# Product Security Engineer II

**Company:** [Flexport](https://hotfix.jobs/companies/flexport)
**Location:** Amsterdam, Netherlands
**Role:** Security Engineering
**Experience:** 2+ years
**Skills:** Owasp Top 10, Burp Suite, Owasp Zap, Ruby, Java, Kotlin, TypeScript, JavaScript, Python, AWS, GCP, Azure, Cycode, Semgrep, Snyk
**Posted:** 2026-07-09

> Build secure-by-default tooling, guardrails, and developer enablement practices while conducting threat modeling, code reviews, vulnerability triage, and remediation support. The role requires 2–5 years of product or application security experience, web security expertise, programming knowledge, cloud familiarity, and SAST experience.

## Job Description

## Responsibilities

### Strategy & Foundations
- Build guardrails and AI-accelerated patterns that make secure-by-default the path of least resistance for developers.
- Build and maintain security tooling and automation that scales product security.
- Respond to emerging threats.

### Design-Time & Review
- Contribute to threat modeling, design reviews, and code reviews with pragmatic guidance that balances risk against velocity.
- Partner with engineering to security-review and test new features and services as they are built.

### Vulnerability Management
- Triage, reproduce, and validate incoming bug bounty submissions and internal security reports.
- Prioritize real issues amid SAST, secrets, and vulnerability-scanner noise, and guide developers toward effective fixes.
- Partner with development teams to drive remediation and track issues through closure.

### Developer Enablement
- Write clear, actionable security patterns that let developers ship quickly and securely.
- Write and maintain runbooks, developer guidelines, and security documentation that scale team practices.
- Stay current on web and cloud security trends and bring new findings into product discussions.

## Requirements

- 2–5 years of experience in product/application security or software development with a security focus.
- Strong grasp of web application security principles and common attack vectors, including the OWASP Top 10.
- Proficiency with application-testing tools such as Burp Suite, OWASP ZAP, or browser developer tools.
- Working knowledge of at least one modern programming language, such as Ruby, Java/Kotlin, TypeScript/JavaScript, or Python.
- Working knowledge of at least one major cloud provider: AWS, Google Cloud, or Azure.
- Hands-on experience with SAST tools such as Cycode, Semgrep, Snyk, or similar.
- Experience improving security-focused developer experience without slowing teams down.
- Clear, constructive communication of technical risk in writing, code review, and conversation.
- Collaborative approach with developers, SREs, and security peers.
- Comfort with a security on-call rotation and work across security disciplines.

## Nice to Have

- Hands-on experience with bug bounty platforms.
- Experience with cloud infrastructure security and container technologies.
- Participation in CTF events or open-source security projects.
- Familiarity with threat-modeling frameworks and secure SDLC best practices.
- Interest in contributing to internal developer security training programs.

## Work Arrangement

- Amsterdam office attendance three times per week.
- Collaboration with coworkers on other continents.

## Compensation & Benefits

- Catered lunches, breakfast, snacks, and soft drinks at the office.
- Commuting-cost coverage for employees living outside Amsterdam.
- 25 vacation days based on full-time employment.
- Collective health insurance with Flexport-paid monthly premiums.
- Defined pension contribution scheme.
- Equity program.
- Employee Assistance Program through Aetna Resources for Living.
- Parental leave benefit.

## Similar jobs

- [Platform Security Engineer](https://hotfix.jobs/jobs/e556dd76-0f95-4dfa-9d3d-e476f24057c0) - Supabase - Remote
- [Manager, Security Operations](https://hotfix.jobs/jobs/0a4637da-6072-4ec3-a0a9-8b6d4a412d45) - Vanta - Remote - $178k – $209k/yr
- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Security Engineer - Product](https://hotfix.jobs/jobs/d32dc9fa-f31b-4fc4-a7c6-eade39acfb64) - Wiz - Berlin, Germany
- [Lead Product GRC Subject Matter Expert](https://hotfix.jobs/jobs/57c937d5-05e3-4033-875a-890645c4aa6b) - Vanta - Remote - $230k – $270k/yr

**Apply:** https://hotfix.jobs/jobs/1c7135d4-c307-45ca-bf0a-666012c2920e
**Canonical:** https://hotfix.jobs/jobs/1c7135d4-c307-45ca-bf0a-666012c2920e