Enter a job title or keyword

Security Engineer, Corporate Security

Flexport


Job Location:

San Francisco, CA - USA

Hourly Salary: USD 10 - 10
Posted: 2 September 2026 (10 hours ago)
Application Deadline: 30 November 2026
Vacancies: 1 Vacancy

Job Summary

About Flexport:

At Flexport we believe global trade can move the human race forward. Thats why its our mission to make global commerce so easy there will be more of it. Were shaping the future of a $10T industry with solutions powered by innovative technology and exceptional people. Today companies of all sizesfrom emerging brands to Fortune 500suse Flexport technology to move more than $19B of merchandise across 112 countries a year.

The recent global supply chain crisis has put Flexport center stage as we continue to play a pivotal role in how goods move around the world. We are proud to have the support of the best investors in the game who believe in our mission solutions and people. Ready to tackle global challenges that impact business society and the environment Come join us.

What youll do
  • Identity & access
    • Advance our identity posture: SSO coverage phishing-resistant MFA rollout SCIM lifecycle automation and least-privilege access across the SaaS and cloud estate.
    • Build the detections and guardrails that catch account takeover MFA fatigue attacks and session token theft before they turn into incidents.
  • Endpoint & device lifecycle
    • Write and ship device policy as code configuration profiles remediation scripts and enforcement rules across macOS and Windows with staged rollout and rollback built in from day one.
    • Maintain and improve our EDR stacks detection and response coverage across the fleet.
  • SaaS posture
    • Reduce SaaS risk at scale through SSPM tooling and automation including detection of risky OAuth grants shadow IT and configuration drift across our critical SaaS applications.
    • Own security configuration for the SaaS tools hundreds of Flexporters use daily (Google Workspace Slack and similar) and keep pace as we add AI agents and MCP integrations to that surface.
  • Automation & enablement
    • Automate the parts of corporate security that dont need a human device provisioning access reviews vendor security questionnaires so the team scales with headcount instead of straining against it.
    • Write runbooks and documentation that make the rest of the team more capable and partner with IT and People teams to ship controls that dont create the friction that drives people to workarounds.
You should have
  • Typically 25 years of experience in corporate enterprise or IT security engineering we care more about what youve shipped than the exact number. If you meet most of this apply; wed rather see your work than filter you out on a résumé line.
  • Hands-on experience with modern endpoint management and EDR tooling (Jamf Kandji Intune CrowdStrike SentinelOne or similar).
  • Working knowledge of identity protocols (SAML OIDC SCIM) and a major identity provider (Okta Entra Google Workspace or similar).
  • Comfort writing real code or scripts (Python Go or similar) to replace manual ticket-driven work with automation.
  • Clear practical communicator who can explain a control tradeoff to an engineer a salesperson and a VP without changing the facts.
Nice to have
  • Experience with SSPM tooling and OAuth-grant governance.
  • Exposure to DLP or insider-risk tooling.
  • Familiarity with infrastructure-as-code (Terraform) for managing security configuration.
  • A point of view on how agentic AI tools and MCP integrations change what corporate security needs to watch for
  • Interest in growing into a broader corporate security or detection engineering scope over time.
How we work
  • Were in the San Francisco office regularly to work through incidents and detection design in person.
  • We stay closely aligned with teammates on other continents via Slack video and async docs.
  • We have the latest hardware and software including frontier AI models on day one.
  • Were agile but not dogmatic. Teams decide how they work best.
Why this role is special
  • Broad real ownership: at this level elsewhere you might own a slice of a control; here youll own well-defined projects end to end from design through rollout with support scoping the ambiguous parts.
  • Every device policy or identity control you ship protects every Flexporter immediately no six-month rollout to a subset of customers.
  • Youre part of PSI: security is treated as infrastructure to build not policy to enforce and platform and infrastructure engineers are a Slack message away.
Where youll work

This role is based in San Francisco and we have a strong preference for candidates who are there or willing to relocate were deliberately building this team in one place. Relocation support is available for the right candidate.

Investing your time with Flexport means having immediate impact all over the world. Youre empowered to do whats best for everyone and trusted to make the right decisions when and where you need them. Join our collective of entrepreneurs and improve the worlds experience in global trade.

#LI-Onsite

The range displayed on each job posting reflects the minimum and maximum target for new hire base salary for the position in the postings respective region. Our salary ranges are determined by role level and location. Within the range displayed individual pay is determined by work location and additional factors including job-related skills experience and relevant education and / or training. Base salary is just one part of our total rewards package at Flexport which also includes bonus equity and comprehensive benefit offerings such as medical dental and flexible time off.

The US base salary range for this position (this does not include bonus equity and benefits):

$165375 - $202125 USD

Commitment to Equal Opportunity

At Flexport our ability to fulfill our mission of making global commerce easy and accessible relies on having a diverse dedicated and engaged workforce. All qualified applicants will receive consideration for employment regardless of race color religion sex national origin age physical and mental disability health status marital and family status sexual orientation gender identity and expression military and veteran status and any other characteristic protected by applicable law.

Global Data Privacy Notice for Job Candidates and Applicants

Depending on your location the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job submitting your application you are agreeing to our use and processing of your data as required. Please see our Privacy Notice available at additional information.


Required Experience:

IC


About Company

Company Logo

Cut costs, automate workflows, reliably move goods, go carbon-neutral, and improve your supply chain from end to end. It all starts here.

View Profile View Profile