As a Senior Security Engineer on the Active Operational Defender track you will act as a core operational lead for threat detection, penetration testing and incident containment across Flywires global footprint. You will combine an aggressive attackers mindset with the analytical rigour needed to build high fidelity detection engineering, serving as a primary responder when live incidents put our global payment networks at risk.
Responsibilities
- Offensive Penetration Testing &
- Red Teaming: Personally adopt an attackers mindset to uncover complex logic flaws, carry out exploit research and emulate adversarial behaviour across financial platforms and product architectures.
- Threat Detection Engineering &
- SIEM: Design, build and deploy high fidelity detection rules, behavioural analytics and automated alert workflows within the enterprise SIEM to catch anomalous activity at scale.
- Incident Response &
- Forensics: Lead technical containment, forensic collection and rapid threat eradication during active, critical security incidents.
- Cross Functional Collaboration &
- Technical Mentorship: Embed within security operations and engineering planning to ensure detection and response capability keeps pace with the platform.
- Provide expert level guidance on exploit chains and incident findings to engineering and leadership stakeholders.
- Mentor junior security engineers on offensive tooling, detection engineering and incident response practice.
Qualifications
- Education: Bachelors degree required in Computer Science, Cyber Security, Software Engineering or a related technical discipline.
A Masters degree is preferred.
- Core Experience: Indicative range [5 to 8 years] of progressive engineering experience across Security Operations, Incident Response and Penetration Testing.
- Advanced Exploitation Depth: a proven track record of independently performing deep manual penetration testing, web application exploitation and incident containment rather than relying solely on commercial automated scanning platforms.
- SecOps &
- Forensics Tool Stack:
advanced working proficiency with modern EDR platforms, SIEM systems, network packet analysis (PCAP), threat intelligence frameworks (MITRE ATT&CK;) and forensic collection tools.
- Technical Language Depth: solid proficiency with a language such as Python, together with practical familiarity with common web and API technologies used to build exploit tooling.
- AI &
- Adversarial Testing Mastery:
expert level understanding of the OWASP Top 10 for LLMs and how to apply an attackers mindset to generative AI features, including prompt injection and insecure output handling.
- Regulatory &
- Compliance Competency:
practical experience aligning technical testing and logging outputs with standards such as PCI-DSS (v4.0), SOC 1, SOC 2 and DORA.
Highly Preferred Certifications
- Hands-On Offensive &
- Red Team:
OSCP, OSCE or SANS GXPN (GIAC Exploit Researcher and Advanced Penetration Tester).
- Incident Response &
- Defence:
GCIH (GIAC Certified Incident Handler), GCFA (GIAC Certified Forensic Analyst) or a specialised Blue Team certification.
- Up-to-date AI Security: OffSec OSAI (Offensive Security AI Red Teamer).
Skills and Abilities
- Combines an aggressive, attackers mindset used to find vulnerabilities with the analytical discipline required to write clear, actionable detection rules.
- Stays calm and analytically clear under intense pressure during active, live breach events or business critical system failures.
- Communicates exploit chains and log anomalies clearly, turning technical detail into a plain, high impact risk profile for non-technical leadership.
- Resilience and analytical clarity in high-pressure scenarios, with the ability to manage transparency and guide risk-based decisions during active security incidents or compressed financial product launch windows.
- Balances technical risk reduction with business enablement, ensuring security infrastructure serves as a competitive advantage that unblocks global revenue and enterprise-client acquisition.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Sr Security Engineer (Offensive) (Bengaluru)
🏢 MPC
📍 Bengaluru