About this role
Flywire is seeking a Director of Security Risk Engineering in Boston, MA. This senior leadership role partners directly with the CISO to shape and mature Flywire's global enterprise security infrastructure and systems. The position bridges high-level security strategy with tactical engineering execution across six domains: Application Security, AI Security, Cloud Security, Corporate Security, Security Operations (SecOps), and Red Teaming (Penetration Testing). You will drive an organizational shift toward global operational resilience, safeguarding our payment rails while fostering collaboration, innovation, and continuous improvement. A solid working knowledge of cloud-native infrastructure, software applications, AI/LLM model development, governance and validation, and automated risk mitigation is required.
Responsibilities
- Strategic Domain Leadership: Define, implement, and monitor a comprehensive security engineering strategy across Application Security, AI Security, Cloud Security, Corporate Security, SecOps/Incident Detection & Response, and Red Teaming, aligning initiatives with global business objectives and emerging financial threats.
- Team Management & Mentorship: Support the CISO in leading and managing the global security engineering organization, including hiring, training, mentoring, performance management, and budget oversight.
- Secure Architecture & Governance: Oversee the design and continuous improvement of secure architecture for systems, cloud infrastructure, networks, and applications, ensuring alignment with security best practices.
- Global Cross-Functional Collaboration: Partner with Business, Development, DevOps, Product, Program, Risk/Compliance, and IT leaders to integrate security controls into all phases of the engineering and CI/CD lifecycle. Engage with external stakeholders, auditors, and global regulators as needed.
- Advanced Cyber Risk Efficacy: Use AI and automated tooling to develop proactive measures, threat intelligence capabilities, and scalable defenses across all engineering domains.
- Adversarial / Penetration Testing: Apply an attacker’s mindset to identify complex attack chains, logic flaws, and zero-day vulnerabilities within financial platforms and product architectures.
- Incident Response & Operational Resilience: Direct and coordinate responses to critical enterprise security incidents, overseeing containment, forensic investigations, and rapid remediation with SecOps.
- Regulatory Compliance Frameworks: Maintain an information security framework that supports continuous readiness for global audits and regulatory requirements (e.g., NIST CSF 2.0, ISO 27001, PCI-DSS 4.0, DORA).
- Executive & Stakeholder Reporting: Define and maintain metrics that communicate security posture, program progress, and incident risk analysis to the CISO, senior leadership, and the Board.
- Innovation & Emerging Tech: Stay ahead of fintech trends and adopt cutting-edge technologies and methodologies, with a focus on secure AI deployment to strengthen the security posture.
What we’re looking for:
- Education: Bachelor’s degree in Computer Science, Information Security, or a related technical field; Master’s degree strongly preferred.
- Core
Experience
- 12+ years in information security, IT risk management, or cyber defense, with hands-on experience in manual penetration testing, vulnerability exploitation, detection/response, and code reviews across cloud and application infrastructures. Must not rely solely on automated tools.
- Leadership
Experience
- 3+ years in senior leadership or management roles within a security engineering organization, overseeing people, cross-functional teams, and complex security programs.
- Domain Mastery: Deep technical knowledge of security architecture, secure cloud infrastructure (AWS/Azure/GCP), application security, and adversarial emulation (Red Teaming).
- Certifications (highly preferred): Core security certifications such as CISSP or CISM; governance/risk certifications like CRISC, CISA, or ISACA AAISM; hands-on offensive and AI security credentials such as OffSec OSAI, OSCP, OSCE, or SANS GXPN.
- Skills and Abilities: Strong strategic and practical execution skills with a commercial mindset; excellent communication and stakeholder management; ability to operate as a second-line cyber risk governance leader; defense-in-depth expertise; ability to make high-stakes decisions under pressure; and proven collaborative leadership across a global organization.