Flexport

Security Engineer, Corporate Security

Flexport$165K — $202K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 2-5 years in corporate or IT security engineering, focusing on shipped products rather than tenure.
  • Hands-on experience with endpoint management and EDR tools like Jamf, Intune, or CrowdStrike.
  • Knowledge of identity protocols including SAML and OIDC, and familiarity with identity providers such as Okta.
  • Ability to write scripts in languages like Python or Go for automation purposes.
  • Strong communication skills to convey complex information across technical and non-technical audiences.

Responsibilities

  • Advance identity security measures through SSO, MFA, and least-privilege access.
  • Develop detection mechanisms to prevent account takeovers and session token thefts.
  • Create and enforce device management policies for macOS and Windows systems.
  • Enhance detection and response capabilities in the EDR environment.
  • Automate risk reduction in SaaS applications and manage security configurations for essential tools.
  • Write comprehensive runbooks and documentation to improve team efficiency and coordination.
  • Collaborate with IT and People teams to ensure smooth implementation of security controls.

Benefits

  • Opportunity for immediate global impact within the organization.
  • Support for relocation to the San Francisco office.
  • Access to cutting-edge hardware and software, including AI models.
  • A flexible and agile workflow environment designed by teams themselves.
Full Job Description
What you'll do
  • Identity & access
    • Advance our identity posture: SSO coverage, phishing-resistant MFA rollout, SCIM lifecycle automation, and least-privilege access across the SaaS and cloud estate.
    • Build the detections and guardrails that catch account takeover, MFA fatigue attacks, and session token theft before they turn into incidents.
  • Endpoint & device lifecycle
    • Write and ship device policy as code - configuration profiles, remediation scripts, and enforcement rules across macOS and Windows - with staged rollout and rollback built in from day one.
    • Maintain and improve our EDR stack's detection and response coverage across the fleet.
  • SaaS posture
    • Reduce SaaS risk at scale through SSPM tooling and automation, including detection of risky OAuth grants, shadow IT, and configuration drift across our critical SaaS applications.
    • Own security configuration for the SaaS tools hundreds of Flexporters use daily (Google Workspace, Slack, and similar), and keep pace as we add AI agents and MCP integrations to that surface.
  • Automation & enablement
    • Automate the parts of corporate security that don't need a human - device provisioning, access reviews, vendor security questionnaires - so the team scales with headcount instead of straining against it.
    • Write runbooks and documentation that make the rest of the team more capable, and partner with IT and People teams to ship controls that don't create the friction that drives people to workarounds.
You should have
  • Typically 2-5 years of experience in corporate, enterprise, or IT security engineering - we care more about what you've shipped than the exact number. If you meet most of this, apply; we'd rather see your work than filter you out on a résumé line.
  • Hands-on experience with modern endpoint management and EDR tooling (Jamf, Kandji, Intune, CrowdStrike, SentinelOne, or similar).
  • Working knowledge of identity protocols (SAML, OIDC, SCIM) and a major identity provider (Okta, Entra, Google Workspace, or similar).
  • Comfort writing real code or scripts (Python, Go, or similar) to replace manual, ticket-driven work with automation.
  • Clear, practical communicator who can explain a control tradeoff to an engineer, a salesperson, and a VP without changing the facts.
Nice to have
  • Experience with SSPM tooling and OAuth-grant governance.
  • Exposure to DLP or insider-risk tooling.
  • Familiarity with infrastructure-as-code (Terraform) for managing security configuration.
  • A point of view on how agentic AI tools and MCP integrations change what corporate security needs to watch for
  • Interest in growing into a broader corporate security or detection engineering scope over time.
How we work
  • We're in the San Francisco office regularly to work through incidents and detection design in person.
  • We stay closely aligned with teammates on other continents via Slack, video, and async docs.
  • We have the latest hardware and software, including frontier AI models on day one.
  • We're agile, but not dogmatic. Teams decide how they work best.
Why this role is special
  • Broad, real ownership: at this level elsewhere you might own a slice of a control; here you'll own well-defined projects end to end, from design through rollout, with support scoping the ambiguous parts.
  • Every device policy or identity control you ship protects every Flexporter, immediately - no six-month rollout to a subset of customers.
  • You're part of PSI: security is treated as infrastructure to build, not policy to enforce, and platform and infrastructure engineers are a Slack message away.
Where you'll work

This role is based in San Francisco, and we have a strong preference for candidates who are there or willing to relocate - we're deliberately building this team in one place. Relocation support is available for the right candidate.

Investing your time with Flexport means having immediate impact, all over the world. You're empowered to do what's best for everyone and trusted to make the right decisions when and where you need them. Join our collective of entrepreneurs and improve the world's experience in global trade.

#LI-Onsite

The range displayed on each job posting reflects the minimum and maximum target for new hire base salary for the position in the posting's respective region. Our salary ranges are determined by role, level, and location. Within the range displayed, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education and / or training. Base salary is just one part of our total rewards package at Flexport, which also includes bonus, equity, and comprehensive benefit offerings such as medical, dental, and flexible time off.

The US base salary range for this position (this does not include bonus, equity and benefits):

$165,375-$202,125 USD

About Flexport

Flexport is a freight forwarding and customs brokerage company headquartered in San Francisco, California. It was founded in 2013 by Ryan Petersen and has since grown to become one of the leading companies in the industry. Flexport provides a wide range of logistics services, including air and ocean freight, customs brokerage, and supply chain management. The company uses technology to streamline the shipping process and provide real-time visibility into shipments. Flexport is committed to providing high-quality service and has received numerous awards and recognitions for its efforts. The company is also actively involved in the communities it serves, supporting a variety of local organizations and initiatives.
Learn more about Flexport
Size
2,000 employees
Industry
Founded
2013

Similar Jobs

More Jobs at Flexport

More Information Technology Jobs

Find similar Security Engineer, Corporate Security jobs: