# Security Engineer, Corporate Security

**Company:** [Flexport](https://hotfix.jobs/companies/flexport)
**Location:** Unspecified
**Role:** Security Engineering
**Salary:** $131k – $202k/yr
**Experience:** 2+ years
**Skills:** SAML, OIDC, SCIM, Jamf, Kandji, Intune, Crowdstrike, Sentinelone, Okta, Google Workspace, Python, Go, Terraform, OAuth
**Posted:** 2026-08-31

> Corporate Security Engineer responsible for identity, endpoint, SaaS, and security automation controls across the company. The role requires 2–5 years of security engineering experience, hands-on endpoint and EDR expertise, identity protocol knowledge, and scripting ability.

## Job Description

## Responsibilities

### Identity and Access
- Advance identity security posture through SSO coverage, phishing-resistant MFA, SCIM lifecycle automation, and least-privilege access across SaaS and cloud environments.
- Build detections and guardrails for account takeover, MFA fatigue attacks, and session token theft.

### Endpoint and Device Lifecycle
- Write and deploy device policy as code, including configuration profiles, remediation scripts, and enforcement rules for macOS and Windows.
- Implement staged rollouts with rollback capabilities.
- Maintain and improve EDR detection and response coverage across the device fleet.

### SaaS Security
- Reduce SaaS risk through SSPM tooling and automation, including detection of risky OAuth grants, shadow IT, and configuration drift.
- Own security configuration for Google Workspace, Slack, and other critical SaaS applications.
- Assess security implications of AI agents and MCP integrations.

### Automation and Enablement
- Automate device provisioning, access reviews, vendor security questionnaires, and other repetitive corporate security workflows.
- Write runbooks and documentation.
- Partner with IT and People teams to implement effective, low-friction security controls.

## Requirements
- 2–5 years of experience in corporate, enterprise, or IT security engineering; demonstrated delivery and impact are valued.
- Hands-on experience with endpoint management and EDR tools such as Jamf, Kandji, Intune, CrowdStrike, or SentinelOne.
- Working knowledge of SAML, OIDC, and SCIM identity protocols.
- Experience with a major identity provider such as Okta, Entra, or Google Workspace.
- Ability to write production code or scripts in Python, Go, or similar languages.
- Clear communication skills and the ability to explain security control tradeoffs to technical and nontechnical stakeholders.

## Nice to Have
- Experience with SSPM tooling and OAuth grant governance.
- Exposure to DLP or insider-risk tooling.
- Familiarity with Terraform for infrastructure-as-code security configuration.
- Understanding of how agentic AI tools and MCP integrations affect corporate security monitoring.
- Interest in expanding into broader corporate security or detection engineering responsibilities.

## Compensation
- US base salary range: $130,950–$202,125, varying by location.
- Additional compensation may include bonus, equity, and benefits.

## Similar jobs

- [Cybersecurity Software Engineer - New Grad](https://hotfix.jobs/jobs/e6590524-c732-4954-a09c-e8a3a040ed8e) - Applied Intuition - Sunnyvale, CA - $130k – $158k/yr
- [Threat Intelligence Platform Engineer](https://hotfix.jobs/jobs/4d005958-d28e-4873-a179-6fa03275091b) - Coinbase - Remote - $145k – $170k/yr
- [Security Software Engineer](https://hotfix.jobs/jobs/224cc3c2-74cd-4a03-869e-9e3f15a09f4c) - Hover - San Francisco, CA - $148k – $183k/yr
- [Software Engineer, Security](https://hotfix.jobs/jobs/8bbd2781-fac5-4687-84a8-4fa6faaed51e) - Harvey - San Francisco, CA - $161k – $245k/yr
- [Security Engineer, Detection & Response](https://hotfix.jobs/jobs/f57773ca-7aee-45f7-8b87-6b9764437ca8) - Sentry - San Francisco, CA - CA$162k – CA$420k/yr

**Apply:** https://hotfix.jobs/jobs/ea38e135-9fc8-4374-90f8-e09ea1b02e3b
**Canonical:** https://hotfix.jobs/jobs/ea38e135-9fc8-4374-90f8-e09ea1b02e3b