Security Engineer, Corporate SecurityActive$165K

The opportunity

At Flexport, we believe global trade can move the human race forward. That’s why it’s our mission to make global commerce so easy there will be more of it.

What you'll do

  • Identity & access Advance our identity posture: SSO coverage,: phishing-resistant MFA rollout, SCIM lifecycle automation, and least-privilege access across the SaaS and cloud estate.

  • Build the detections and guardrails that catch account takeover, MFA fatigue: attacks, and session token theft before they turn into incidents.

  • Endpoint & device lifecycle Write and ship device policy as code —: configuration profiles, remediation scripts, and enforcement rules across macOS and Windows — with staged rollout and rollback built in from day one.

  • Maintain and improve our EDR stack's detection and response coverage across the fleet.

  • SaaS posture Reduce SaaS risk at scale through SSPM tooling and automation: , including detection of risky OAuth grants, shadow IT, and configuration drift across our critical SaaS applications.

  • Own security configuration for the SaaS tools hundreds of Flexporters use: daily (Google Workspace, Slack, and similar), and keep pace as we add AI agents and MCP integrations to that surface.

What they're looking for

  • Automation & enablement Automate the parts of corporate security that don't: need a human — device provisioning, access reviews, vendor security questionnaires — so the team scales with headcount instead of straining against it.
  • Write runbooks and documentation that make the rest of the team more capable: , and partner with IT and People teams to ship controls that don't create the friction that drives people to workarounds.