
Security Engineer (Offensive Operations)
Flywire · Boston, United States
About The Role
Join Flywire as a Security Engineer II, where you'll be at the forefront of our security defenses. In this role, you'll execute manual penetration testing, assess web applications and APIs, conduct source code analysis, and collaborate with the Blue Team on adversary emulation exercises. You'll also participate in Red Team engagements, manage bug bounty operations, and apply threat intelligence to align testing methodologies with the MITRE ATT&CK framework. This position requires a strong background in IT security and penetration testing, as well as experience with AWS cloud infrastructure and secure coding practices.
- Execute manual internal and external penetration testing across AWS/multicloud environments to identify vulnerabilities, misconfigurations, and privilege escalation paths.
- Perform deep-dive testing on web applications and REST/GraphQL APIs, targeting complex business logic flaws, auth bypasses, and OWASP Top 10 risks.
- Participate in goal-oriented adversarial simulations evaluating Flywire’s physical/digital posture and incident response readiness.
- Do you spend your free time figuring out how systems break? Are you driven by the thrill of discovering complex vulnerabilities before malicious actors do? If you’re a natural tinkerer who loves attacking systems to make them unshakeable, this role is built for you
- Dual Focus: Combines an attacker’s drive to break systems with a defender's discipline to build actionable SIEM detection rules
- High-Impact Communication: Ability to write formal/informal technical reports and translate complex exploit chains to non-technical stakeholders
- Hands-on PenTesting: Demonstrated track record executing network, web application, and API penetration tests
- Code & Automation: Experience with SAST/DAST tools, secure code reviews, and scripting knowledge in Python, Java, or Ruby
- Composure Under Pressure: Analytical and calm during live security breaches or tight release windows
- Education & Experience: Bachelor of Science and at least 2+ years’ experience in IT security and Penetration Testing
- Modern Stack Exposure: Understanding of AWS Cloud infrastructure, Agile environments, CI/CD pipelines, and Infrastructure as Code (IaC)
- Security Frameworks: Strong knowledge of OWASP methodologies, threat vectors (malware, intrusion, DoS), and platform security strategies
- Business-Minded Security: Balances risk mitigation with organizational growth
- Offensive Toolset: Proficiency with Kali Linux, commercial/open-source penetration tools, and active involvement on bug bounty platforms
- Offensive & Red Team: OSCP, OSCE, or SANS GXPN
- AI Security: OffSec OSAI (Offensive Security AI Red Teamer)
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing