SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Security Engineer, Detection & Response

Flexport - San Francisco, CA, United States - Hybrid - posted 2026-08-28

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Flexport is a global commerce platform that moves over $19B in merchandise annually across 112 countries. This Senior Security Engineer role focuses on detection engineering and incident response within a distributed security team operating on a follow-the-sun pager rotation. You will own detection engineering end-to-end: building and tuning detections across endpoint, identity, SaaS, and cloud infrastructure using modern SIEM platforms. Detections are treated as software with version control, peer review, and CI/CD practices. You'll track detection quality metrics including MITRE ATT&CK coverage, precision, and time-to-detect, ensuring continuous improvement rather than build-and-forget approaches. Incident response responsibilities include triaging, containing, and remediating security incidents, then writing retrospectives that drive systemic fixes. You'll build automation to reduce investigation toil and partner with the US-based team to maintain context across time zones. Telemetry and partnership work involves defining telemetry requirements for new systems before they ship, collaborating with infrastructure and product teams to close visibility gaps proactively. You'll conduct threat hunting across the estate, converting hypotheses into new detections or documented coverage. The role requires 5–8 years of hands-on experience in detection engineering, incident response, or threat hunting. You must be proficient in at least one programming language (Python, Go, or similar) and have practical experience with modern SIEMs like Panther, Elastic, or Splunk. Real incident response experience leading or playing major roles in triaging and closing security incidents is essential. Nice-to-have skills include treating detections as code with CI/CD practices, defining telemetry contracts upfront, experience with cloud-native and Kubernetes telemetry, and familiarity with fraud or financial-crime detection patterns. The posting notably values critical evaluation of AI-assisted work, testing, source-checking, and validation rather than blind trust in agent output. The team works regularly in the San Francisco office for incident response and detection design collaboration, with global alignment via Slack, video, and async documentation. You'll have access to latest hardware, software, and frontier AI models. The role offers concrete stakes: containment decisions directly impact customs filings and freight movement, making security decisions tangible rather than abstract.

Similar roles