Director of Security Risk Engineering
$200k - $210kFlywire
Are you ready to trade your job for a journey? Become a FlyMate!
Passion, excitement & global collaboration are all core to what it means to be a FlyMate. At Flywire, we’re on a mission to deliver the world’s most important and complex payments. We use our Flywire Advantage - the combination of our next-gen payments platform, proprietary payment network and vertical specific software, to help our clients get paid, and help their customers pay with ease - no matter where they are in the world.
What more do we need to truly be unstoppable? Perhaps, that is you!
Who we are:
Flywire is a global payments enablement and software company, founded more than a decade ago to solve high-stakes, high-value payments in higher education. We’ve since scaled into new regions and industry verticals and expanded our product offerings to deliver meaningful value to our clients around the world.
Today we support more than 5,100 clients across the global education, healthcare, travel & B2B industries, with diverse payment methods across 240 countries & territories and more than 140 currencies.
With over 1,200 global FlyMates, representing more than 40 nationalities, and in 12 offices world-wide, we’re looking for FlyMates to join the next stage of our journey as we continue to grow.
Job Description
The Opportunity:
As the Director of Security Risk Engineering, you will serve as a key senior leader working in direct partnership with the CISO to drive, shape, and mature Flywire's global enterprise security infrastructure and systems. In this role, you will bridge the gap between high-level security strategy and tactical engineering execution across six core domains: Application Security, AI Security, Cloud Security, Corporate Security, Security Operations (SecOps), and Red Teaming (Penetration Testing).
In partnership with the internal stakeholder organizations, you will lead the organizational shift from technical recovery to global enterprise operational resilience, managing a highly impactful program that safeguards our global payment rails while fostering a culture of collaboration, innovation, and continuous improvement. A solid working knowledge of all aspects of cloud-native infrastructure, software applications, AI/LLM model development, governance & validation, and automated risk mitigation is required.
Responsibilities:
- Strategic Domain Leadership: Define, implement, and monitor a comprehensive security engineering strategy across Application Security, AI Security, Cloud Security, Corporate Security, Security Operations (SecOps/Incident Detection & Response), and Red Teaming (Penetration Testing), aligning initiatives with global business objectives and emerging financial threats.
- Team Management & Mentorship: Support the CISO to lead and manage the global security engineering organization, including hiring, training, mentoring, performance management, and budget oversight.
- Secure Architecture & Governance: Oversee the design and continuous improvement of secure architecture for systems, cloud infrastructure, networks, and applications, ensuring strict alignment with security best practices.
- Global Cross-Functional Collaboration: Partner with Business, Development, DevOps, Product, Program, Risk/Compliance, and IT leaders to seamlessly integrate security controls into all phases of the engineering and CI/CD lifecycle. Engage actively with external stakeholders, auditors and global regulators on related fronts.
- Advanced Cyber Risk Efficacy: Leverage AI and automated tooling to develop proactive measures, threat intelligence capabilities, and scalable defenses against vulnerabilities across all engineering domains.
- Adversarial / Penetration Testing: Personally adopt an attacker's mindset to identify complex attack chains, logic flaws, and zero-day vulnerabilities within financial platforms and product architectures.
- Incident Response & Operational Resilience: Direct and coordinate responses to critical enterprise security incidents, managing containment, forensic investigation, and rapid remediation efforts alongside SecOps.
- Regulatory Compliance Frameworks: Maintain an information security framework that ensures continuous readiness for strict industry audits and regulatory compliance requirements globally (e.g., NIST CSF 2.0, ISO 27001, PCI-DSS 4.0, DORA).
- Executive & Stakeholder Reporting: Define and maintain metrics that communicate security posture, program progress, and incident risk analysis to the CISO, senior executive leadership, and the Board.
- Innovation & Emerging Tech: Stay ahead of global fintech trends, adopting cutting-edge technologies and methodologies—specifically regarding secure AI deployment—to continuously strengthen the organization's security posture.
Qualifications
Here's What We're Looking For:
- Education: Bachelor's degree required in Computer Science, Information Security, or a related technical field. A Master's degree is highly preferred.
- Core Experience: 12+ years of progressive experience in information security, IT risk management, or cyber defense roles. Must be an active technical practitioner with a proven track record of independently performing manual penetration testing, vulnerability exploitation, detection/response activities, and code reviews across cloud and application infrastructures, without relying solely on automated commercial tools.
- Leadership Experience: 3+ years of proven experience in senior leadership or management roles specifically within a security engineering organization, managing people, cross-functional teams and complex security programs.
- Domain Mastery: In-depth technical knowledge of security architecture, secure cloud infrastructure (e.g., AWS/Azure/GCP), application security principles, and adversarial emulation (Red Teaming).
Highly Preferred Certifications
- Core Security: CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager)
- Governance & Risk: CRISC (Certified in Risk and Information Systems Control), CISA (Certified Information Systems Auditor), or ISACA AAISM™ (Advanced in AI Security Management)
- Hands-On Offensive & AI: OffSec OSAI (Offensive Security AI Red Teamer), OSCP (Offensive Security Certified Professional), OSCE (Offensive Security Certified Expert), or SANS GXPN (GIAC Exploit Researcher and Advanced Penetration Tester)
Skills and Abilities
- Strategic & Tactical Balancer with a Commercial Mindset: Highly hands-on and technically skilled. Strong strategic thinker with the ability to contribute to and translate the CISO’s high-level vision into actionable plans and drive successful execution. Balances technical risk reduction with business enablement, ensuring security infrastructure serves as a competitive advantage that unblocks global revenue and enterprise-client acquisition.
- Executive Presence: Exceptional communication and stakeholder management skills, with a demonstrated ability to articulate complex security risks and technical concepts to both engineering teams and executive management/the Board.
- 2nd-Line Cyber Risk Oversight & Governance: Robust capability to operate as a strategic second-line risk leader. Proven experience defining enterprise security risk appetites, establishing governance frameworks, and executing independent control testing to validate that the first line (engineering/product teams) effectively manages cyber risk.
- Defense-in-Depth Expertise: Comprehensive understanding of modern system security design principles, intrusion prevention, API security, and automated vulnerability management.
- High-Pressure Decision Making: Demonstrated capability to prioritize tasks, maintain cross-functional transparency, and make critical risk decisions under pressure during live security incidents.
- Lateral Influencing / Influential Leadership: Ability to collaborate effectively as a trusted partner across the global organization, promoting a collaborative culture of continuous resilience and security awareness.
Additional Information
What We Offer:
- Competitive compensation
- Employee Stock Purchase Plan (ESPP)
- Competitive time off, including Digital Disconnect and FlyBetter Days to volunteer in a cause you believe in.
- Work with brilliant people globally Learn more about their journeys by checking out #InsideFlywire on social media
- Wellbeing Programs (Mental Health, Wellness, Yoga/Pilates/HIIT Classes) with Global FlyMates
- Be a meaningful part in our success - every FlyMate makes an impact
- Great Talent & Development Programs (Managers Taking Flight – for new or aspiring managers, OneFlywire Career Mobility)
Submit today and get started!
We are excited to get to know you! Throughout our process you can expect to meet with different FlyMates including the Hiring Manager, Peers on the team, the VP of the department, and a skills assessment. Your Talent Acquisition Partner will walk you through the steps and be your “go-to” person for any questions.
The US base salary range for this full-time position is $200,000 - 210,000 and benefits. Our salary ranges are determined by role, position level, and location. The range displayed on this job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. Within the range, individual pay is determined by work location and several other factors, including job-related skills, experience, relevant education and training.
Flywire is an equal opportunity employer and follows a policy of administering all employment decisions and personnel actions without regard to race, color, religion, sex, pregnancy, gender identity, national origin, age, ancestry, physical or mental disability, sexual orientation, genetic disposition or carrier status, veteran status, or any other category protected under applicable national, federal, state or local law.
#LI-Hybrid
$99k - $232k
...SectorNot ApplicableSpecialismCybersecurity & PrivacyManagement LevelManagerJob Description & SummaryThe OpportunityAs a Security Risk & Engineering - Tech and Cyber Risk & Compliance - Manager, you will play a pivotal role in guiding organizations through complex regulatory...SuggestedFull timeH1b$77k - $202k
...ApplicableSpecialismCybersecurity & PrivacyManagement LevelSenior AssociateJob Description & SummaryThe OpportunityAs a Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Associate, you will focus on maintaining regulatory compliance and managing risks...SuggestedFull timeH1b$156k - $234k
...to own their own destiny.An exciting opportunity within the Security Trust and Risk (STAR) team whose mission is to ensure the safety and... ...organization.About the role:The Lead Security Governance & Risk Engineer is a senior, hands-on role at the point where security governance...Suggested$154.59k - $162k
...Follow @abbvie on X , Facebook , Instagram , YouTube , LinkedIn and Tik Tok . Job Description Senior Data Security Engineer (Insider Risk Management – Engineering), AbbVie Inc., Cambridge, MA; Hybrid (onsite 3 days a week/ 2 days WFH/remote). Key...SuggestedFull timeTemporary workWork experience placementRemote workWork from home3 days per week$317.5k - $365k
...payments, and cloud-native APIs. As VP, Global Head of Product Security & Risk, you will define and lead the enterprise framework that... ...of Product, Security, Compliance, Risk, Legal, Policy, and Engineering—translating complex regulatory and risk requirements into practical...SuggestedWorldwideFlexible hours- ...Protecting our members’ data and ensuring our systems scale securely and reliably is core to this mission.As a Director of Product Security you will play a critical role in shaping, driving, and leading our software engineering teams towards a secure software development...Work at officeRelocation
$78k - $80k
...Overview Northeast Security, Inc. was founded in 1967 and has grown to become one of the largest and most highly regarded security... ...Supervisor experience or equivalent field. Concierge Security Director Requirements: Must have three years of Security Account...Shift workNight shiftWeekend workAfternoon shift$165k - $185k
...keeps that platform fast, reliable, and secure. As Director of DevOps, Security & IT, you'll own... ...connected functions: DevOps & platform engineering first, then security & compliance,... ...governing AI systems for privacy and security risk. Own security and operational...Full timeRemote work- Klaviyo in Boston is seeking a Lead Security Governance & Risk Engineer, a senior, hands-on role where governance meets risk engineering. You will own parts of the risk programme turning policy into measured, automated risk decisions, report to Senior Manager, Security...
$100k - $164.1k
Zurich’s Property Risk Engineering team seeking a Senior Property Account Engineering consultant with highly protected risk (HPR) experience. This role will include account engineering responsibilities, depending on level of experience and workload. This is a work from...Temporary workWork at officeLocal areaRemote workWork from home$178.4k - $226.7k
The Senior Security Engineer is a senior individual contributor responsible for independently driving security initiatives across multiple services... ...exercises for complex distributed systems, identifying risks and recommending mitigationsManual Code Review: Conduct...InternshipFlexible hours$100k - $140k
Bitsight is a cyber risk management leader transforming how companies manage exposure,... ...solutions deliver value across enterprise security performance, digital supply chains, cyber... ...for a skilled and passionate Cybersecurity Engineer to strengthen and scale our security...Full timeRemote workFlexible hours$120k - $217.5k
...are looking forThe State Street Cyber Architecture & Engineering team is looking for a Head of Cloud Security Engineering. We deliver the tooling and solutions to... ...investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability...Full timeTemporary workWork experience placementFlexible hours- ...and solutions to customers and prospects. In your role, you will strive to provide an exceptional client experience while minimizing risk.Job Responsibilities: Collaborates with Business Relationship Managers-Acquisition (BRMs) and Business Development Managers (BDMs)...
$180k - $190k
...Boston, or New York office.About the DepartmentOur Investment Risk team safeguards the quality and performance of the firm’s fixed... ...RoleExperience, Education & CertificationsQuantitative undergrad (Engineering, Mathematics, Physics, etc.) with an MBA or PhD in Economics,...Full timeWork at officeLocal area- ...the mission of our organization. Job Purpose: Reporting to the Associate Chief Quality and Patient Safety Officer, the Senior Director of Risk Management and Patient Safety serves as a strategic leader for the enterprise-wide Risk Management and Patient Safety program....
$175k - $225k
...The Director, Investment Risk will establish a centralized investment risk function within the Enterprise Data & Analytics team. Building upon GW&K’s current investment risk management practices, this function will provide coordinated risk measurement, analytics, governance...Work at officeLocal areaRemote work1 day per week$127.6k - $206.53k
...outcomes.Job SummaryThe TeamInformation Security - We’re not your ordinary Information Security... ....Job SummaryAs a Staff Network Security Engineer on our Enterprise Security team, you will... ...vulnerabilities and data exposure risks in cloud and network environments using a...Full timeWork at officeVisa sponsorshipWork visa$210k - $234.1k
...few technology companies ever operate at.Security at Compass International HoldingsThe Security... ...estates in the industry. We are hands-on engineers who build security as a service: secure-... ...teams, offering security guidance and risk evaluations for new product features, development...Minimum wageWork experience placementFlexible hours$82.6k - $162.8k
...with resilience, grow with confidence, and proactively manage to secure success. Identity security market is undergoing a fundamental... ...Recruiting for this role ends on 12/31/2026.Work you'll doAs a Security Engineer II on the Deloitte Cyber Identity & Access Management team, you...Local areaVisa sponsorship- Draper is seeking a Director 2, Cyber Operations in Cambridge, MA to lead cyber operations within the CISO organization. You will oversee IT infrastructure security, budgets (~$15M), dashboards, and strategic IT framework development to support national security objectives...
$194.5k - $324.1k
...terminations.Participate in Community Bank activities/initiatives to drive cross-selling success.Adhere to applicable compliance/operational risk controls in accordance with Company or regulatory standards and policies.Promote an environment that supports belonging and reflects...Full timeWork experience placement$115k - $130k
...solutions that traditional providers cannot.ROLE OVERVIEWThe Manager, Risks Processes and Controls will take ownership of critical fund... ...package designed to support employees’ health, financial security, family needs, and overall well-being.Bain Capital is an equal...Full timeWork at officeFlexible hours$130k
...and define the people we want to join us on our journey.Managing, and may directing, the implementation and delivery of a range of risk services to support commissions and to provide line management leadership and guidance for others within the PMO and Planning centre...Full timePart timeFlexible hours- DescriptionThe Risk Manager supports the overall management of potential risks and liabilities within Brigham & Women’s Faulkner Hospital (BWFH) and promotes patient safety. This role works closely with hospital staff to assess potential risks from several sources - including...Work experience placementWork at office
$117k - $153k
Role SummaryAs a First Line Risk Senior Manager supporting the Treasury and Wholesale Payments division in Commercial Banking, you will... ..., and identifying emerging risks, escalating to the Senior Director/Director of First Line Risk where appropriate. You will work with...Local areaFlexible hours- ...Jade Biosciences is seeking a Director of Investor Relations to build and lead a high‑caliber IR function for a publicly traded biotech company. You will communicate Jade’s strategy, pipeline, clinical progress, and financial position to investors and analysts, translating...Remote job
$90k - $110k
As a First Line Risk Manager supporting the Treasury and Wholesale Payments division in Commercial Banking, you will serve as the primary execution lead for risk and control activities across assigned products, processes, and services for Treasury & Wholesale Payments...Local areaVisa sponsorshipFlexible hours$77k - $214k
Industry/SectorNot ApplicableSpecialismIFS - Risk & Quality (R&Q)Management LevelSenior AssociateJob Description & SummaryAt PwC, our... ...members. We evaluate these factors thoughtfully to establish a secure and trusted workplace for all.Applications will be accepted until...Full timeH1b- ...Boston, MABase Salary: $100k - $125kOverviewA leading, growth-oriented investment management firm is seeking an experienced operational risk professional to join its high-performing Risk and Control team. In this strategic role, you’ll work directly with senior leadership...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director of Security Risk Engineering. Be the first to apply!
- operational risk manager Boston, MA
- senior risk manager Boston, MA
- risk management manager Boston, MA
- risk management associate Boston, MA
- director of risk management Boston, MA
- director credit risk Boston, MA
- risk management specialist Boston, MA
- enterprise risk manager Boston, MA
- head of risk management Boston, MA
- principal network engineer Boston, MA



