Security Engineer II (Offensive Operations)

Flywire
Boston
Workplace: HybridFull timeUSD 99,000 - 120,000 annuallyFunction: CybersecurityExperience: 2+ yearsEducation: bachelorsSkills: ["Technical reporting","Communication","Analytical thinking","Composure under pressure","Business-minded security"]

Execute manual penetration testing across AWS and multicloud environments, assessing web applications and REST/GraphQL APIs for complex business logic, auth bypasses, and OWASP Top 10 risks. Analyze code and SAST/DAST findings, run purple-team/active adversary simulations, and operate bug bounty programs. Apply MITRE ATT&CK TTPs, refine SIEM detection with the blue team, and deliver remediation guidance to Engineering, SRE, and IT.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Flywire
Flywire
19 hours ago

Security Engineer II (Offensive Operations)

âś“ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 3 hours agoStatus: Live

Job Summary

Execute manual penetration testing across AWS and multicloud environments, assessing web applications and REST/GraphQL APIs for complex business logic, auth bypasses, and OWASP Top 10 risks. Analyze code and SAST/DAST findings, run purple-team/active adversary simulations, and operate bug bounty programs. Apply MITRE ATT&CK TTPs, refine SIEM detection with the blue team, and deliver remediation guidance to Engineering, SRE, and IT.
Location: Boston
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Entry level

Key Responsibilities

  • •Execute manual internal and external penetration testing across AWS/multicloud environments to identify vulnerabilities, misconfigurations, and privilege escalation paths.
  • •Perform deep-dive testing of web applications and REST/GraphQL APIs, targeting business logic flaws, auth bypasses, and OWASP Top 10 risks.
  • •Review SAST/DAST findings and conduct targeted code audits (Python, Java, Ruby) to eliminate false positives and prioritize high-risk fixes.
  • •Partner with the blue team during purple-team exercises to validate security controls and refine SIEM detection rules and real-time alerting.
  • •Manage bug bounty programs by triaging submissions, validating severity, and coordinating prompt engineering fixes.

Pay and Benefits

Salary: USD 99,000 - 120,000 annually

Key Requirements

  • •Bachelor of Science and at least 2+ years’ experience in IT security and penetration testing.
  • •Demonstrated track record executing network, web application, and API penetration tests.
  • •Proficiency with Kali Linux and active involvement on bug bounty platforms.
  • •Experience with SAST/DAST tools, secure code reviews, and scripting knowledge in Python, Java, or Ruby.
  • •Understanding of AWS Cloud infrastructure, Agile environments, CI/CD pipelines, and Infrastructure as Code (IaC).
Experience:2+ yearsIT securityPenetration testingBug bounty
Education:Bachelor's
Skills:Technical reportingCommunicationAnalytical thinkingComposure under pressureBusiness-minded security
Certifications:OSCPOSCESANS GXPNOffSec OSAI
Languages:English
Tech Stack:AWSMulticloudKali LinuxSASTDASTPythonJavaRubyWeb application testingRESTGraphQLSIEMMITRE ATT&CKCI/CDInfrastructure as Code (IaC)OWASPAgileBug bountyScripting

Company Brief

Flywire
Provides a global payments platform and vertical-specific software to enable complex cross-border and domestic receivables for education, healthcare, travel and B2B clients, streamlining payments, reconciliation and receivables workflows.
Industry: Payments
Company Size: Enterprise (1,001+ employees)
Revenue: USD 100M to 250M
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Boston, United States
Founded: 2009
Glassdoor
Glassdoor: 3.5
WebsiteLinkedInGlassdoor