Director of Security Risk Engineering
Boston, MA - USA
Department:
Job Summary
The Opportunity:
As the Director of Security Risk Engineering you will serve as a key senior leader working in direct partnership with the CISO to drive shape and mature Flywires global enterprise security infrastructure and this role you will bridge the gap between high-level security strategy and tactical engineering execution across six core domains: Application Security AI Security Cloud Security Corporate Security Security Operations (SecOps) and Red Teaming (Penetration Testing).
In partnership with the internal stakeholder organizations you will lead the organizational shift from technical recovery to global enterprise operational resilience managing a highly impactful program that safeguards our global payment rails while fostering a culture of collaboration innovation and continuous improvement. A solid working knowledge of all aspects of cloud-native infrastructure software applications AI/LLM model development governance & validation and automated risk mitigation is required.
Responsibilities:
- Strategic Domain Leadership: Define implement and monitor a comprehensive security engineering strategy across Application Security AI Security Cloud Security Corporate Security Security Operations (SecOps/Incident Detection & Response) and Red Teaming (Penetration Testing) aligning initiatives with global business objectives and emerging financial threats.
- Team Management & Mentorship: Support the CISO to lead and manage the global security engineering organization including hiring training mentoring performance management and budget oversight.
- Secure Architecture & Governance: Oversee the design and continuous improvement of secure architecture for systems cloud infrastructure networks and applications ensuring strict alignment with security best practices.
- Global Cross-Functional Collaboration: Partner with Business Development DevOps Product Program Risk/Compliance and IT leaders to seamlessly integrate security controls into all phases of the engineering and CI/CD lifecycle. Engage actively with external stakeholders auditors and global regulators on related fronts.
- Advanced Cyber Risk Efficacy: Leverage AI and automated tooling to develop proactive measures threat intelligence capabilities and scalable defenses against vulnerabilities across all engineering domains.
- Adversarial / Penetration Testing: Personally adopt an attackers mindset to identify complex attack chains logic flaws and zero-day vulnerabilities within financial platforms and product architectures.
- Incident Response & Operational Resilience: Direct and coordinate responses to critical enterprise security incidents managing containment forensic investigation and rapid remediation efforts alongside SecOps.
- Regulatory Compliance Frameworks: Maintain an information security framework that ensures continuous readiness for strict industry audits and regulatory compliance requirements globally (e.g. NIST CSF 2.0 ISO 27001 PCI-DSS 4.0 DORA).
- Executive & Stakeholder Reporting: Define and maintain metrics that communicate security posture program progress and incident risk analysis to the CISO senior executive leadership and the Board.
- Innovation & Emerging Tech: Stay ahead of global fintech trends adopting cutting-edge technologies and methodologiesspecifically regarding secure AI deploymentto continuously strengthen the organizations security posture.
Qualifications :
Heres What Were Looking For:
- Education: Bachelors degree required in Computer Science Information Security or a related technical field. A Masters degree is highly preferred.
- Core Experience: 12 years of progressive experience in information security IT risk management or cyber defense roles. Must be an active technical practitioner with a proven track record of independently performing manual penetration testing vulnerability exploitation detection/response activities and code reviews across cloud and application infrastructures without relying solely on automated commercial tools.
- Leadership Experience: 3 years of proven experience in senior leadership or management roles specifically within a security engineering organization managing people cross-functional teams and complex security programs.
- Domain Mastery: In-depth technical knowledge of security architecture secure cloud infrastructure (e.g. AWS/Azure/GCP) application security principles and adversarial emulation (Red Teaming).
Highly Preferred Certifications
- Core Security: CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager)
- Governance & Risk: CRISC (Certified in Risk and Information Systems Control) CISA (Certified Information Systems Auditor) or ISACA AAISM (Advanced in AI Security Management)
- Hands-On Offensive & AI: OffSec OSAI (Offensive Security AI Red Teamer) OSCP (Offensive Security Certified Professional) OSCE (Offensive Security Certified Expert) or SANS GXPN (GIAC Exploit Researcher and Advanced Penetration Tester)
Skills and Abilities
- Strategic & Tactical Balancer with a Commercial Mindset: Highly hands-on and technically skilled. Strong strategic thinker with the ability to contribute to and translate the CISOs high-level vision into actionable plans and drive successful execution. Balances technical risk reduction with business enablement ensuring security infrastructure serves as a competitive advantage that unblocks global revenue and enterprise-client acquisition.
- Executive Presence: Exceptional communication and stakeholder management skills with a demonstrated ability to articulate complex security risks and technical concepts to both engineering teams and executive management/the Board.
- 2nd-Line Cyber Risk Oversight & Governance: Robust capability to operate as a strategic second-line risk leader. Proven experience defining enterprise security risk appetites establishing governance frameworks and executing independent control testing to validate that the first line (engineering/product teams) effectively manages cyber risk.
- Defense-in-Depth Expertise: Comprehensive understanding of modern system security design principles intrusion prevention API security and automated vulnerability management.
- High-Pressure Decision Making: Demonstrated capability to prioritize tasks maintain cross-functional transparency and make critical risk decisions under pressure during live security incidents.
- Lateral Influencing / Influential Leadership: Ability to collaborate effectively as a trusted partner across the global organization promoting a collaborative culture of continuous resilience and security awareness.
Additional Information :
What We Offer:
- Competitive compensation
- Employee Stock Purchase Plan (ESPP)
- Competitive time off including Digital Disconnect and FlyBetter Days to volunteer in a cause you believe in.
- Work with brilliant people globally Learn more about their journeys by checking out #InsideFlywire on social media
- Wellbeing Programs (Mental Health Wellness Yoga/Pilates/HIIT Classes) with Global FlyMates
- Be a meaningful part in our success - every FlyMate makes an impact
- Great Talent & Development Programs (Managers Taking Flight for new or aspiring managers OneFlywire Career Mobility)
Submit today and get started!
We are excited to get to know you! Throughout our process you can expect to meet with different FlyMates including the Hiring Manager Peers on the team the VP of the department and a skills assessment. Your Talent Acquisition Partner will walk you through the steps and be your go-to person for any questions.
The US base salary range for this full-time position is $200000 - 210000 and benefits. Our salary ranges are determined by role position level and location. The range displayed on this job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. Within the range individual pay is determined by work location and several other factors including job-related skills experience relevant education and training.
Flywire is an equal opportunity employer and follows a policy of administering all employment decisions and personnel actions without regard to race color religion sex pregnancy gender identity national origin age ancestry physical or mental disability sexual orientation genetic disposition or carrier status veteran status or any other category protected under applicable national federal state or local law.
#LI-Hybrid
Remote Work :
No
Employment Type :
Full-time
About Company
Flywire is a global payments enablement and software company, delivering high-stakes, high-value payments across the global education, healthcare, travel and B2B industries. Today, weve digitized payments for more than 4,000+ global clients in more than 140 currencies across 240 cou ... View more