> Markdown version of [/jobs/ext/2695420-security-engineer-corporate-security](https://www.wearedevelopers.com/jobs/ext/2695420-security-engineer-corporate-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer, Corporate Security - **Company:** Flexport Inc. - **Location:** New York, NY, United States - **Experience:** Experienced - **Salary:** $165,375.0 - $202,125.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software as a Service, Cyber Security, Intrusion Detection and Prevention, Python (Programming Language), OAuth, OpenID, Security Assertion Markup Language (SAML), Okta, Microsoft InTune, Falcon Platform, Casper Suite, Gsuite, Terraform, SentinelOne Expertise - **Published:** September 3, 2026 - **Apply:** https://www.dice.com/job-detail/066477d3-202c-4df8-a7ae-1700b36d0d73 ## About the Role * Typically 2-5 years of experience in corporate, enterprise, or IT security engineering - we care more about what you've shipped than the exact number. If you meet most of this, apply; we'd rather see your work than filter you out on a rsum line. * Hands-on experience with modern endpoint management and EDR tooling (Jamf, Kandji, Intune, CrowdStrike, SentinelOne, or similar). * Working knowledge of identity protocols (SAML, OIDC, SCIM) and a major identity provider (Okta, Entra, Google Workspace, or similar). * Comfort writing real code or scripts (Python, Go, or similar) to replace manual, ticket-driven work with automation. * Clear, practical communicator who can explain a control tradeoff to an engineer, a salesperson, and a VP without changing the facts. Nice to have * Experience with SSPM tooling and OAuth-grant governance. * Exposure to DLP or insider-risk tooling. * Familiarity with infrastructure-as-code (Terraform) for managing security configuration. * A point of view on how agentic AI tools and MCP integrations change what corporate security needs to watch for * Interest in growing into a broader corporate security or detection engineering scope over time. ## Description + Reduce SaaS risk at scale through SSPM tooling and automation, including detection of risky OAuth grants, shadow IT, and configuration drift across our critical SaaS applications. + Own security configuration for the SaaS tools hundreds of Flexporters use daily (Google Workspace, Slack, and similar), and keep pace as we add AI agents and MCP integrations to that surface. * Automation & enablement + Automate the parts of corporate security that don't need a human - device provisioning, access reviews, vendor security questionnaires - so the team scales with headcount instead of straining against it. + Write runbooks and documentation that make the rest of the team more capable, and partner with IT and People teams to ship controls that don't create the friction that drives people to workarounds., * We're in the San Francisco office regularly to work through incidents and detection design in person. * We stay closely aligned with teammates on other continents via Slack, video, and async docs. * We have the latest hardware and software, including frontier AI models on day one. * We're agile, but not dogmatic. Teams decide how they work best. Why this role is special * Broad, real ownership: at this level elsewhere you might own a slice of a control; here you'll own well-defined projects end to end, from design through rollout, with support scoping the ambiguous parts. * Every device policy or identity control you ship protects every Flexporter, immediately - no six-month rollout to a subset of customers. * You're part of PSI: security is treated as infrastructure to build, not policy to enforce, and platform and infrastructure engineers are a Slack message away. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)