> Markdown version of [/jobs/ext/2805192-lead-security-engineer-appsec-cloudsec-pentest-secops](https://www.wearedevelopers.com/jobs/ext/2805192-lead-security-engineer-appsec-cloudsec-pentest-secops). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Engineer - AppSec / CloudSec & PenTest / SecOps - **Company:** Flywire - **Location:** Boston, MA, United States - **Experience:** Expert - **Salary:** $150,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Cloud Computing, Cloud Engineering, Cyber Security, DevOps, Identity and Access Management, Intrusion Detection and Prevention, Open Web Application Security, PCI Data Security Standards, Red Team (Cyber Security), Zero Trust Network Access, Software Engineering, Large Language Models, Software Security, Gitlab-ci - **Published:** September 9, 2026 - **Apply:** https://jobs.smartrecruiters.com/Flywire1/744000148227869-lead-security-engineer-appsec-cloudsec-pentest-secops ## About the Role * Education: Bachelor's degree in Computer Science, Cyber Security, Software Engineering, or a related technical discipline required. Master's degree preferred. * Core Experience: 8+ years of progressive security engineering experience, demonstrating deep expertise in either the defensive or offensive discipline alongside strong working fluency across both. Technical Expertise & Core Competencies * Cross-Discipline Credibility: Deep hands-on seniority in application security, cloud architecture defense, penetration testing, or security operations, with the breadth to speak authoritatively across the entire function. * Cloud, DevOps & Tooling Stack: Deep practical knowledge spanning public cloud topologies (AWS/Azure/GCP), containerization/orchestration, CI/CD pipelines (GitLab CI), manual penetration testing, and forensic analysis tools. * AI Security & Cryptography: Expert-level understanding of the OWASP Top 10 for LLMs, applied cryptography, and federated authentication architectures. * Regulatory Compliance: Practical experience aligning security controls with PCI-DSS v4.0, SOC 1, SOC 2, and DORA standards. * Leadership Track Record: Proven background mentoring engineers, shaping technical roadmaps, and influencing hiring and resourcing decisions. Preferred Certifications * Cloud & Architecture: AWS Certified Security - Specialty, CKS (Certified Kubernetes Security Specialist), or CISSP. * Offensive & Red Team: OSCP, OSCE, or SANS GXPN. * Incident Response & Defense: GCIH or GCFA. * Modern AI Security: OffSec OSAI (Offensive Security AI Red Teamer). Soft Skills & Core Mindset * Dual Builder/Breaker Mindset: Transitions seamlessly between establishing defensive architecture standards and directing offensive assurance operations. * Executive Influence: Leads with influence, skillfully prioritizing competing business priorities and presenting high-impact risks to executive leadership. * Crisis Management & Mentorship: Displays calm, analytical decision-making under intense pressure, leveraging crisis scenarios to coach and guide engineers. * Commercial Drive: Balances technical risk reduction with enterprise enablement, positioning security as a revenue driver and business differentiator. ## Description This is a blended role spanning both the Defensive Platform Builder (AppSec & CloudSec) and Active Operational Defender (PenTest & SecOps) disciplines. You will set the technical direction across both areas, with the opportunity for the scope to adapt based on organizational priorities., As Lead Security Engineer, you will set the technical direction for security engineering across both defensive and offensive disciplines, acting as the senior technical authority for the wider team. You will combine deep hands-on credibility with the ability to prioritize, resource, and represent the security engineering roadmap to Cyber leadership and the broader business, while directly mentoring senior and junior engineers across the function., 1. Technical Strategy & Roadmap + Define and own the technical strategy across secure software design, cloud infrastructure defense, offensive testing, and incident detection, aligning priorities with Cyber leadership's wider goals. + Represent the security engineering function in cross-functional and executive forums, translating technical risk into clear business impact for non-technical stakeholders. 2. Secure Engineering & Cloud Defense + Direct the integration of automated security controls into engineering pipelines and cloud infrastructure, setting the standard that senior and junior engineers build against. + Own escalation and final sign-off on complex cloud architecture, Identity and Access Management (IAM), and Zero Trust design decisions. 3. Offensive Assurance & Incident Leadership + Set the standard and cadence for penetration testing, red team simulations, and detection engineering across the enterprise estate. + Act as the senior technical escalation point during critical security incidents, directing containment and post-incident review efforts. 4. Team Leadership & Mentorship + Mentor senior and junior security engineers across both tracks, shaping career development and technical growth within the team. + Partner with Talent Acquisition and Cyber leadership on hiring, structuring the security engineering career ladder, and making key resourcing decisions. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)