Flywire

Flywire

Director of Security Risk Engineering

Boston, MA, United States · Director · Full-time

Sponsorship not specified$200k-$210kDetected 40 days ago
RailsCode ReviewAWSGCPAzureCloud PlatformsCI/CDDevOpsLLMsCybersecurityPenetration TestingSOC OperationsIncident ResponseComplianceStakeholder ManagementRecruitingPerformance ManagementLeadershipCommunicationCollaborationMentoring

About the role

  • As the Director of Security Risk Engineering, you will serve as a key senior leader working in direct partnership with the CISO to drive, shape, and mature Flywire's global enterprise security infrastructure and systems.
  • In this role, you will bridge the gap between high-level security strategy and tactical engineering execution across six core domains: Application Security, AI Security, Cloud Security, Corporate Security, Security Operations (SecOps), and Red Teaming (Penetration Testing).
  • In partnership with the internal stakeholder organizations, you will lead the organizational shift from technical recovery to global enterprise operational resilience, managing a highly impactful program that safeguards our global payment rails while fostering a culture of collaboration, innovation, and continuous improvement.

Responsibilities

  • Strategic Domain Leadership: Define, implement, and monitor a comprehensive security engineering strategy across Application Security, AI Security, Cloud Security, Corporate Security, Security Operations (SecOps/Incident Detection & Response), and Red Teaming (Penetration Testing), aligning initiatives with global business objectives and emerging financial threats.
  • Team Management & Mentorship: Support the CISO to lead and manage the global security engineering organization, including hiring, training, mentoring, performance management, and budget oversight.
  • Secure Architecture & Governance: Oversee the design and continuous improvement of secure architecture for systems, cloud infrastructure, networks, and applications, ensuring strict alignment with security best practices.
  • Global Cross-Functional Collaboration: Partner with Business, Development, DevOps, Product, Program, Risk/Compliance, and IT leaders to seamlessly integrate security controls into all phases of the engineering and CI/CD lifecycle.
  • Advanced Cyber Risk Efficacy: Leverage AI and automated tooling to develop proactive measures, threat intelligence capabilities, and scalable defenses against vulnerabilities across all engineering domains.
  • Regulatory Compliance Frameworks: Maintain an information security framework that ensures continuous readiness for strict industry audits and regulatory compliance requirements globally (e.g., NIST CSF 2.0, ISO 27001, PCI-DSS 4.0, DORA).
  • Executive & Stakeholder Reporting: Define and maintain metrics that communicate security posture, program progress, and incident risk analysis to the CISO, senior executive leadership, and the Board.
  • Your Talent Acquisition Partner will walk you through the steps and be your "go-to" person for any questions.

Requirements

  • 12+ years of progressive experience in information security, IT risk management, or cyber defense roles.
  • A solid working knowledge of all aspects of cloud-native infrastructure, software applications, AI/LLM model development, governance & validation, and automated risk mitigation is required.
  • Core Experience: 12+ years of progressive experience in information security, IT risk management, or cyber defense roles.

Nice to have

  • Bachelor's degree required in Computer Science, Information Security, or a related technical field.
  • A Master's degree is highly preferred.
  • In-depth technical knowledge of security architecture, secure cloud infrastructure (e.g., AWS/Azure/GCP), application security principles, and adversarial emulation (Red Teaming).
  • Highly Preferred Certifications

Skills

  • Engage actively with external stakeholders, auditors and global regulators on related fronts.
  • Skills and Abilities
  • Robust capability to operate as a strategic second-line risk leader.

Compensation

  • $200k-$210k

Benefits

  • Employee Stock Purchase Plan (ESPP)
  • Competitive time off, including Digital Disconnect and FlyBetter Days to volunteer in a cause you believe in.
  • Wellbeing Programs (Mental Health, Wellness, Yoga/Pilates/HIIT Classes) with Global FlyMates
  • The US base salary range for this full-time position is $200,000 - 210,000 and benefits.
  • Strong strategic thinker with the ability to contribute to and translate the CISO's high-level vision into actionable plans and drive successful execution.
  • Education: Bachelor's degree required in Computer Science, Information Security, or a related technical field.
  • Within the range, individual pay is determined by work location and several other factors, including job-related skills, experience, relevant education and training.

Company info

  • Flywire is a global payments enablement and software company, founded more than a decade ago to solve high-stakes, high-value payments in higher education.
  • We've since scaled into new regions and industry verticals and expanded our product offerings to deliver meaningful value to our clients around the world.
  • Today we support more than 5,100 clients across the global education, healthcare, travel & B2B industries, with diverse payment methods across 240 countries & territories and more than 140 currencies.
  • With over 1,200 global FlyMates, representing more than 40 nationalities, and in 12 offices world-wide, we're looking for FlyMates to join the next stage of our journey as we continue to grow.
  • The Opportunity:
  • Here's What We're Looking For:
  • We are excited to get to know you!

This listing is sourced directly from Flywire's careers page and normalized into a canonical job model.