Flywire · Posted 7 days ago

Security Engineer II (Offensive)

BengaluruMid

The posting

key requirement, as the employer wrote it

Job Summary: As a Security Engineer II on the Active Operational Defender track you will build hands on experience across penetration testing, threat detection and incident response, working under the direction of senior and lead engineers.

You will support live operational work within a high velocity fintech environment, developing the manual testing and detection engineering skills needed to take on more independent responsibility over time.

Responsibilities and Tasks: 1.

Offensive Penetration Testing & Red Teaming Support penetration testing engagements across financial platforms and product architectures under senior guidance, building practical exploit research experience.

Assist with manual security reviews including source code audits, API testing and cloud configuration checks, working towards independent delivery of smaller engagements.

Contribute to adversarial testing of AI features where in scope, learning to identify prompt injection and related LLM specific weaknesses. 2.

Threat Detection Engineering & SIEM Help design and tune detection rules and alert workflows within the enterprise SIEM, working from senior engineers' guidance and established detection frameworks.

Support SecOps in reviewing detection coverage against current threats, referencing frameworks such as MITRE ATT&CK. 3.

Incident Response & Forensics Act as a first line responder during active security incidents, carrying out evidence collection and initial triage under senior direction.

Support post incident analysis by pulling together logs, timelines and technical findings for senior review. 4.

Cross Functional Collaboration & Development Take part in security operations and engineering planning to build a practical understanding of detection and response capability.

Communicate findings from testing and incidents clearly to immediate team members and stakeholders.

Actively seek mentorship from senior and lead security engineers on offensive tooling, detection engineering and incident response practice.

Education: Bachelor's degree in Computer Science, Cyber Security, Software Engineering or a related technical discipline, or equivalent practical experience.

Core Experience: indicative range [1 to 3 years] of hands on experience in penetration testing, security operations or a closely related technical role.

Foundational Offensive Skills: exposure to manual web application testing, CTF style exploitation or vulnerability research, gained through work experience, personal projects or study.

SecOps & Forensics Familiarity: basic working knowledge of SIEM concepts, EDR tooling or network packet analysis, and an interest in frameworks such as MITRE ATT&CK.

Technical Language Foundation: comfort reading and, ideally, writing scripts in a language such as Python to support testing and automation.

AI Security Awareness: a working interest in the OWASP Top 10 for LLMs and how adversarial testing of AI features differs from traditional application testing.

Regulatory Awareness : a general understanding of standards such as PCI-DSS, SOC 2 or DORA, with willingness to build practical depth on the job.

Highly Preferred Certifications Hands-On Offensive & Red Team: OSCP, OSCE or SANS GXPN (GIAC Exploit Researcher and Advanced Penetration Tester).

Incident Response & Defence: GCIH (GIAC Certified Incident Handler), GCFA (GIAC Certified Forensic Analyst) or a specialised Blue Team certification.

Skills and Abilities Combines an aggressive, attacker's mindset used to find vulnerabilities with the analytical discipline required to write clear, actionable detection rules.

Stays calm and analytically clear under intense pressure during active, live breach events or business critical system failures.

Communicates exploit chains and log anomalies clearly, turning technical detail into a plain, high impact risk profile for non-technical leadership.

Resilience and analytical clarity in high-pressure scenarios, supporting transparent communication and contributing to risk-based decisions during active security incidents or compressed financial product launch windows.

Balances technical risk reduction with business enablement, supporting security infrastructure that serves as a competitive advantage and helps unblock global revenue and enterprise-client acquisition.

Modern AI Security: OffSec OSAI (Offensive Security AI Red Teamer).

Flywire

Open roles in India
3
Hiring in
Bengaluru
Applications through
SmartRecruiters

Counted from the roles we read off Flywire's own hiring page today.

Flywire

fintech company

Founded
2009
Headquarters
Boston
Industry
fintech
Company website

Facts from Wikidata, the open, community-edited database behind Wikipedia — check the link if something looks out of date. Funding rounds, investors and employee ratings are not shown: no free source carries them reliably.

My match scoreApply