Lead Security Engineer – AppSec / CloudSec & PenTest / SecOps

flywire1· Security
Apply Now ↗
📍 Boston, MA, United StatesFull time💰 USD 150K–180K

About this role

Company Description

Are you ready to trade your job for a journey? Become a FlyMate!

Passion, excitement & global collaboration are all core to what it means to be a FlyMate. At Flywire, we’re on a mission to deliver the world’s most important and complex payments. We use our Flywire Advantage - the combination of our next-gen payments platform, proprietary payment network and vertical specific software, to help our clients get paid, and help their customers pay with ease - no matter where they are in the world.

What more do we need to truly be unstoppable? Perhaps, that is you! 

Who we are: 
Flywire is a global payments enablement and software company, founded more than a decade ago to solve high-stakes, high-value payments in higher education. We’ve since scaled into new regions and industry verticals and expanded our product offerings to deliver meaningful value to our clients around the world. 

Today we support more than 5,300 clients across the global education, healthcare, travel & B2B industries, with diverse payment methods across 240 countries & territories and more than 140 currencies.

With over 1,400 global FlyMates, representing more than 40 nationalities, and in 15 offices world-wide, we’re looking for FlyMates to join the next stage of our journey as we continue to grow.
 

Job Description

Role Focus

This is a blended role spanning both the Defensive Platform Builder (AppSec & CloudSec) and Active Operational Defender (PenTest & SecOps) disciplines. You will set the technical direction across both areas, with the opportunity for the scope to adapt based on organizational priorities.

Job Summary

As Lead Security Engineer, you will set the technical direction for security engineering across both defensive and offensive disciplines, acting as the senior technical authority for the wider team. You will combine deep hands-on credibility with the ability to prioritize, resource, and represent the security engineering roadmap to Cyber leadership and the broader business, while directly mentoring senior and junior engineers across the function.

Key Responsibilities & Tasks (by Priority)

  1. Technical Strategy & Roadmap

    • Define and own the technical strategy across secure software design, cloud infrastructure defense, offensive testing, and incident detection, aligning priorities with Cyber leadership's wider goals.

    • Represent the security engineering function in cross-functional and executive forums, translating technical risk into clear business impact for non-technical stakeholders.

  2. Secure Engineering & Cloud Defense

    • Direct the integration of automated security controls into engineering pipelines and cloud infrastructure, setting the standard that senior and junior engineers build against.

    • Own escalation and final sign-off on complex cloud architecture, Identity and Access Management (IAM), and Zero Trust design decisions.

  3. Offensive Assurance & Incident Leadership

    • Set the standard and cadence for penetration testing, red team simulations, and detection engineering across the enterprise estate.

    • Act as the senior technical escalation point during critical security incidents, directing containment and post-incident review efforts.

  4. Team Leadership & Mentorship

    • Mentor senior and junior security engineers across both tracks, shaping career development and technical growth within the team.

    • Partner with Talent Acquisition and Cyber leadership on hiring, structuring the security engineering career ladder, and making key resourcing decisions.

Qualifications

Minimum Requirements (Education & Experience)

  • Education: Bachelor's degree in Computer Science, Cyber Security, Software Engineering, or a related technical discipline required. Master's degree preferred.

  • Core Experience: 8+ years of progressive security engineering experience, demonstrating deep expertise in either the defensive or offensive discipline alongside strong working fluency across both.

Technical Expertise & Core Competencies

  • Cross-Discipline Credibility: Deep hands-on seniority in application security, cloud architecture defense, penetration testing, or security operations, with the breadth to speak authoritatively across the entire function.

  • Cloud, DevOps & Tooling Stack: Deep practical knowledge spanning public cloud topologies (AWS/Azure/GCP), containerization/orchestration, CI/CD pipelines (GitLab CI), manual penetration testing, and forensic analysis tools.

  • AI Security & Cryptography: Expert-level understanding of the OWASP Top 10 for LLMs, applied cryptography, and federated authentication architectures.

  • Regulatory Compliance: Practical experience aligning security controls with PCI-DSS v4.0, SOC 1, SOC 2, and DORA standards.

  • Leadership Track Record: Proven background mentoring engineers, shaping technical roadmaps, and influencing hiring and resourcing decisions.

Preferred Certifications 

  • Cloud & Architecture: AWS Certified Security – Specialty, CKS (Certified Kubernetes Security Specialist), or CISSP.

  • Offensive & Red Team: OSCP, OSCE, or SANS GXPN.

  • Incident Response & Defense: GCIH or GCFA.

  • Modern AI Security: OffSec OSAI (Offensive Security AI Red Teamer).

Soft Skills & Core Mindset

  • Dual Builder/Breaker Mindset: Transitions seamlessly between establishing defensive architecture standards and directing offensive assurance operations.

  • Executive Influence: Leads with influence, skillfully prioritizing competing business priorities and presenting high-impact risks to executive leadership.

  • Crisis Management & Mentorship: Displays calm, analytical decision-making under intense pressure, leveraging crisis scenarios to coach and guide engineers.

  • Commercial Drive: Balances technical risk reduction with enterprise enablement, positioning security as a revenue driver and business differentiator.

Additional Information

Submit today and get started!

We are excited to get to know you! Throughout our process you can expect to meet different FlyMates including the Hiring Manager and other Flymates. Your Talent Acquisition Partner will walk you through the steps and be your “go-to” person for questions.

Flywire is an equal opportunity employer and follows a policy of administering all employment decisions and personnel actions without regard to race, color, religion, sex, pregnancy, gender identity, national origin, age, ancestry, physical or mental disability, sexual orientation, genetic disposition or carrier status, veteran status, or any other category protected under applicable national, federal, state or local law.

The US base salary range for this full-time position is $150,000 - 180,000 and benefits. Our salary ranges are determined by role, position level, and location. The range displayed on this job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. Within the range, individual pay is determined by work location and several other factors, including job-related skills, experience, relevant education and training. 

#LI-Hybrid

Frequently Asked Questions

What is the salary for the Lead Security Engineer – AppSec / CloudSec & PenTest / SecOps role at flywire1?
The listed salary for this Lead Security Engineer – AppSec / CloudSec & PenTest / SecOps position at flywire1 is USD 150K–180K. This is an Full time role.
Where is the Lead Security Engineer – AppSec / CloudSec & PenTest / SecOps position at flywire1 located?
This Lead Security Engineer – AppSec / CloudSec & PenTest / SecOps role at flywire1 is based in Boston, MA, United States. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Lead Security Engineer – AppSec / CloudSec & PenTest / SecOps role at flywire1 full-time or part-time?
This is listed as a Full time position. It is posted as a Lead Security Engineer – AppSec / CloudSec & PenTest / SecOps role in the Security department at flywire1.
Which team or department does the Lead Security Engineer – AppSec / CloudSec & PenTest / SecOps at flywire1 belong to?
This Lead Security Engineer – AppSec / CloudSec & PenTest / SecOps position is part of the Security department at flywire1. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Lead Security Engineer – AppSec / CloudSec & PenTest / SecOps position at flywire1?
Click the "Apply Now" button on this page. You will be redirected to flywire1's official application portal hosted on smartrecruiters where you can submit your application directly.
When was the Lead Security Engineer – AppSec / CloudSec & PenTest / SecOps job at flywire1 posted?
This Lead Security Engineer – AppSec / CloudSec & PenTest / SecOps position at flywire1 was posted on Sep 8, 2026. Apply as soon as possible — early applications are often reviewed first.
Lead Security Engineer – AppSec / CloudSec & PenTest / SecOps
flywire1 · 💰 USD 150K–180K
Apply for this role ↗

You'll be redirected to flywire1's official application page on SmartRecruiters.