{"schemaVersion":"jobsearcher.job.v1","id":"8880da8110cc48b41f164d0c","url":"https://jobsearcher.com/jobs/8880da8110cc48b41f164d0c","canonicalUrl":"https://jobsearcher.com/jobs/8880da8110cc48b41f164d0c","title":"Senior Security Engineer, Detection & Response","description":"About Flexport:\n\nAt Flexport, we believe global trade can move the human race forward. That's why it's our mission to make global commerce so easy there will be more of it. We're shaping the future of a $10T industry with solutions powered by innovative technology and exceptional people. Today, companies of all sizes—from emerging brands to Fortune 500s—use Flexport technology to move more than $19B of merchandise across 112 countries a year.\n\nThe recent global supply chain crisis has put Flexport center stage as we continue to play a pivotal role in how goods move around the world. We are proud to have the support of the best investors in the game who believe in our mission, solutions and people. Ready to tackle global challenges that impact business, society, and the environment? Come join us.\n\nWhat you'll do\n\nThere is no MSSP and no tier-1 queue here. Detection & Response engineers own their detections end to end: you write them, you tune them, and your team is paged when they fire. The security team is spread across the globe with a follow-the-sun pager rotation so nobody is paged at 3am local.\n\nThe adversaries are real. The business is growing fast and the threat surface is growing with it. Defining the necessary telemetry is part of the job.\n\nDetection engineering\n\nBuild and tune detections across endpoint, identity, SaaS, and cloud, treating them as software: version-controlled, peer-reviewed, and shipped through the same CI/CD practices the rest of engineering uses.\nTrack detection quality as measured quantities: coverage against MITRE ATT&CK, precision, time-to-detect. We don't build-and-forget here.\n\nResponse & automation\n\nOwn incident response: triage, contain, remediate, and write the retrospective that turns the incident into a systemic fix.\nBuild automation that removes toil from investigations, and partner closely with the US-based team so context carries across time zones instead of getting lost at handoff.\n\nTelemetry & partnership\n\nDefine telemetry requirements for new systems before they ship, working with infrastructure and product teams to close visibility gaps rather than discovering them during an incident.\nThreat hunt proactively across the estate, converting hypotheses into either new detections or documented coverage.\nYou Should Have\nTypically 5–8 years of experience in detection engineering, incident response, or threat hunting, with real hands-on time writing and tuning detections. We care more about what you've built than the exact number.\nProficiency in at least one programming language (Python, Go, or similar) and comfort writing production-grade detection and automation code.\nExperience with a modern SIEM or detection pipeline (Panther, Elastic, Splunk, or similar). What matters is that you've shipped and tuned detection logic in production.\nPractical incident response experience: you've led or played a major role in triaging and closing out real security incidents.\nNice to have\nExperience treating detections as code with CI/CD, peer review, and staged rollout.\nExperience defining telemetry contracts for systems before they ship, rather than retrofitting logging after an incident.\nA track record of critically evaluating and verifying AI-assisted work - testing, source-checking, validation - rather than trusting agent output by default. If you haven't already spotted the em dashes in this job description and already thought about where the hiring manager (hi!) has put hands on keyboard and compared that to where they let the LLM watermarks through, you might not be the right person for the job.\nFamiliarity with cloud-native and Kubernetes telemetry.\nExperience with fraud or financial-crime detection patterns.\nHow we work\nWe're in the San Francisco office regularly to work through incidents and detection design in person.\nWe stay closely aligned with teammates on other continents via Slack, video, and async docs.\nWe have the latest hardware and software, including frontier AI models on day one.\nWe're agile, but not dogmatic. Teams decide how they work best.\nWhy this role is special\nYou own your detections end to end, no MSSP, no tier-1 queue, no handing your work to someone else to triage.\nThe consequences here are physical, not abstract: a containment decision can stop a customs filing or freight actually moving, which makes the stakes concrete in a way a SaaS control plane rarely is.\nYou'll inherit a real, established estate with legacy telemetry gaps to close, genuinely underexplored surface area, not a well-mined problem.\nWhere you'll work\n\nThis role is based in San Francisco, and we have a strong preference for candidates who are there or willing to relocate — we're deliberately building this team in one place. Relocation support is available for the right candidate.\n\nInvesting your time with Flexport means having immediate impact, all over the world. You're empowered to do what's best for everyone and trusted to make the right decisions when and where you need them. Join our collective of entrepreneurs and improve the world's experience in global trade.\n\n#LI-Onsite\n\nCommitment to Equal Opportunity\n\nAt Flexport, our ability to fulfill our mission of making global commerce easy and accessible relies on having a diverse, dedicated and engaged workforce. All qualified applicants will receive consideration for employment regardless of race, color, religion, sex, national origin, age, physical and mental disability, health status, marital and family status, sexual orientation, gender identity and expression, military and veteran status, and any other characteristic protected by applicable law.\n\nGlobal Data Privacy Notice for Job Candidates and Applicants\n\nDepending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. By submitting your application, you are agreeing to our use and processing of your data as required. Please see our Privacy Notice available at www.flexport.com/privacy for additional information.","company":"Flexport","rawCompany":"flexport","city":"Millbrae","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-08-29T08:54:33.718Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Senior Security Engineer, Detection & Response","description":"About Flexport:\n\nAt Flexport, we believe global trade can move the human race forward. That's why it's our mission to make global commerce so easy there will be more of it. We're shaping the future of a $10T industry with solutions powered by innovative technology and exceptional people. Today, companies of all sizes—from emerging brands to Fortune 500s—use Flexport technology to move more than $19B of merchandise across 112 countries a year.\n\nThe recent global supply chain crisis has put Flexport center stage as we continue to play a pivotal role in how goods move around the world. We are proud to have the support of the best investors in the game who believe in our mission, solutions and people. Ready to tackle global challenges that impact business, society, and the environment? Come join us.\n\nWhat you'll do\n\nThere is no MSSP and no tier-1 queue here. Detection & Response engineers own their detections end to end: you write them, you tune them, and your team is paged when they fire. The security team is spread across the globe with a follow-the-sun pager rotation so nobody is paged at 3am local.\n\nThe adversaries are real. The business is growing fast and the threat surface is growing with it. Defining the necessary telemetry is part of the job.\n\nDetection engineering\n\nBuild and tune detections across endpoint, identity, SaaS, and cloud, treating them as software: version-controlled, peer-reviewed, and shipped through the same CI/CD practices the rest of engineering uses.\nTrack detection quality as measured quantities: coverage against MITRE ATT&CK, precision, time-to-detect. We don't build-and-forget here.\n\nResponse & automation\n\nOwn incident response: triage, contain, remediate, and write the retrospective that turns the incident into a systemic fix.\nBuild automation that removes toil from investigations, and partner closely with the US-based team so context carries across time zones instead of getting lost at handoff.\n\nTelemetry & partnership\n\nDefine telemetry requirements for new systems before they ship, working with infrastructure and product teams to close visibility gaps rather than discovering them during an incident.\nThreat hunt proactively across the estate, converting hypotheses into either new detections or documented coverage.\nYou Should Have\nTypically 5–8 years of experience in detection engineering, incident response, or threat hunting, with real hands-on time writing and tuning detections. We care more about what you've built than the exact number.\nProficiency in at least one programming language (Python, Go, or similar) and comfort writing production-grade detection and automation code.\nExperience with a modern SIEM or detection pipeline (Panther, Elastic, Splunk, or similar). What matters is that you've shipped and tuned detection logic in production.\nPractical incident response experience: you've led or played a major role in triaging and closing out real security incidents.\nNice to have\nExperience treating detections as code with CI/CD, peer review, and staged rollout.\nExperience defining telemetry contracts for systems before they ship, rather than retrofitting logging after an incident.\nA track record of critically evaluating and verifying AI-assisted work - testing, source-checking, validation - rather than trusting agent output by default. If you haven't already spotted the em dashes in this job description and already thought about where the hiring manager (hi!) has put hands on keyboard and compared that to where they let the LLM watermarks through, you might not be the right person for the job.\nFamiliarity with cloud-native and Kubernetes telemetry.\nExperience with fraud or financial-crime detection patterns.\nHow we work\nWe're in the San Francisco office regularly to work through incidents and detection design in person.\nWe stay closely aligned with teammates on other continents via Slack, video, and async docs.\nWe have the latest hardware and software, including frontier AI models on day one.\nWe're agile, but not dogmatic. Teams decide how they work best.\nWhy this role is special\nYou own your detections end to end, no MSSP, no tier-1 queue, no handing your work to someone else to triage.\nThe consequences here are physical, not abstract: a containment decision can stop a customs filing or freight actually moving, which makes the stakes concrete in a way a SaaS control plane rarely is.\nYou'll inherit a real, established estate with legacy telemetry gaps to close, genuinely underexplored surface area, not a well-mined problem.\nWhere you'll work\n\nThis role is based in San Francisco, and we have a strong preference for candidates who are there or willing to relocate — we're deliberately building this team in one place. Relocation support is available for the right candidate.\n\nInvesting your time with Flexport means having immediate impact, all over the world. You're empowered to do what's best for everyone and trusted to make the right decisions when and where you need them. Join our collective of entrepreneurs and improve the world's experience in global trade.\n\n#LI-Onsite\n\nCommitment to Equal Opportunity\n\nAt Flexport, our ability to fulfill our mission of making global commerce easy and accessible relies on having a diverse, dedicated and engaged workforce. All qualified applicants will receive consideration for employment regardless of race, color, religion, sex, national origin, age, physical and mental disability, health status, marital and family status, sexual orientation, gender identity and expression, military and veteran status, and any other characteristic protected by applicable law.\n\nGlobal Data Privacy Notice for Job Candidates and Applicants\n\nDepending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. By submitting your application, you are agreeing to our use and processing of your data as required. Please see our Privacy Notice available at www.flexport.com/privacy for additional information.","datePosted":"2026-08-29T08:54:33.718Z","dateModified":"2026-08-29T08:54:33.718Z","hiringOrganization":{"@type":"Organization","name":"Flexport","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Millbrae","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"8880da8110cc48b41f164d0c"},"url":"https://jobsearcher.com/jobs/8880da8110cc48b41f164d0c"}}