructure, CI/CD pipelines, applications, and AI workflows. Responsibilities include secure SDLC automation, cloud and Kubernetes hardening, IAM and Zero Trust architecture, code and API reviews, LLM security controls, vulnerability analysis, and security guidance for engineering and SRE teams. The role also mentors junior staff and aligns technical controls with PCI-DSS, SOC, and DORA requirements.
Top Skills: AWSDockerDoraGitlab Ci/CdJavaKubernetesLlm ApisNode.jsOauth2OidcOwasp Top 10 For LlmsPci-DssPythonRuby On RailsSAMLSoc 1Soc 2TerraformZero Trust Iam
Yesterday
Hybrid
Senior level
Senior level
Fintech • Payments • Software
Leads offensive security, penetration testing, red teaming, threat detection engineering, incident response, digital forensics, and containment across global payment platforms. Performs manual source code, API, cloud, and AI security testing; builds SIEM detections aligned with MITRE ATT&CK; leads root-cause analysis; mentors junior engineers; and advises stakeholders on exploit chains, incident findings, and risk reduction.
Top Skills: APIsCloud SecurityDoraEdrMitre Att&CkOwasp Top 10 For LlmsPcapPci-Dss 4.0PythonSIEMSoc 1Soc 2Web Applications
Yesterday
Hybrid
Junior
Junior
Fintech • Payments • Software
Supports application and cloud security engineering across secure SDLC automation, GitLab CI/CD pipelines, infrastructure hardening, and cloud IAM. Performs security scans, code and API reviews, container security activities, and AI security assessments involving LLM risks. Collaborates with SRE, DevOps, and software teams while developing automation skills and progressing toward independent AppSec and CloudSec ownership.
Top Skills: AWSDockerGitlab Ci/CdJavaKubernetesLlm ApisNode.jsPythonTerraform

What you need to know about the Kolkata Tech Scene

When considering the industries shaping India's tech scene, gaming might not immediately come to mind. However, in the last decade, increased internet usage and greater access to mobile devices have catapulted the industry to new heights, with Kolkata-based companies like Virtualinfocom, Red Apple Technologies and Digitoonz, at the forefront, driving the design and animation of new gaming titles for players.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account