Flywire
Director of Security Risk Engineering
Boston, MA, United States · Director · Full-time
Sponsorship not specified$200k-$210kDetected 40 days ago
RailsCode ReviewAWSGCPAzureCloud PlatformsCI/CDDevOpsLLMsCybersecurityPenetration TestingSOC OperationsIncident ResponseComplianceStakeholder ManagementRecruitingPerformance ManagementLeadershipCommunicationCollaborationMentoringCISSP
About the role
- As the Director of Security Risk Engineering, you will serve as a key senior leader working in direct partnership with the CISO to drive, shape, and mature Flywire's global enterprise security infrastructure and systems.
- In this role, you will bridge the gap between high-level security strategy and tactical engineering execution across six core domains: Application Security, AI Security, Cloud Security, Corporate Security, Security Operations (SecOps), and Red Teaming (Penetration Testing).
- In partnership with the internal stakeholder organizations, you will lead the organizational shift from technical recovery to global enterprise operational resilience, managing a highly impactful program that safeguards our global payment rails while fostering a culture of collaboration, innovation, and continuous improvement.
Responsibilities
- Strategic Domain Leadership: Define, implement, and monitor a comprehensive security engineering strategy across Application Security, AI Security, Cloud Security, Corporate Security, Security Operations (SecOps/Incident Detection & Response), and Red Teaming (Penetration Testing), aligning initiatives with global business objectives and emerging financial threats.
- Team Management & Mentorship: Support the CISO to lead and manage the global security engineering organization, including hiring, training, mentoring, performance management, and budget oversight.
- Secure Architecture & Governance: Oversee the design and continuous improvement of secure architecture for systems, cloud infrastructure, networks, and applications, ensuring strict alignment with security best practices.
- Global Cross-Functional Collaboration: Partner with Business, Development, DevOps, Product, Program, Risk/Compliance, and IT leaders to seamlessly integrate security controls into all phases of the engineering and CI/CD lifecycle.
- Advanced Cyber Risk Efficacy: Leverage AI and automated tooling to develop proactive measures, threat intelligence capabilities, and scalable defenses against vulnerabilities across all engineering domains.
- Regulatory Compliance Frameworks: Maintain an information security framework that ensures continuous readiness for strict industry audits and regulatory compliance requirements globally (e.g., NIST CSF 2.0, ISO 27001, PCI-DSS 4.0, DORA).
- Executive & Stakeholder Reporting: Define and maintain metrics that communicate security posture, program progress, and incident risk analysis to the CISO, senior executive leadership, and the Board.
- Your Talent Acquisition Partner will walk you through the steps and be your "go-to" person for any questions.
Requirements
- 12+ years of progressive experience in information security, IT risk management, or cyber defense roles.
- A solid working knowledge of all aspects of cloud-native infrastructure, software applications, AI/LLM model development, governance & validation, and automated risk mitigation is required.
- Core Experience: 12+ years of progressive experience in information security, IT risk management, or cyber defense roles.
Nice to have
- Bachelor's degree required in Computer Science, Information Security, or a related technical field.
- A Master's degree is highly preferred.
- In-depth technical knowledge of security architecture, secure cloud infrastructure (e.g., AWS/Azure/GCP), application security principles, and adversarial emulation (Red Teaming).
- Highly Preferred Certifications
Skills
- Engage actively with external stakeholders, auditors and global regulators on related fronts.
- Skills and Abilities
- Robust capability to operate as a strategic second-line risk leader.
Compensation
- $200k-$210k
Benefits
- Employee Stock Purchase Plan (ESPP)
- Competitive time off, including Digital Disconnect and FlyBetter Days to volunteer in a cause you believe in.
- Wellbeing Programs (Mental Health, Wellness, Yoga/Pilates/HIIT Classes) with Global FlyMates
- The US base salary range for this full-time position is $200,000 - 210,000 and benefits.
- Strong strategic thinker with the ability to contribute to and translate the CISO's high-level vision into actionable plans and drive successful execution.
- Education: Bachelor's degree required in Computer Science, Information Security, or a related technical field.
- Within the range, individual pay is determined by work location and several other factors, including job-related skills, experience, relevant education and training.
Company info
- Flywire is a global payments enablement and software company, founded more than a decade ago to solve high-stakes, high-value payments in higher education.
- We've since scaled into new regions and industry verticals and expanded our product offerings to deliver meaningful value to our clients around the world.
- Today we support more than 5,100 clients across the global education, healthcare, travel & B2B industries, with diverse payment methods across 240 countries & territories and more than 140 currencies.
- With over 1,200 global FlyMates, representing more than 40 nationalities, and in 12 offices world-wide, we're looking for FlyMates to join the next stage of our journey as we continue to grow.
- The Opportunity:
- Here's What We're Looking For:
- We are excited to get to know you!
Apply directly at Flywire →Create a free account for alerts like thisView Flywire immigration profile
This listing is sourced directly from Flywire's careers page and normalized into a canonical job model.