> Markdown version of [/jobs/ext/3448657-security-engineer-ii-defensive-operations](https://www.wearedevelopers.com/jobs/ext/3448657-security-engineer-ii-defensive-operations). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer II (Defensive Operations) - **Company:** Flywire - **Location:** Boston, United States - **Experience:** Experienced - **Salary:** $99,000.0 - $120,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Continuous Integration, DevOps, Identity and Access Management, Intrusion Detection and Prevention, Network Packet, Python (Programming Language), Network Security, Pcap, Node.Js, OAuth, OpenID, Open Web Application Security, PCI Data Security Standards, Scrum Methodology, Systems Development Life Cycle, Ruby on Rails, E2e Testing, Software Tools, Red Team (Cyber Security), Zero Trust Network Access, Security Assertion Markup Language (SAML), Security Information and Event Management, Software Engineering, Web Applications, Large Language Models, Software Security, Mitre Att&ck, Containerization, Gitlab-ci, Kubernetes, Infrastructure Automation Frameworks, Information Technology, Terraform, Automation Anywhere, Blue Team (Cyber Security), Docker, Vulnerability Analysis, Programming Languages - **Published:** September 21, 2026 - **Apply:** https://startup.jobs/security-engineer-ii-defensive-operations-flywire-10151559 ## About the Role * Education: Bachelor's degree in Computer Science, Cyber Security, Software Engineering, or a related technical discipline (or equivalent experience). * Experience: 3+ years of progressive engineering experience moving fluidly between Application Security, Cloud Architecture Defense, and Active Security Operations (SecOps/Incident Response/Penetration Testing). * Advanced Exploitation & Defense: Proven track record of independently performing deep manual penetration testing, web application exploitation, and incident containment without relying solely on commercial automated scanners. * Cloud & DevOps Stack: Strong practical knowledge of AWS or public cloud topologies, containerization (Docker, Kubernetes), network security, and building/maintaining GitLab CI pipelines. * Programming Languages: Foundational proficiency with modern web development frameworks and programming languages including Python, Ruby on Rails, Java, or Node.js. * AI & Security Domains: Solid understanding of the OWASP Top 10 for LLMs framework, applied cryptography, cloud network isolation, and federated authentication architectures (OAuth2, SAML, OIDC, Zero Trust IAM). * SecOps & Forensics: Working proficiency with modern EDR platforms, SIEM systems, network packet analysis (PCAP), threat intelligence frameworks (MITRE ATT&CK), and forensic collection tools. * Compliance: Practical experience aligning technical software and infrastructure controls with standards like PCI-DSS (v4.0), SOC 1, SOC 2, or DORA. Preferred Qualifications / Certifications: * Offensive/Red Team: OSCP, OSCE, or SANS GXPN. * Cloud & Architecture: AWS Certified Security - Specialty, CKS (Certified Kubernetes Security Specialist), or CISSP. * Incident Response: GCIH, GCFA, or specialized Blue Team certifications. * AI Security: OffSec OSAI. ## Description This role demands an "automation-first" approach embedded within a high-velocity fintech ecosystem. You will actively partner with software engineering and SRE squads to integrate security controls directly into our public cloud and GitLab CI/CD pipelines using AI workflows. Simultaneously, you will serve as an operational responder for threat detection engineering, red team penetration testing, and live incident containment., * Secure SDLC & CI/CD Automation: Own, design, and drive the end-to-end integration of automated technical security requirements and validation tools into high-velocity engineering pipelines. Build custom internal tooling, wrappers, and automated controls to maximize development velocity without friction. * SRE & Cloud Infrastructure Hardening: Partner directly with SRE and DevOps teams to establish secure cloud architecture blueprints, manage Infrastructure-as-Code (IaC) security scans (Terraform), and enforce Zero Trust boundaries in containerized environments (Docker/Kubernetes). * AI-Driven Security & Governance: Design and deploy automated security review workflows using LLM APIs (e.g., Claude). Establish controls to protect generative AI features against prompt injection, insecure output handling, model inversion, and data poisoning. * Offensive Penetration Testing & Red Teaming: Adopt an attacker's mindset to discover logic flaws, perform exploit research, and emulate zero-day adversarial behavior across financial platforms through manual source code audits, API exploitation, and cloud penetration testing. * Incident Response & Threat Detection: Lead technical containment, forensic collection, and rapid threat eradication during active security incidents. Design and deploy high-fidelity detection rules and automated alert workflows within the SIEM environment. * Cross-Functional Collaboration & Mentorship: Embed within software development and infrastructure sprint planning from inception to ensure security is built-in from day one. Provide actionable code modifications and mentor junior engineers. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)