SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Engineer, Corporate Security

Flexport - San Francisco, CA, United States - Hybrid - posted 2026-08-31

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Flexport is a global commerce platform that moves over $19B in merchandise annually across 112 countries. This Security Engineer role sits within Corporate Security (PSI team) and focuses on building and scaling identity, endpoint, and SaaS security controls across the organization. Key responsibilities include: **Identity & Access Management**: Advance Flexport's identity posture by expanding SSO coverage, rolling out phishing-resistant MFA, automating SCIM lifecycle management, and implementing least-privilege access across SaaS and cloud infrastructure. Build detections and guardrails to catch account takeover, MFA fatigue attacks, and session token theft before they escalate into incidents. **Endpoint & Device Lifecycle**: Write and deploy device policy as code (configuration profiles, remediation scripts, enforcement rules) for macOS and Windows with staged rollout and rollback capabilities. Maintain and improve the EDR stack's detection and response coverage across the entire fleet. **SaaS Security Posture**: Reduce SaaS risk at scale using SSPM tooling and automation to detect risky OAuth grants, shadow IT, and configuration drift. Own security configuration for widely-used SaaS tools (Google Workspace, Slack, etc.) and adapt as the company integrates AI agents and MCP tools. **Automation & Enablement**: Automate repetitive corporate security work—device provisioning, access reviews, vendor questionnaires—so the team scales efficiently. Write runbooks and documentation that empower teammates and partner with IT and People teams to ship controls that don't create friction. You'll have broad, end-to-end ownership of well-defined projects from design through rollout. Every control you ship protects all Flexporters immediately. The team works hybrid from San Francisco with distributed collaboration across continents, using the latest hardware and frontier AI tools. Required: 2–5 years in corporate, enterprise, or IT security engineering; hands-on experience with modern endpoint management and EDR tools (Jamf, Kandji, Intune, CrowdStrike, SentinelOne); working knowledge of identity protocols (SAML, OIDC, SCIM) and major identity providers (Okta, Entra, Google Workspace); comfort writing code/scripts (Python, Go) to automate manual work; clear communication across technical and non-technical audiences. Nice-to-have: SSPM tooling experience, DLP/insider-risk exposure, infrastructure-as-code (Terraform), perspective on agentic AI and MCP security implications, interest in growing into broader corporate security or detection engineering.

Similar roles