Valencia, Valencia, Spain Hybrid

Flywire is hiring a Security Engineer II

About the Role

Flywire is seeking a Security Engineer II to join our Security Team. You will be responsible for ensuring security is built into our products from the ground up, supporting global development houses, and protecting confidential business and personal information.

What You'll Do

  • Define comprehensive security requirements for every new system, service, or integration.
  • Own threat modeling and secure architecture initiatives to prevent vulnerabilities at the design stage.
  • Perform lead tasks, providing guidance to other team members and setting technical standards.
  • Attend engineering syncs and collaborate with different squads to identify and address security issues in real-time.
  • Perform deep-dive security reviews, from source code auditing to dynamic testing of live applications.
  • Execute technical tasks on change and integration reviews to ensure 'security-first' deployments.
  • Be an active part of the secure software development lifecycle (S-SDLC).
  • Provide expert guidance to developers on how to mitigate and fix security flaws.

What We're Looking For

  • 4+ years in Application Security (AppSec).
  • Proven experience performing web application penetration tests and vulnerability research.
  • Strong skills in source code auditing and development of custom security tools.
  • Proficiency in Ruby on Rails, Python, Bash, Java, Node.js, among others, focusing on identifying vulnerabilities at the logic and code level.
  • Ability to think like an attacker to identify flaws while effectively crafting mitigating controls.
  • Deep understanding of OWASP Top 10 and the OWASP Top 10 for LLM Applications (AI-driven security).
  • Working experience with OAuth, SAML, and SSO.
  • Experience with SAST/DAST/SCA tools and integrating them into CI/CD pipelines.
  • Knowledge of security audit certifications such as PCI-DSS, SOC 1, and SOC 2.
  • Ability to explain complex technical findings to both technical and non-technical audiences with empathy and clarity.

Technical Stack

  • Languages & Frameworks: Ruby on Rails, Python, Bash, Java, Node.js
  • Security Protocols: OAuth, SAML, SSO
  • Tools: SAST, DAST, SCA tools

Team & Environment

You will be part of the elite Security Team, collaborating with global development houses and different engineering squads.

Benefits & Compensation

  • Competitive compensation
  • Employee Stock Purchase Plan (ESPP)
  • Flying Start - Global Induction Program
  • Dynamic & Global Team
  • Wellbeing Programs (Mental Health, Wellness)
  • Competitive time off including FlyBetter Days to volunteer
  • Digital Disconnect Days
  • Great Talent & Development Programs

Work Mode

This position follows a hybrid work model.

Flywire is an equal opportunity employer.

Required Skills
Ruby on RailsPythonBashJavaNode.jsOAuthSAMLSSOSASTDASTSCAApplication SecurityPenetration TestingVulnerability ResearchSource Code Auditing Ruby on RailsPythonBashJavaNode.jsOAuthSAMLSSOSASTDASTSCAApplication SecurityPenetration TestingVulnerability ResearchSource Code Auditing
Starting a business in Thailand?

Company registration done right

Foreign ownership rules, licenses, tax registration — Thai business setup has many moving parts. SVBL guides you through every step with full legal compliance.

Company registration & structure
Foreign ownership solutions
License & tax registration
BOI promotion eligibility
Start your business
100% foreign ownership possible
About company
Flywire
Flywire is a global payments enablement and software company that digitizes payments for over 3,300+ global clients across education, healthcare, travel & B2B, covering more than 240 countries and territories and supporting over 140 currencies.
All jobs at Flywire Visit website
Job Details
Department Information Technology
Category security
Posted a month ago