# Security Engineer, Corporate Security

**Company**: Flexport
**Location**: San Francisco, California
**Work arrangement**: onsite
**Experience**: senior
**Job type**: full-time
**Salary**: $165,375-$202,125 USD
**Category**: Engineering
**Industry**: Technology

**Apply**: https://job-boards.greenhouse.io/flexport/jobs/8166038?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_6ee4e026-7c3

## Description

## Job Overview

As a Security Engineer in the Corporate Security team at Flexport, you will play a crucial role in advancing our security posture. Flexport is a leading player in global supply chain management, and we are looking for talented individuals to help us tackle global challenges that impact business, society, and the environment.

## Responsibilities

### Identity & Access

- Advance our identity posture by implementing SSO coverage, phishing-resistant MFA rollout, SCIM lifecycle automation, and least-privilege access across the SaaS and cloud estate.

- Develop detections and guardrails to prevent account takeover, MFA fatigue attacks, and session token theft.

### Endpoint & Device Lifecycle

- Write and deploy device policy as code, including configuration profiles, remediation scripts, and enforcement rules for macOS and Windows.

- Maintain and improve our EDR stack's detection and response coverage across the fleet.

### SaaS Posture

- Reduce SaaS risk at scale through SSPM tooling and automation, detecting risky OAuth grants, shadow IT, and configuration drift across critical SaaS applications.

- Own security configuration for SaaS tools used daily by Flexporters, such as Google Workspace and Slack.

### Automation & Enablement

- Automate tasks in corporate security, such as device provisioning, access reviews, and vendor security questionnaires.

- Create runbooks and documentation to empower the team and partner with IT and People teams to implement effective controls.

## Requirements

- Typically 2–5 years of experience in corporate, enterprise, or IT security engineering.

- Hands-on experience with modern endpoint management and EDR tooling (e.g., Jamf, Kandji, Intune, CrowdStrike, SentinelOne).

- Working knowledge of identity protocols (SAML, OIDC, SCIM) and a major identity provider (e.g., Okta, Entra, Google Workspace).

- Comfortable writing code or scripts (e.g., Python, Go) to automate tasks.

- Clear, practical communication skills.

## Nice to Have

- Experience with SSPM tooling and OAuth-grant governance.

- Exposure to DLP or insider-risk tooling.

- Familiarity with infrastructure-as-code (e.g., Terraform) for managing security configuration.

- Understanding of how agentic AI tools and MCP integrations impact corporate security.

## How We Work

- Regular work in the San Francisco office to collaborate on incidents and detection design.

- Close alignment with global teammates via Slack, video, and async documentation.

- Access to the latest hardware and software.

## Why This Role Is Special

- Broad ownership of well-defined projects from design to rollout.

- Immediate impact protecting all Flexporters with each device policy or identity control deployed.

- Part of PSI, where security is treated as infrastructure to build.

## Location

This role is based in San Francisco, with a strong preference for candidates willing to relocate.

## Salary

The US base salary range for this position is $165,375-$202,125 USD.

## Skills

### Required
- endpoint management
- EDR tooling
- identity protocols
- scripting
- communication skills

### Nice to have
- SSPM tooling
- OAuth-grant governance
- DLP
- insider-risk tooling
- infrastructure-as-code

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/flexport/jobs/8166038?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
