ApplySarthi Match jobs to your CV

Senior Security Engineer (Defensive)

Flywire

Make my CV for this job, freeView job and applyYour CV, rewritten for this role using only your real experience. Sign in with Google and upload your CV. Nothing to install.

Skills named in this job

Read from the description itself, not inferred.

This role on the market

6 open defensive roles across 4 companies are on ApplySarthi right now, most of them in Bengaluru (1).

What defensive roles keep asking for: AWS (33%), Python (33%), Agile (17%), Azure (17%), CI/CD (17%), Docker (17%), Generative AI (17%), IAM (17%) — counted across their open postings here.

Security Engineer jobs in Bengaluru · Security Engineer jobs in India · Remote Security Engineer jobs · AWS jobs · CI/CD jobs · Docker jobs · Generative AI jobs

Flywire has 58 open roles listed here.

Counted across 14 company job boards, updated as roles open and close.

Preparing for this interview

Interviews for defensive roles keep coming back to AWS, Python, Agile, Azure. Practise those questions before you sit with Flywire.

Questions you are likely to be asked

  1. Why do you want to join Flywire?
  2. What is your experience with Kubernetes? Tell me one thing you learned the hard way.
  3. Tell me about an outage you handled. What did you learn from it?
  4. How do you decide what to monitor, and what should wake someone up at night?
  5. How would you cut the cloud bill of a system without hurting it?

Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.

Practise the Senior Security Engineer (Defensive) at Flywire interview free →

Job Summary As a Senior Security Engineer on the Defensive Platform Builder track you will act as a technical authority for secure software design and cloud native infrastructure defence across Flywire's global footprint. You will bring an automation first mindset to a high velocity fintech environment, partnering with software engineering and SRE squads to embed security controls directly into our public cloud and GitLab CI/CD pipelines using AI workflows, so that our global payment systems stay secure by design and resilient in production. Responsibilities and Tasks: 1. Secure SDLC & CI/CD Automation Ownership Own, design and drive the end to end integration of automated security requirements and validation tooling into high velocity engineering pipelines. Build custom internal tooling, wrappers and automated controls to replace manual security checkpoints, protecting development velocity while removing friction. 2. Cloud & Infrastructure Hardening Partner directly with SRE and DevOps teams to establish secure public cloud architecture blueprints, manage Infrastructure as Code security scanning (for example Terraform) and enforce strict network isolation. Architect and maintain cloud Identity and Access Management controls and enforce Zero Trust boundaries within containerised environments such as Docker and Kubernetes. 3. AI Driven Security & Application Reviews Design, prompt engineer and deploy automated security review workflows using LLM APIs to run real time code analysis and give context aware feedback on pull requests. Establish and enforce technical controls that protect internal and external generative AI features against LLM specific risks, including prompt injection, insecure output handling, model inversion and data poisoning. Run deep dive source code audits and API security reviews that go beyond automated scanning, surfacing complex logic flaws before they reach production. 4. Cross Functional Collaboration & Technical Mentorship Embed within software development and infrastructure sprint planning from the inception phase so that security is built in from day one rather than bolted on. Provide expert level, actionable code and configuration guidance directly to software and SRE engineers. Mentor junior security, software and SRE engineers to raise technical resilience across the wider organisation. Education: Bachelor's degree required in Computer Science, Cyber Security, Software Engineering or a related technical discipline. A Master's degree is preferred. Core Experience: indicative range [5 to 8 years] of progressive engineering experience across Application Security and Cloud Architecture Defence. Advanced Defensive Depth : a proven track record of independently running deep manual code and configuration reviews rather than relying solely on commercial automated scanning platforms. Cloud & DevOps Engineering Stack: deep practical knowledge of AWS or similar public cloud topologies, containerisation and orchestration (Docker, Kubernetes), network security controls and high velocity GitLab CI pipelines. Technical Language Depth: solid proficiency with modern web development frameworks and languages including Python, Ruby on Rails, Java and Node.js. AI & Cryptographic Domain Mastery: expert level understanding of the OWASP Top 10 for LLMs, prompt engineering wrappers, applied cryptography, cloud network isolation and federated authentication architectures (OAuth2, SAML, OIDC, Zero Trust IAM). Regulatory & Compliance Competency: practical experience aligning technical software and infrastructure controls with standards such as PCI-DSS (v4.0), SOC 1, SOC 2 and DORA. Highly Preferred Certifications Cloud & Architecture: AWS Certified Security - Specialty, Certified Kubernetes Security Specialist (CKS) or CISSP. Modern AI Security: OffSec OSAI (Offensive Security AI Red Teamer). Broader Depth: OSCP or GCIH, where candidates bring exposure to offensive or incident response work as a secondary strength. Skills and Abilities Balances a builder's engineering empathy with a security first mindset, treating software, SRE and product teams as operational allies rather than a source of friction. Communicates clearly under pressure, able to distill cloud configuration drift or a live vulnerability into a plain, high impact risk summary for non-technical stakeholders. Shows creative, novel problem solving across complex, non-standard application and cloud infrastructure challenges within a distributed financial microservices environment. Resilience and analytical clarity in high-pressure scenarios, with the ability to manage transparency and guide risk-based decisions during active security incidents or compressed financial product launch windows. Balances technical risk reduction with business enablement, ensuring security infrastructure serves as a competitive advantage that unblocks global revenue and enterprise-client acquisition. What We Offer: Competitive compensation Employee Stock Purchase Plan (ESPP) Competitive time off, including Digital Disconnect and FlyBetter Days to volunteer in a cause you believe in. Flying Start - Our immersive Global Induction Program (Meet our Execs & Global Teams) Work with brilliant people globally Learn more about their journeys by checking out #InsideFlywire on social media Wellbeing Programs (Mental Health, Wellness, Yoga/Pilates/HIIT Classes) with Global FlyMates Be a meaningful part in our success - every FlyMate makes an impact Great Talent & Development Programs (Managers Taking Flight – for new or aspiring managers, OneFlywire Career Mobility) Submit today and get started! We are excited to get to know you! Throughout our process you can expect to meet with different FlyMates including the Hiring Manager, Peers on the team, the VP of the department, and a skills assessment. Your Talent Acquisition Partner will walk you through the steps and be your “go-to” person for any questions. #LI-Hybrid

Match this job to your CV

ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.

Check my match →

Similar open roles

Need answers during your interview? Try Live Sarthi.

Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.

Try Live Sarthi free →

A Windows app, from the same team as ApplySarthi.

Listed on smartrecruiters · posted 2026-09-08. ApplySarthi collects openings and links to application pages; the role is advertised by Flywire, not by us.