# Senior Security Engineer, Detection & Response

**Company**: Flexport
**Location**: San Francisco, California
**Work arrangement**: onsite
**Experience**: senior
**Job type**: full-time
**Salary**: $183,272-$229,091 USD
**Category**: Engineering
**Industry**: Technology

**Apply**: https://job-boards.greenhouse.io/flexport/jobs/8160833?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_0fc3c580-93c

## Description

## Job Overview

We are looking for a Senior Security Engineer to join our Detection & Response team at Flexport. As a Senior Security Engineer, you will own detections end-to-end, from writing and tuning them to handling incidents and implementing automation.

## Responsibilities

### Detection Engineering

- Build and tune detections across endpoint, identity, SaaS, and cloud, using version control, peer review, and CI/CD practices.

- Track detection quality metrics such as coverage against MITRE ATT&CK, precision, and time-to-detect.

### Response & Automation

- Own incident response processes, including triage, containment, remediation, and writing retrospectives.

- Develop automation to streamline investigations and collaborate with the US-based team.

### Telemetry & Partnership

- Define telemetry requirements for new systems, working with infrastructure and product teams.

- Proactively threat hunt across the estate, converting hypotheses into new detections or documented coverage.

## Requirements

- Typically 5–8 years of experience in detection engineering, incident response, or threat hunting.

- Proficiency in at least one programming language (Python, Go, or similar).

- Experience with a modern SIEM or detection pipeline (Panther, Elastic, Splunk, or similar).

- Practical incident response experience.

## Nice to Have

- Experience treating detections as code with CI/CD, peer review, and staged rollout.

- Experience defining telemetry contracts for systems before they ship.

- Familiarity with cloud-native and Kubernetes telemetry.

- Experience with fraud or financial-crime detection patterns.

## How We Work

- Regular work in the San Francisco office.

- Collaboration with global teammates via Slack, video, and async docs.

- Access to the latest hardware and software.

## Why This Role Is Special

- End-to-end ownership of detections.

- Concrete consequences of your work impacting global trade.

- Opportunity to work on an established estate with legacy telemetry gaps.

## Location

This role is based in San Francisco, with a strong preference for candidates willing to relocate.

## Salary Range

The US base salary range for this position is $183,272-$229,091 USD.

## Skills

### Required
- detection engineering
- incident response
- threat hunting
- programming languages (Python, Go)
- SIEM or detection pipeline (Panther, Elastic, Splunk)

### Nice to have
- treating detections as code with CI/CD
- defining telemetry contracts
- cloud-native and Kubernetes telemetry
- fraud or financial-crime detection patterns

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/flexport/jobs/8160833?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
