Flexport logo
Flexport
Posted 34 days agoVerified live 22h ago

Security Engineer, Corporate Security

Brief overview

Remote
$165k–$202k/yrStated range
162 H-1B approvalsDept. of Labor
11 green cardsCertified filings
Endpoint Management and EDR JamfEndpoint Management and EDR KandjiEndpoint Management and EDR IntuneEndpoint Management and EDR CrowdStrikeEndpoint Management and EDR SentinelOneIdentity Protocols SAMLIdentity Protocols OIDCIdentity Protocols SCIMIdentity Providers OktaIdentity Providers EntraIdentity Providers Google WorkspacePythonGoSSPM and OAuth-Grant GovernanceData Loss Prevention (DLP)Terraform

About the company

Flexport logo
Flexportflexport.com

Flexport is a full-service global freight forwarder and logistics platform using modern software to fix the user experience in global trade.

Visa sponsorship history

4 years sponsoring, last filed FY2026

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
162H-1B approved
98%approval rate
48new H-1B hires
11PERM certified
$187,425median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
2023106
202422
202528
20266
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
202314
202411
20254
20268
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
20235
20241
20255
Top sponsored roles
Software EngineerSenior Software EngineerStaff Software EngineerSenior Network EngineerAccounting Manager
Sponsored employees from
IndiaChina

Job description

Summary

Flexport is a technology company focused on making global commerce easier through innovative solutions. The Security Engineer will own and deliver corporate security projects across identity and access, endpoint and device lifecycle, SaaS posture, detection and response, and security automation.

Responsibilities

  • Advance our identity posture: SSO coverage, phishing-resistant MFA rollout, SCIM lifecycle automation, and least-privilege access across the SaaS and cloud estate
  • Build the detections and guardrails that catch account takeover, MFA fatigue attacks, and session token theft before they turn into incidents
  • Write and ship device policy as code — configuration profiles, remediation scripts, and enforcement rules across macOS and Windows — with staged rollout and rollback built in from day one
  • Maintain and improve our EDR stack's detection and response coverage across the fleet
  • Reduce SaaS risk at scale through SSPM tooling and automation, including detection of risky OAuth grants, shadow IT, and configuration drift across our critical SaaS applications
  • Own security configuration for the SaaS tools hundreds of Flexporters use daily (Google Workspace, Slack, and similar), and keep pace as we add AI agents and MCP integrations to that surface
  • Automate the parts of corporate security that don't need a human — device provisioning, access reviews, vendor security questionnaires — so the team scales with headcount instead of straining against it
  • Write runbooks and documentation that make the rest of the team more capable, and partner with IT and People teams to ship controls that don't create the friction that drives people to workarounds

Skills

  • Typically **2–5 years of experience** in corporate, enterprise, or IT security engineering — we care more about what you've shipped than the exact number. If you meet most of this, apply; we'd rather see your work than filter you out on a résumé line
  • **Hands-on experience with modern endpoint management and EDR tooling** (Jamf, Kandji, Intune, CrowdStrike, SentinelOne, or similar)
  • **Working knowledge of identity protocols** (SAML, OIDC, SCIM) and a major identity provider (Okta, Entra, Google Workspace, or similar)
  • **Comfort writing real code or scripts** (Python, Go, or similar) to replace manual, ticket-driven work with automation
  • **Clear, practical communicator** who can explain a control tradeoff to an engineer, a salesperson, and a VP without changing the facts
  • Experience with SSPM tooling and OAuth-grant governance
  • Exposure to DLP or insider-risk tooling
  • Familiarity with infrastructure-as-code (Terraform) for managing security configuration
  • A point of view on how agentic AI tools and MCP integrations change what corporate security needs to watch for
  • Interest in growing into a broader corporate security or detection engineering scope over time

Qualifications

Must Haves

  • Typically **2–5 years of experience** in corporate, enterprise, or IT security engineering — we care more about what you've shipped than the exact number. If you meet most of this, apply; we'd rather see your work than filter you out on a résumé line
  • **Hands-on experience with modern endpoint management and EDR tooling** (Jamf, Kandji, Intune, CrowdStrike, SentinelOne, or similar)
  • **Working knowledge of identity protocols** (SAML, OIDC, SCIM) and a major identity provider (Okta, Entra, Google Workspace, or similar)
  • **Comfort writing real code or scripts** (Python, Go, or similar) to replace manual, ticket-driven work with automation
  • **Clear, practical communicator** who can explain a control tradeoff to an engineer, a salesperson, and a VP without changing the facts

Nice to Haves

  • Experience with SSPM tooling and OAuth-grant governance
  • Exposure to DLP or insider-risk tooling
  • Familiarity with infrastructure-as-code (Terraform) for managing security configuration
  • A point of view on how agentic AI tools and MCP integrations change what corporate security needs to watch for
  • Interest in growing into a broader corporate security or detection engineering scope over time

Benefits

  • Bonus
  • Equity
  • Medical
  • Dental
  • Flexible time off
  • The latest hardware and software, including frontier AI models on day one

More jobs like this