Description
Job Overview
As a Security Engineer in the Corporate Security team at Flexport, you will play a crucial role in advancing our security posture. Flexport is a leading player in global supply chain management, and we are looking for talented individuals to help us tackle complex challenges that impact business, society, and the environment.
Responsibilities
Identity & Access
- Advance our identity posture by implementing SSO coverage, phishing-resistant MFA rollout, SCIM lifecycle automation, and least-privilege access across the SaaS and cloud estate.
- Develop detections and guardrails to prevent account takeover, MFA fatigue attacks, and session token theft.
Endpoint & Device Lifecycle
- Write and deploy device policy as code, including configuration profiles, remediation scripts, and enforcement rules for macOS and Windows.
- Maintain and improve our EDR stack's detection and response coverage across the fleet.
SaaS Posture
- Reduce SaaS risk at scale through SSPM tooling and automation, detecting risky OAuth grants, shadow IT, and configuration drift across critical SaaS applications.
- Own security configuration for SaaS tools used daily by Flexporters, such as Google Workspace and Slack.
Automation & Enablement
- Automate tasks in corporate security that don't require human intervention, such as device provisioning and access reviews.
- Create runbooks and documentation to enhance team capabilities and collaborate with IT and People teams to implement controls.
Requirements
- Typically 2-5 years of experience in corporate, enterprise, or IT security engineering.
- Hands-on experience with modern endpoint management and EDR tooling (e.g., Jamf, Kandji, Intune, CrowdStrike, SentinelOne).
- Working knowledge of identity protocols (SAML, OIDC, SCIM) and a major identity provider (e.g., Okta, Entra, Google Workspace).
- Proficiency in writing code or scripts (e.g., Python, Go) to automate tasks.
- Excellent communication skills, with the ability to explain technical concepts to non-technical stakeholders.
Nice to Have
- Experience with SSPM tooling and OAuth-grant governance.
- Exposure to DLP or insider-risk tooling.
- Familiarity with infrastructure-as-code (e.g., Terraform) for managing security configuration.
- Understanding of how agentic AI tools and MCP integrations impact corporate security.
How We Work
- Regular work in the San Francisco office to collaborate on incidents and detection design.
- Close alignment with teammates across other continents via Slack, video, and async documentation.
- Access to the latest hardware and software, including frontier AI models.
- Agile approach to work, with flexibility in team workflows.
Why This Role Is Special
- Broad ownership of well-defined projects from design through rollout.
- Immediate impact of your work, protecting all Flexporters.
- Collaboration with platform and infrastructure engineers.
Compensation
The salary ranges for this position vary by location:
- California: $165,375 - $202,125 USD
- Washington: $147,000 - $183,750 USD
- Colorado: $130,950 - $163,688 USD
- New York City: $147,000 - $183,750 USD
- Illinois: $130,950 - $163,688 USD
Our total rewards package also includes bonus, equity, and comprehensive benefits such as medical, dental, and flexible time off.
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://job-boards.greenhouse.io/flexport/jobs/8166040