Skip to content
FlexportFlexport

Product Security Engineer II

Build secure-by-default tooling, guardrails, and developer enablement practices while conducting threat modeling, code reviews, vulnerability triage, and remediation support. The role requires 2–5 years of product or application security experience, web security expertise, programming knowledge, cloud familiarity, and SAST experience.

About the job

Responsibilities

Strategy & Foundations

  • Build guardrails and AI-accelerated patterns that make secure-by-default the path of least resistance for developers.
  • Build and maintain security tooling and automation that scales product security.
  • Respond to emerging threats.

Design-Time & Review

  • Contribute to threat modeling, design reviews, and code reviews with pragmatic guidance that balances risk against velocity.
  • Partner with engineering to security-review and test new features and services as they are built.

Vulnerability Management

  • Triage, reproduce, and validate incoming bug bounty submissions and internal security reports.
  • Prioritize real issues amid SAST, secrets, and vulnerability-scanner noise, and guide developers toward effective fixes.
  • Partner with development teams to drive remediation and track issues through closure.

Developer Enablement

  • Write clear, actionable security patterns that let developers ship quickly and securely.
  • Write and maintain runbooks, developer guidelines, and security documentation that scale team practices.
  • Stay current on web and cloud security trends and bring new findings into product discussions.

Requirements

  • 2–5 years of experience in product/application security or software development with a security focus.
  • Strong grasp of web application security principles and common attack vectors, including the OWASP Top 10.
  • Proficiency with application-testing tools such as Burp Suite, OWASP ZAP, or browser developer tools.
  • Working knowledge of at least one modern programming language, such as Ruby, Java/Kotlin, TypeScript/JavaScript, or Python.
  • Working knowledge of at least one major cloud provider: AWS, Google Cloud, or Azure.
  • Hands-on experience with SAST tools such as Cycode, Semgrep, Snyk, or similar.
  • Experience improving security-focused developer experience without slowing teams down.
  • Clear, constructive communication of technical risk in writing, code review, and conversation.
  • Collaborative approach with developers, SREs, and security peers.
  • Comfort with a security on-call rotation and work across security disciplines.

Nice to Have

  • Hands-on experience with bug bounty platforms.
  • Experience with cloud infrastructure security and container technologies.
  • Participation in CTF events or open-source security projects.
  • Familiarity with threat-modeling frameworks and secure SDLC best practices.
  • Interest in contributing to internal developer security training programs.

Work Arrangement

  • Amsterdam office attendance three times per week.
  • Collaboration with coworkers on other continents.

Compensation & Benefits

  • Catered lunches, breakfast, snacks, and soft drinks at the office.
  • Commuting-cost coverage for employees living outside Amsterdam.
  • 25 vacation days based on full-time employment.
  • Collective health insurance with Flexport-paid monthly premiums.
  • Defined pension contribution scheme.
  • Equity program.
  • Employee Assistance Program through Aetna Resources for Living.
  • Parental leave benefit.

Skills

Owasp Top 10, Burp Suite, Owasp Zap, Ruby, Java, Kotlin, TypeScript, JavaScript, Python, AWS, GCP, Azure, Cycode, Semgrep, Snyk

Supabase

Supabase

Remote

Platform Security Engineer
No salary listedRemote5+ YOESecurity Engineering

Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.

Vanta

Vanta

Remote

Manager, Security Operations
$178k+/yrRemote5+ YOESecurity Engineering

Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.

Monarch

Monarch

Remote

Senior Security GRC Analyst
$180k+/yrRemote5+ YOESecurity Engineering

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.

Wiz

Wiz

Berlin, Germany
Security Engineer - Product
No salary listedOn-site7+ YOESecurity Engineering

Security Engineer responsible for threat modeling, security reviews, vulnerability management, cloud and Kubernetes security, and detection and response across products and production infrastructure. Requires 7+ years of cloud security experience and hands-on expertise with IAM, infrastructure as code, automation, and security tooling.

Vanta

Vanta

Remote

Lead Product GRC Subject Matter Expert
$230k+/yrRemote10+ YOESecurity Engineering

Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.