Startups · AI

Security Engineer II (Offensive Operations)

FlyWire · Boston, MA · On-site

← All jobs
About FlyWire

Are you ready to trade your job for a journey? Become a FlyMate! Passion, excitement & global collaboration are all core to what it means to be a FlyMate. At Flywire, we’re on a mission to deliver the world’s most important and complex payments. Backed by Techstars.

About the role

Cloud Infrastructure PenTesting: Execute manual internal and external penetration testing across AWS/multicloud environments to identify vulnerabilities, misconfigurations, and privilege escalation paths. Web Application & API Assessment: Perform deep-dive testing on web applications and REST/GraphQL APIs, targeting complex business logic flaws, auth bypasses, and OWASP Top 10 risks.

What they're looking for

  • Education & Experience: Bachelor of Science and at least 2+ years’ experience in IT security and Penetration Testing
  • Hands-on PenTesting: Demonstrated track record executing network, web application, and API penetration tests
  • Offensive Toolset: Proficiency with Kali Linux, commercial/open-source penetration tools, and active involvement on bug bounty platforms
  • Code & Automation: Experience with SAST/DAST tools, secure code reviews, and scripting knowledge in Python, Java, or Ruby
  • Modern Stack Exposure: Understanding of AWS Cloud infrastructure, Agile environments, CI/CD pipelines, and Infrastructure as Code (IaC)
  • Security Frameworks: Strong knowledge of OWASP methodologies, threat vectors (malware, intrusion, DoS), and platform security strategies
More about this role

Do you spend your free time figuring out how systems break? Are you driven by the thrill of discovering complex vulnerabilities before malicious actors do? If you’re a natural tinkerer who loves attacking systems to make them unshakeable, this role is built for you.

As a Security Engineer II on our Active Operational Offensive track , you’ll sit at the heart of Flywire’s security defenses under the guidance of senior engineers. You will bridge manual penetration testing with active security operations, building the technical depth needed to lead independent engagements over time.

Cloud Infrastructure PenTesting: Execute manual internal and external penetration testing across AWS/multicloud environments to identify vulnerabilities, misconfigurations, and privilege escalation paths.

Web Application & API Assessment: Perform deep-dive testing on web applications and REST/GraphQL APIs, targeting complex business logic flaws, auth bypasses, and OWASP Top 10 risks.

Source Code & Vulnerability Analysis: Review SAST/DAST findings and conduct targeted code audits (Python, Java, Ruby) to eliminate false positives and prioritize high-risk fixes.

Purple Team Operations: Partner with the Blue...

Read the full posting on FlyWire's site ↗

Security

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.