Flywire Logo

Flywire

Security Engineer II (Defensive)

Posted Yesterday
Be an Early Applicant
Hybrid
Bengaluru, Bengaluru Urban, Karnataka
Junior
Hybrid
Bengaluru, Bengaluru Urban, Karnataka
Junior
Supports application and cloud security engineering across secure SDLC automation, GitLab CI/CD pipelines, infrastructure hardening, and cloud IAM. Performs security scans, code and API reviews, container security activities, and AI security assessments involving LLM risks. Collaborates with SRE, DevOps, and software teams while developing automation skills and progressing toward independent AppSec and CloudSec ownership.
The summary above was generated by AI
Company Description

Are you ready to trade your job for a journey? Become a FlyMate!

Passion, excitement & global collaboration are all core to what it means to be a FlyMate. At Flywire, we’re on a mission to deliver the world’s most important and complex payments. We use our Flywire Advantage - the combination of our next-gen payments platform, proprietary payment network and vertical specific software, to help our clients get paid, and help their customers pay with ease - no matter where they are in the world.

What more do we need to truly be unstoppable? Perhaps, that is you! 

Who we are: 

Flywire is a global payments enablement and software company, founded more than a decade ago to solve high-stakes, high-value payments. We’ve scaled into new regions and industry verticals and expanded our product offerings to deliver meaningful value to our clients around the world. 

Today we support more than 5,300 clients across the global education, healthcare, travel & B2B industries, with diverse payment methods across 240 countries & territories and more than 140 currencies.

With over 1,400+ global FlyMates, representing more than 40 nationalities, and in 15 offices world-wide, we’re looking for FlyMates to join the next stage of our journey as we continue to grow.

 

Job Description

Job Summary: 

As a Security Engineer II on the Defensive Platform Builder track you will build hands on experience across secure software design and cloud native infrastructure defence, working under the direction of senior and lead engineers. You will develop an automation first mindset within a high velocity fintech environment, supporting the integration of security controls into our public cloud and GitLab CI/CD pipelines while building towards independent ownership of AppSec and CloudSec work.

Responsibilities and Tasks (in order of priority)

1. Secure SDLC & CI/CD Automation

  • Support the integration of automated security requirements and validation tooling into engineering pipelines under the direction of senior team members.

  • Help build and maintain internal tooling and automated controls that reduce reliance on manual security checkpoints.

2. Cloud & Infrastructure Hardening

  • Work alongside SRE and DevOps teams on secure public cloud architecture, running Infrastructure as Code security scans (for example Terraform) and supporting network isolation controls.

  • Contribute to cloud Identity and Access Management reviews and help maintain Zero Trust boundaries within containerised environments such as Docker and Kubernetes.

3. AI Driven Security & Application Reviews

  • Assist in configuring and running automated security review workflows that use LLM APIs for pull request analysis.

  • Learn and apply technical controls that protect generative AI features against LLM specific risks such as prompt injection and insecure output handling.

  • Support source code audits and API security reviews, building towards independent ownership of more complex assessments over time.

4. Cross Functional Collaboration & Development

  • Take part in software development and infrastructure sprint planning to build a practical understanding of how security fits into the wider engineering lifecycle.

  • Provide clear, actionable feedback on code and configuration issues under the guidance of senior and lead engineers.

  • Actively seek mentorship from senior and lead security engineers to develop breadth across the wider security function.

 

Qualifications

  • Education: Bachelor's degree in Computer Science, Cyber Security, Software Engineering or a related technical discipline, or equivalent practical experience.
  • Core Experience:  indicative range [1 to 3 years] of hands on experience in application or cloud security, software engineering or a closely related technical role.

  • Foundational Depth: exposure to manual code review, dependency or container scanning and cloud security concepts, gained through work experience, personal projects or study.

  • Cloud & DevOps Familiarity: working knowledge of a public cloud platform such as AWS, plus basic familiarity with containerisation (Docker) and CI/CD pipelines.

  • Technical Language Foundation: comfort reading and writing code in at least one modern language such as Python, Java or Node.js.

  • AI Security Awareness: a working interest in the OWASP Top 10 for LLMs and how AI features introduce new categories of risk.

  • Regulatory Awareness: a general understanding of standards such as PCI-DSS, SOC 2 or DORA, with willingness to build practical depth on the job.

Highly Preferred Certifications

  • Cloud & Architecture: AWS Certified Security - Specialty, Certified Kubernetes Security Specialist (CKS) or CISSP.

  • Modern AI Security: OffSec OSAI (Offensive Security AI Red Teamer).

  • Broader Depth: OSCP or GCIH, where candidates bring exposure to offensive or incident response work as a secondary strength.

Skills and Abilities

  • Balances a builder's engineering empathy with a security first mindset, treating software, SRE and product teams as operational allies rather than a source of friction.

  • Communicates clearly under pressure, able to distill cloud configuration drift or a live vulnerability into a plain, high impact risk summary for non-technical stakeholders.

  • Shows creative, novel problem solving across complex, non-standard application and cloud infrastructure challenges within a distributed financial microservices environment.

  • Resilience and analytical clarity in high-pressure scenarios, supporting transparent communication and contributing to risk-based decisions during active security incidents or compressed financial product launch windows.

  • Balances technical risk reduction with business enablement, supporting security infrastructure that serves as a competitive advantage and helps unblock global revenue and enterprise-client acquisition.
     

Additional Information

What We Offer:

  • Competitive compensation
  • Employee Stock Purchase Plan (ESPP)
  • Competitive time off, including Digital Disconnect and FlyBetter Days to volunteer in a cause you believe in.
  • Flying Start - Our immersive Global Induction Program (Meet our Execs & Global Teams)
  • Work with brilliant people globally  Learn more about their journeys by checking out #InsideFlywire on social media
  • Wellbeing Programs (Mental Health, Wellness, Yoga/Pilates/HIIT Classes) with Global FlyMates 
  • Be a meaningful part in our success - every FlyMate makes an impact
  • Great Talent & Development Programs (Managers Taking Flight – for new or aspiring managers, OneFlywire Career Mobility)

Submit today and get started!

We are excited to get to know you! Throughout our process you can expect to meet with different FlyMates including the Hiring Manager, Peers on the team, the VP of the department, and a skills assessment. Your Talent Acquisition Partner will walk you through the steps and be your “go-to” person for any questions.

#Li-Hybrid

Similar Jobs at Flywire

An Hour Ago
Hybrid
Senior level
Senior level
Fintech • Payments • Software
Leads security engineering strategy across application security, cloud security, penetration testing, red teaming, and security operations. Establishes secure engineering and cloud defense standards, oversees IAM and Zero Trust architecture, directs offensive testing and incident response, and mentors security engineers. Represents security priorities to executives, aligns controls with regulatory frameworks, and supports hiring, career development, roadmap planning, and resource allocation.
Top Skills: Applied CryptographyAWSCloud InfrastructureContainerizationDoraFederated AuthenticationForensic ToolingGitlab CiIdentity And Access ManagementIncident DetectionOrchestrationOwasp Top 10 For LlmsPci-Dss 4.0Penetration TestingRed TeamingSecurity OperationsSoc 1Soc 2Zero Trust
Yesterday
Hybrid
Senior level
Senior level
Fintech • Payments • Software
Designs and implements defensive security controls across cloud infrastructure, CI/CD pipelines, applications, and AI workflows. Responsibilities include secure SDLC automation, cloud and Kubernetes hardening, IAM and Zero Trust architecture, code and API reviews, LLM security controls, vulnerability analysis, and security guidance for engineering and SRE teams. The role also mentors junior staff and aligns technical controls with PCI-DSS, SOC, and DORA requirements.
Top Skills: AWSDockerDoraGitlab Ci/CdJavaKubernetesLlm ApisNode.jsOauth2OidcOwasp Top 10 For LlmsPci-DssPythonRuby On RailsSAMLSoc 1Soc 2TerraformZero Trust Iam
Yesterday
Hybrid
Senior level
Senior level
Fintech • Payments • Software
Leads offensive security, penetration testing, red teaming, threat detection engineering, incident response, digital forensics, and containment across global payment platforms. Performs manual source code, API, cloud, and AI security testing; builds SIEM detections aligned with MITRE ATT&CK; leads root-cause analysis; mentors junior engineers; and advises stakeholders on exploit chains, incident findings, and risk reduction.
Top Skills: APIsCloud SecurityDoraEdrMitre Att&CkOwasp Top 10 For LlmsPcapPci-Dss 4.0PythonSIEMSoc 1Soc 2Web Applications

What you need to know about the Kolkata Tech Scene

When considering the industries shaping India's tech scene, gaming might not immediately come to mind. However, in the last decade, increased internet usage and greater access to mobile devices have catapulted the industry to new heights, with Kolkata-based companies like Virtualinfocom, Red Apple Technologies and Digitoonz, at the forefront, driving the design and animation of new gaming titles for players.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account