Description
Job Overview
As a Security Engineer in the Corporate Security team at Flexport, you will play a crucial role in advancing our security posture. Flexport is a leading player in global supply chain management, and we are looking for talented individuals to help us tackle global challenges that impact business, society, and the environment.
Responsibilities
Identity & Access
- Advance our identity posture by implementing SSO coverage, phishing-resistant MFA rollout, SCIM lifecycle automation, and least-privilege access across the SaaS and cloud estate.
- Develop detections and guardrails to prevent account takeover, MFA fatigue attacks, and session token theft.
Endpoint & Device Lifecycle
- Write and deploy device policy as code, including configuration profiles, remediation scripts, and enforcement rules for macOS and Windows.
- Maintain and improve our EDR stack's detection and response coverage across the fleet.
SaaS Posture
- Reduce SaaS risk at scale through SSPM tooling and automation, detecting risky OAuth grants, shadow IT, and configuration drift across critical SaaS applications.
- Own security configuration for SaaS tools used daily by Flexporters, such as Google Workspace and Slack.
Automation & Enablement
- Automate tasks in corporate security, such as device provisioning, access reviews, and vendor security questionnaires.
- Create runbooks and documentation to empower the team and partner with IT and People teams to implement effective controls.
Requirements
- Typically 2–5 years of experience in corporate, enterprise, or IT security engineering.
- Hands-on experience with modern endpoint management and EDR tooling (e.g., Jamf, Kandji, Intune, CrowdStrike, SentinelOne).
- Working knowledge of identity protocols (SAML, OIDC, SCIM) and a major identity provider (e.g., Okta, Entra, Google Workspace).
- Comfortable writing code or scripts (e.g., Python, Go) to automate tasks.
- Clear, practical communication skills.
Nice to Have
- Experience with SSPM tooling and OAuth-grant governance.
- Exposure to DLP or insider-risk tooling.
- Familiarity with infrastructure-as-code (e.g., Terraform) for managing security configuration.
- Understanding of how agentic AI tools and MCP integrations impact corporate security.
How We Work
- Regular work in the San Francisco office to collaborate on incidents and detection design.
- Close alignment with global teammates via Slack, video, and async documentation.
- Access to the latest hardware and software.
Why This Role Is Special
- Broad ownership of well-defined projects from design to rollout.
- Immediate impact protecting all Flexporters with each device policy or identity control deployed.
- Part of PSI, where security is treated as infrastructure to build.
Location
This role is based in San Francisco, with a strong preference for candidates willing to relocate.
Salary
The US base salary range for this position is $165,375-$202,125 USD.
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://job-boards.greenhouse.io/flexport/jobs/8166038