Skip to content
← Back to job listings

Director of Security Risk Engineering

Flywire · Boston, United States

External listingfull-timeabout 2 months ago

About The Role

Join Flywire as the Director of Security Risk Engineering, where you will play a crucial role in shaping and maturing the company's global enterprise security infrastructure. You will bridge the gap between high-level security strategy and tactical engineering execution across six core domains. Your responsibilities will include defining and implementing a comprehensive security engineering strategy, managing the global security engineering organization, overseeing secure architecture and governance, collaborating with cross-functional teams, and driving incident response and operational resilience. You will also maintain regulatory compliance frameworks and report on security posture and program progress to senior leadership and the Board.

  • Definir, implementar y monitorear una estrategia integral de ingeniería de seguridad en múltiples dominios.
  • Liderar y gestionar la organización global de ingeniería de seguridad, incluyendo la contratación, capacitación y gestión del rendimiento.
  • Colaborar con diversas partes interesadas para integrar sin problemas los controles de seguridad en todas las fases del ciclo de vida de la ingeniería.
  • A solid working knowledge of all aspects of cloud-native infrastructure, software applications, AI/LLM model development, governance & validation, and automated risk mitigation is required
  • Domain Mastery: In-depth technical knowledge of security architecture, secure cloud infrastructure (e.g., AWS/Azure/GCP), application security principles, and adversarial emulation (Red Teaming)
  • Core Experience: 12+ years of progressive experience in information security, IT risk management, or cyber defense roles. Must be an active technical practitioner with a proven track record of independently performing manual penetration testing, vulnerability exploitation, detection/response activities, and code reviews across cloud and application infrastructures, without relying solely on automated commercial tools
  • Leadership Experience: 3+ years of proven experience in senior leadership or management roles specifically within a security engineering organization, managing people, cross-functional teams and complex security programs
  • Education: Bachelor's degree required in Computer Science, Information Security, or a related technical field. A Master's degree is highly preferred
  • Core Security: CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager)
  • Governance & Risk: CRISC (Certified in Risk and Information Systems Control), CISA (Certified Information Systems Auditor), or ISACA AAISM™ (Advanced in AI Security Management)
  • Hands-On Offensive & AI: OffSec OSAI (Offensive Security AI Red Teamer), OSCP (Offensive Security Certified Professional), OSCE (Offensive Security Certified Expert), or SANS GXPN (GIAC Exploit Researcher and Advanced Penetration Tester)
  • Strategic & Tactical Balancer with a Commercial Mindset: Highly hands-on and technically skilled. Strong strategic thinker with the ability to contribute to and translate the CISO’s high-level vision into actionable plans and drive successful execution. Balances technical risk reduction with business enablement, ensuring security infrastructure serves as a competitive advantage that unblocks global revenue and enterprise-client acquisition
  • Lateral Influencing / Influential Leadership: Ability to collaborate effectively as a trusted partner across the global organization, promoting a collaborative culture of continuous resilience and security awareness
  • Defense-in-Depth Expertise: Comprehensive understanding of modern system security design principles, intrusion prevention, API security, and automated vulnerability management
  • High-Pressure Decision Making: Demonstrated capability to prioritize tasks, maintain cross-functional transparency, and make critical risk decisions under pressure during live security incidents
  • 2nd-Line Cyber Risk Oversight & Governance: Robust capability to operate as a strategic second-line risk leader. Proven experience defining enterprise security risk appetites, establishing governance frameworks, and executing independent control testing to validate that the first line (engineering/product teams) effectively manages cyber risk
  • Executive Presence: Exceptional communication and stakeholder management skills, with a demonstrated ability to articulate complex security risks and technical concepts to both engineering teams and executive management/the Board

This is an external listing. JobSpring does not represent or verify the employer. Report this listing