The Opportunity:
At Flywire, security isn t a checkbox-it s a foundational pillar of how we build. We are looking for a high-impact Senior Security Engineer I, Application Security to act as a technical visionary, bridging the gap between robust defense and rapid innovation. We expect this role to be able to blend traditional security architecture with new technologies like AI-driven automation.
Key Responsibilities
- AI-Driven Security Automation: Design, prompt-engineer, and deploy automated security review workflows, using for example Claude or other LLM APIs to perform real-time code analysis and architectural reviews within our CI/CD environment.
- Security Design Architecture: Lead secure design reviews and advanced threat modeling for our complex payment systems and AI integrated applications.
- Engineering Collaboration Leadership: Act as a technical bridge between Security and Engineering teams. Collaborate frequently with different engineering teams to identify and address security issues.
- Advanced Full-Stack Reviews: Oversee deep-dive technical reviews, moving beyond basic scans to perform source code audits and live application testing on high-risk features.
- Automation SDLC: Contribute and take ownership for the automated security controls we are building and take an active part in every aspect of the secure software development lifecycle (S-SDLC).
- Mentorship Guidance: Provide hands-on remediation guidance and mentor junior security or software engineers, also members of Product teams, on both traditional exploits and emerging AI-specific vulnerabilities. Qualifications
Heres what we are looking for:
Experience Mindset
- 5+ years in Application Security. Proven experience performing web application penetration tests and vulnerability research.
Skills in source code auditing, product assessments and interaction with product teams,
and also experience with development of security tools are essential.
- Automation First: A passion for replacing manual, repetitive tasks with intelligent, automated scripts and AI workflows.
- AI LLM Proficiency
- Prompt Engineering for Security : Demonstrated ability to use tools like Claude for security-specific tasks like code summarization, vulnerability detection, and automated fix generation.
- AI Pipeline Integration : Experience building custom tools or wrappers that leverage LLMs to analyze pull requests and provide context-aware security feedback.
- OWASP Top 10 for LLMs : Deep practical knowledge of defending against Prompt Injection, Insecure Output Handling, and Model Inversion.
Technical Proficiencies
- Full-Stack Depth : experience with Python, Ruby on Rails, Java and modern web dev (JavaScript, Node.js, etc.).
- Cloud DevOps : Good knowledge of AWS or similar cloud environments, containerization (Docker), and building/maintaining GitLab CI pipelines.
- Security Tooling: Advanced experience with SAST, DAST, and SCA tools, and more importantly, the ability to tune them to eliminate noise.
- Crypto Auth: Deep understanding of applied cryptography, OAuth2, SAML, and SSO implementations.
- Soft Skills
- Strategic Communication: Ability to translate complex AI-generated findings into actionable business risks for stakeholders.
Empathy-Driven Security: A team-oriented approach that treats developers and product teams as partners, focusing on enablement rather than friction.
Compliance Standards
- Practical experience aligning technical controls with standards like SOC 1, SOC 2, PCI-DSS, and emerging AI-governance frameworks.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Sr Security Engineer I, Application Security (Bengaluru)
🏢 MPC
📍 Bengaluru