# Security Engineer, Corporate Security

**Company:** [Flexport](https://hotfix.jobs/companies/flexport)
**Location:** San Francisco, CA
**Role:** Security Engineering
**Salary:** $165k – $202k/yr
**Experience:** 2+ years
**Skills:** SSO, MFA, SCIM, SAML, OIDC, Jamf, Kandji, Microsoft Intune, Crowdstrike, Sentinelone, Python, Go, Terraform, Sspm, OAuth
**Posted:** 2026-08-31

> Build and operate corporate security controls across identity, endpoints, SaaS applications, and automation. The role requires 2–5 years of security engineering experience, hands-on endpoint and EDR expertise, identity protocol knowledge, and scripting ability.

## Job Description

## Responsibilities

### Identity and Access
- Improve SSO coverage, phishing-resistant MFA, SCIM lifecycle automation, and least-privilege access across SaaS and cloud environments.
- Build detections and guardrails for account takeover, MFA fatigue attacks, and session token theft.

### Endpoint and Device Lifecycle
- Write and deploy device policy as code, including configuration profiles, remediation scripts, and enforcement rules for macOS and Windows.
- Implement staged rollouts and rollback capabilities.
- Maintain and improve EDR detection and response coverage across the device fleet.

### SaaS Security
- Reduce SaaS risk using SSPM tooling and automation, including detection of risky OAuth grants, shadow IT, and configuration drift.
- Manage security configuration for tools such as Google Workspace and Slack.
- Assess security implications of AI agents and MCP integrations.

### Automation and Enablement
- Automate device provisioning, access reviews, and vendor security questionnaires.
- Write runbooks and documentation.
- Partner with IT and People teams to implement practical security controls.

## Requirements

- Typically 2–5 years of experience in corporate, enterprise, or IT security engineering.
- Hands-on experience with endpoint management and EDR tools such as Jamf, Kandji, Intune, CrowdStrike, or SentinelOne.
- Working knowledge of SAML, OIDC, and SCIM, plus experience with an identity provider such as Okta, Entra, or Google Workspace.
- Ability to write production code or scripts in Python, Go, or a similar language.
- Clear, practical communication skills and the ability to explain security control tradeoffs to technical and non-technical stakeholders.

## Nice to Have

- Experience with SSPM tooling and OAuth grant governance.
- Exposure to DLP or insider-risk tooling.
- Familiarity with Terraform for infrastructure-as-code security configuration.
- Understanding of how agentic AI tools and MCP integrations affect corporate security monitoring.
- Interest in expanding into corporate security or detection engineering.

## Compensation

- Base salary range: **$165,375–$202,125 USD**.

## Similar jobs

- [Security Engineer, Detection & Response](https://hotfix.jobs/jobs/f57773ca-7aee-45f7-8b87-6b9764437ca8) - Sentry - San Francisco, CA - CA$162k – CA$420k/yr
- [Security Engineer, Application Security](https://hotfix.jobs/jobs/f6409472-67fe-454d-ad4c-fe68d8a8ce25) - Sentry - San Francisco, CA - CA$162k – CA$420k/yr
- [Software Engineer, Security](https://hotfix.jobs/jobs/8bbd2781-fac5-4687-84a8-4fa6faaed51e) - Harvey - San Francisco, CA - $161k – $245k/yr
- [Product Engineer, Security](https://hotfix.jobs/jobs/53b78b5e-4db4-4541-90f1-36826a29b8fc) - Greptile - San Francisco, CA - $170k – $300k/yr
- [Security Software Engineer](https://hotfix.jobs/jobs/224cc3c2-74cd-4a03-869e-9e3f15a09f4c) - Hover - San Francisco, CA - $148k – $183k/yr

**Apply:** https://hotfix.jobs/jobs/1f665191-40e9-40ac-9080-dc5d35f11946
**Canonical:** https://hotfix.jobs/jobs/1f665191-40e9-40ac-9080-dc5d35f11946