Valencia, Valencia, Spain Hybrid Employment

Flywire is hiring a Security Engineer II

About the Role

Flywire is seeking a Security Engineer II to join our Security Team. You will be responsible for ensuring security is built into our products from the ground up, supporting global development houses, and protecting confidential business and personal information.

What You'll Do

  • Define comprehensive security requirements for every new system, service, or integration.
  • Own threat modeling and secure architecture initiatives to prevent vulnerabilities at the design stage.
  • Perform lead tasks, providing guidance to other team members and setting technical standards.
  • Attend engineering syncs and collaborate with different squads to identify and address security issues in real-time.
  • Perform deep-dive security reviews, from source code auditing to dynamic testing of live applications.
  • Execute technical tasks on change and integration reviews to ensure 'security-first' deployments.
  • Be an active part of the secure software development lifecycle (S-SDLC).
  • Provide expert guidance to developers on how to mitigate and fix security flaws.

What We're Looking For

  • 4+ years in Application Security (AppSec).
  • Proven experience performing web application penetration tests and vulnerability research.
  • Strong skills in source code auditing and development of custom security tools.
  • Proficiency in Ruby on Rails, Python, Bash, Java, Node.js, among others, focusing on identifying vulnerabilities at the logic and code level.
  • Ability to think like an attacker to identify flaws while effectively crafting mitigating controls.
  • Deep understanding of OWASP Top 10 and the OWASP Top 10 for LLM Applications (AI-driven security).
  • Working experience with OAuth, SAML, and SSO.
  • Experience with SAST/DAST/SCA tools and integrating them into CI/CD pipelines.
  • Knowledge of security audit certifications such as PCI-DSS, SOC 1, and SOC 2.
  • Ability to explain complex technical findings to both technical and non-technical audiences with empathy and clarity.

Technical Stack

  • Languages & Frameworks: Ruby on Rails, Python, Bash, Java, Node.js
  • Security Protocols: OAuth, SAML, SSO
  • Tools: SAST, DAST, SCA tools

Team & Environment

You will be part of the elite Security Team, collaborating with global development houses and different engineering squads.

Benefits & Compensation

  • Competitive compensation
  • Employee Stock Purchase Plan (ESPP)
  • Flying Start - Global Induction Program
  • Dynamic & Global Team
  • Wellbeing Programs (Mental Health, Wellness)
  • Competitive time off including FlyBetter Days to volunteer
  • Digital Disconnect Days
  • Great Talent & Development Programs

Work Mode

This position follows a hybrid work model.

Flywire is an equal opportunity employer.

Required Skills
Ruby on RailsPythonBashJavaNode.jsOAuthSAMLSSOSASTDASTSCAApplication SecurityPenetration TestingVulnerability ResearchSource Code Auditing
Looking for a remote dev community?

200+ professionals, 37 countries, one network

Working remotely doesn't mean working alone. Iglu connects you with developers, designers, and digital experts worldwide. Collaborate, learn, and grow together.

Global professional network
Knowledge sharing & collaboration
Regular community events
Cross-project opportunities
Join the community
37 countries represented
About company
Flywire

Flywire is a global payments enablement and software company that digitizes payments for over 3,300+ global clients across education, healthcare, travel & B2B, covering more than 240 countries and territories and supporting over 140 currencies.

Visit website
Job Details
Department Information Technology
Category security
Posted 14 days ago