Greenhouse ·
contractSenior Security Engineer, Detection & Response
Flexport · San Francisco, California, United States
About Flexport: At Flexport, we believe global trade can move the human race forward. That’s why it’s our mission to make global commerce so easy there will be more of it. We’re shaping the future of a $10T industry with solutions powered by innovative technology and exceptional people. Today, companies of all sizes—from emerging brands to Fortune 500s—use Flexport technology to move more than $19B of merchandise across 112 countries a year. The recent global supply chain crisis has put Flexport center stage as we continue to play a pivotal role in how goods move around the world. We are proud to have the support of the best investors in the game who believe in our mission, solutions and people. Ready to tackle global challenges that impact business, society, and the environment? Come join us. What you'll do There is no MSSP and no tier-1 queue here. Detection & Response engineers own their detections end to end: you write them, you tune them, and your team is paged when they fire. The security team is spread across the globe with a follow-the-sun pager rotation so nobody is paged at 3am local. The adversaries are real. The business is growing fast and the threat surface is growing with it. Defining the necessary telemetry is part of the job. Detection engineering Build and tune detections across endpoint, identity, SaaS, and cloud , treating them as software: version-controlled, peer-reviewed, and shipped through the same CI/CD practices the rest of engineering uses. Track detection quality as measured quantities : coverage against MITRE ATT&CK, precision, time-to-detect. We don’t build-and-forget here. Response & automation Own incident response: triage, contain, remediate, and write the retrospective that turns the incident into a systemic fix. Build automation that removes toil from investigations, and partner closely with the US-based team so context carries across time zones instead of getting lost at handoff. Telemetry & partnership Define telemetry requirements for new systems before they ship , working with infrastructure and product teams to close visibility gaps rather than discovering them during an incident. Threat hunt proactively across the estate , converting hypotheses into either new detections or documented coverage. You Should Have Typically 5–8 years of experience in detection engineering, incident response, or threat hunting, with real hands-on time writing and tuning detections. We care more about what you've built than the exact number. Proficiency in at least one programming language (Python, Go, or similar) and comfort writing production-grade detection and automation code. Experience with a modern SIEM or detection pipeline (Panther, Elastic, Splunk, or similar). What matters is that you've shipped and tuned detection logic in production. Practical incident response experience : you've led or played a major role in triaging and closing out real security incidents. Nice to have Experience treating detections as code with CI/CD, peer review, and staged rollout. Experience defining telemetry contracts for systems before they ship, rather than retrofitting logging after an incident. A track record of critically evaluating and verifying AI-assisted work - testing, source-checking, validation - rather than trusting agent output by default. If you haven’t already spotted the em dashes in this job description and already thought about where the hiring manager (hi!) has put hands on keyboard and compared that to where they let the LLM watermarks through, you might not be the right person for the job. Familiarity with cloud-native and Kubernetes telemetry. Experience with fraud or financial-crime detection patterns. How we work We're in the San Francisco office regularly to work through incidents and detection design in person. We stay closely aligned with teammates on other continents via Slack, video, and async docs. We have the latest hardware and software, including frontier AI models on day one. We're agile, but not dogmatic. Teams decide how they work best. Why this role is special You own your detections end to end, no MSSP, no tier-1 queue, no handing your work to someone else to triage. The consequences here are physical, not abstract: a containment decision can stop a customs filing or freight actually moving, which makes the stakes concrete in a way a SaaS control plane rarely is. You'll inherit a real, established estate with legacy telemetry gaps to close, genuinely underexplored surface area, not a well-mined problem. Where you'll work This role is based in San Francisco, and we have a strong preference for candidates who are there or willing to relocate — we're deliberately building this team in one place. Relocation support is available for the right candidate. Investing your time with Flexport means having immediate impact, all over the world. You're empowered to do what's best for everyone and trusted to make the right decisions when and where you need them. Join our colle
| Role | Senior Security Engineer, Detection & Response |
|---|---|
| Company | Flexport |
| Location | San Francisco, California, United States |
| Type | contract |
| Compensation | Not disclosed |
| Posted | 2026-09-17 |
| Deadline | Rolling |
Typical process for this type of role
A general guide — the exact steps for this specific listing may vary; check the original posting for details.
- 1ApplicationSubmit your resume through the apply link.
- 2ScreeningRecruiter reviews your background against the role.
- 3AssessmentA technical test, assignment, or coding round, depending on the role.
- 4Interview(s)One or more rounds with the hiring team.
- 5OfferOffer letter with compensation and start date.
Before you apply
0/4Senior Security Engineer, Detection & Response at Flexport: frequently asked questions
- What is the salary for this role?
- Flexport has not stated compensation in the listing. Check the original posting or ask during the application process.
- Is the Senior Security Engineer, Detection & Response position remote, hybrid or onsite?
- The listing gives San Francisco, California, United States as the location and does not state a work mode.
- What is the application deadline?
- Flexport has not listed a fixed deadline, so apply early in case the opening is filled.
- How do I apply for the Senior Security Engineer, Detection & Response role?
- Use the Apply button on this page. It opens the original listing on job-boards.greenhouse.io, where you submit your application with the company.
More at Flexport
Other jobs at Flexport
- HR Generalist · Mumbai
- Senior Manager, Supply Chain Protection & Loss Intelligence · Miami, Florida, United States
- Global Operations Associate - Ocean Freight · København, Capital Region of Denmark, Denmark
- Senior Software Engineer: Platform SRE · Amsterdam, Netherlands
- Customs Associate · Amsterdam, Netherlands
Explore Related Placements
// similar opportunities
You might also like
Senior Security Engineer, Detection & Response
Robinhood
Join us in building the future of finance. Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger gene...
['In-person attendance expected at least 3 days per week', '5+ years experience required']
Security Engineer - Detection And Response
Spotify
The Platform team creates the technology that enables Spotify to learn quickly and scale easily, enabling rapid growth in our users and our business around the ...
Staff Detection Engineer
Asana
Our Security team keeps Asana's employees, users, and customers safe by proactively addressing threats and fostering a culture of security across our product an...
Senior Software Engineer, Data Foundation
Mixpanel
About Mixpanel Mixpanel is the leading product intelligence and analytics platform, trusted by more than 29,000 companies to help understand how people use the ...
Senior Security Engineer - Remote
Parity
About Us Parity is one of the world’s most experienced companies building the core infrastructure behind blockchain — the system that allows information and val...
Senior Frontend Engineer
Gitlab
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency,...
0-1 year experience eligible.