> Markdown version of [/jobs/ext/1304838-security-engineer-ii](https://www.wearedevelopers.com/jobs/ext/1304838-security-engineer-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer II - **Company:** Flywire Advantage - **Location:** Valencia, Spain - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Artificial Intelligence, Software System Penetration Testing, User Authentication, Web Development, Python (Programming Language), Node.Js, OAuth, Open Web Application Security, PCI Data Security Standards, Systems Development Life Cycle, Ruby on Rails, Security Assertion Markup Language (SAML), Information Technology Security Auditing, Single Sign-On, Software Engineering, Web Applications, Large Language Models, Software Security, Devsecops, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** July 17, 2026 - **Apply:** https://www.adzuna.es/contact-us.html ## About the Role + 4+ years in Application Security (AppSec). + Proven experience performing web application penetration tests and vulnerability research. + Strong skills in source code auditing and development of custom security tools. The Tech Stack & Knowledge + Languages: Proficiency in Ruby on Rails, Java, and modern web dev (JavaScript, Python, Node.js). + The "Breaker" Mindset: Ability to think like an attacker to identify flaws while effectively crafting mitigating controls. + Modern Standards: Deep understanding of OWASP Top 10 and the OWASP Top 10 for LLM Applications (AI-driven security). + Authentication: Working experience with OAuth, SAML, and SSO. + DevSecOps: Experience with SAST/DAST/SCA tools and integrating them into CI/CD pipelines. + Compliance: Knowledge of security audit certifications such as PCI-DSS, SOC 1, and SOC 2. Soft Skills + Master Communicator: Ability to explain complex technical findings to both technical and non-technical audiences with empathy and clarity. ## Description The Opportunity Flywire is seeking an eager and skillful Application Security Engineer to join our elite Security Team. You will support our security efforts across our global development houses, ensuring the privacy and safety of our most confidential business and personal information. At Flywire, we don't just "check for bugs"-we build security into the heart of our products. If you have a "breaker" mentality and a passion for secure architecture, this journey is for you! Your Impact & Key Responsibilities Your mission is to ensure security is never an afterthought. You will be an active player in every aspect of the development lifecycle: 1. Security by Design & Architecture + Define the Standard: Draft comprehensive security requirements for every new system, service, or integration needed by Flywire. + Lead the Blueprint: Own the threat modeling and secure architecture initiatives to prevent vulnerabilities at the design stage. + Technical Leadership: Perform lead tasks, providing guidance to other team members and setting technical standards. 2. Engineering Partnership & Collaboration + Embed with Teams: Attend engineering syncs and collaborate frequently with different squads to identify and address security issues in real-time. + Full-Stack Reviews: Perform deep-dive security reviews, from meticulous source code auditing to dynamic testing of live applications. + Review & Integrate: Execute technical tasks on change and integration reviews to ensure "security-first" deployments. 3. S-SDLC Mastery + End-to-End Ownership: Be an active part of the secure software development lifecycle (S-SDLC). + Hands-on Remediation: Don't just find flaws-provide expert guidance to developers on how to mitigate and fix them effectively. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)