← Все вакансии/Middle/Flexport
MiddleHybridAmsterdam, Netherlands

Product Security Engineer

F
Flexport
Уровень
Middle
Формат
Hybrid
О роли

Описание вакансии

About the company

At Flexport, we believe global trade can move the human race forward. That’s why it’s our mission to make global commerce so easy there will be more of it. We’re shaping the future of a $10T industry with solutions powered by innovative technology and exceptional people. Today, companies of all sizes—from emerging brands to Fortune 500s—use Flexport technology to move more than $19B of merchandise across 112 countries a year.

The recent global supply chain crisis has put Flexport center stage as we continue to play a pivotal role in how goods move around the world. We are proud to have the support of the best investors in the game who believe in our mission, solutions and people.

Responsibilities
  • Build guardrails and AI-accelerated patterns that make secure-by-default the path of least resistance for developers.
  • Build and maintain security tooling and automation that scales product security.
  • Respond to emerging threats.
  • Contribute to threat modeling, design reviews, and code reviews with pragmatic guidance that balances risk against velocity.
  • Partner with engineering to security-review and test new features and services as they're built.
  • Triage, reproduce, and validate incoming bug bounty submissions and internal security reports.
  • Cut through SAST, secrets, and vulnerability scanner noise to prioritize real issues and guide developers to effective fixes.
  • Partner with development teams to drive remediation and track issues through closure.
  • Write clear, actionable security patterns that let developers ship fast and stay secure.
  • Write and maintain runbooks, developer guidelines, and security documentation that scale the team's practices.
  • Stay current on web and cloud security trends and bring new findings into product discussions.
Requirements
  • 2–5 years of experience in product/application security or software development with a security focus.
  • Strong grasp of web application security principles and common attack vectors (e.g., OWASP Top 10).
  • Proficiency with application testing tools such as Burp Suite, OWASP ZAP, or browser developer tools.
  • Working knowledge of at least one modern programming language (e.g., Ruby, Java/Kotlin, TypeScript/JavaScript, Python).
  • Working knowledge of at least one major cloud provider (AWS, GCP, Azure).
  • Hands-on experience with SAST tools (Cycode, Semgrep, Snyk, or similar).
  • Experience improving developer experience (DevEx) security without slowing teams down.
  • Clear, constructive communicator on technical risk - in writing, in code review, and in conversation.
  • Collaborative by default: you partner with developers, SREs, and security peers rather than handing down mandates.
  • Comfortable with security on-call rotation and picking up work across security disciplines when needed.
Conditions
  • In Amsterdam we come to the office 3 times a week to hang out, whiteboard, and ship together.
  • We stay closely aligned with our coworkers on other continents.
  • We have the latest hardware and software, including frontier AI models on day one.
  • We're agile, but not dogmatic. Teams decide how they work best.
Стек и навыки

С чем работаем