Flox logo
Flox

Flox offers developers, platform engineers, and operators reproducible environments that span the enterprise SDLC.

Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 11-50H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

2 days ago

Salary

$160K - $210K / year

Seniority

Senior

Bachelor Degree3 yrs expEnglishAWSCloudPython

Job Description

Security Engineer

Flox

• Help evaluate whether to stand up an internal SIEM or work with an outsourced SOC provider—then implement whichever path makes sense for where we are as a company. • Build incident response runbooks and triage workflows—then actually test them (e.g. test backups in case needed for ransomware recovery) • Be the person who sees something and does something about it • Scan and harden our AWS posture hands-on: IAM policies, SCPs, security group hygiene, GuardDuty, Security Hub, and automated compliance guardrails need to be evaluated and maintained • Own Cloudflare configuration across WAF rules, DDoS protection, bot management, Zero Trust access, and DLP policies—keeping rules current and tuned as the product evolves • Implement IaC security scanning (Checkov, tfsec, or similar) directly into CI/CD pipelines • Deploy and manage endpoint protection across developer systems and production endpoints—covering EDR, device posture, behavior monitoring (including dynamic scans), DLP, and threat detection • Ensure developer machines (Mac-heavy environment typical of engineering teams) meet baseline security standards while minimizing friction that slows people down. • Define and enforce endpoint compliance policies, including disk encryption, patch posture, and application controls • Secure our build and release pipelines • Consider SLSA framework adoption and supply chain integrity attestations for our catalog and environments • Stand up dependency vulnerability scanning and own the remediation workflow end-to-end for third-party services, libraries, middleware, operating systems, and SaaS • Integrate SAST and SCA tooling (Semgrep, Snyk, GitHub Advanced Security) into developer workflows • Participate in security design reviews and threat modeling for new features • Work shoulder-to-shoulder with developers to find and fix vulnerabilities using a risk-based model instead of just vulnerability aging reports • Audit and rationalize IAM across AWS, Cloudflare, SaaS applications, and internal tooling; implement the fixes, not just the findings • Drive SSO consolidation, enforce MFA universally, and implement least-privilege access in practice, not just policy • Build a lightweight, repeatable access review process—something that actually runs on a cadence and produces real decisions • Own joiner/mover/leaver processes so that entitlements stay clean as the team grows • Evaluate and implement an appropriate identity governance solution for our stage—not an enterprise IGA platform, but something that gives us control and auditability

Job Requirements

  • 3–5 years of hands-on security engineering experience, ideally at a software company or cloud-native environment
  • A demonstrable track record of implementing security tools and controls, not just scoping or recommending them
  • Solid working knowledge of AWS security services: IAM, SCPs, GuardDuty, Security Hub, CloudTrail, and related tooling
  • Hands-on experience with Cloudflare—WAF rule management, Zero Trust, DLP, or similar; comfort learning what you haven’t used yet
  • Experience deploying and managing endpoint protection (EDR/MDM) across a mixed developer and production environment
  • Familiarity with software supply chain concepts: SBOMs, dependency management, artifact signing, SLSA
  • Experience integrating SAST, SCA, or DAST tools into CI/CD pipelines
  • Comfort with scripting or light automation (Python, Bash, or similar) to build repeatable processes
  • Ability to work independently, ruthlessly prioritize, and operate without a playbook
  • The kind of person who is bothered when something is insecure and doesn’t wait for someone else to fix it.

Benefits

  • Competitive salary
  • Meaningful equity in a well-funded company
  • Flexible hybrid environment

Related Categories

Related Job Pages

More Security Engineer Jobs

GuidePoint Security logo

Practice Lead, Network Security

GuidePoint Security

We help organizations make smarter cybersecurity decisions that minimize risk.

Full TimeRemoteTeam 201-500H1B Sponsor

• Lead and develop the Network Security Practice, including strategy, service offerings, team growth, and overall performance management. • Build, mentor, and manage a team of Network Security Engineers through coaching, technical guidance, career development, and performance evaluations. • Establish and maintain technical standards, implementation methodologies, documentation requirements, and best practices across all network security engagements. • Serve as trusted advisor and executive consultant to enterprise customers, leading architecture workshops, security assessments, and strategic planning sessions. • Oversee delivery of complex network security projects, ensuring quality, consistency, customer satisfaction, and serving as escalation point for technical challenges. • Partner with Sales teams throughout the pre-sales process, leading technical discovery, solution design, SOW development, and customer presentations. • Provide architectural leadership across enterprise security technologies, including SASE platforms, next-generation firewalls, SD-WAN, cloud security (AWS, Azure, GCP), and Zero Trust architectures. • Design and review comprehensive security documentation, including network architectures, implementation plans, runbooks, security standards, and executive recommendations. • Evaluate and integrate emerging security technologies to expand the organization's service portfolio and meet evolving client requirements. • Collaborate with executive leadership to establish practice goals, utilization targets, revenue objectives, and strategic growth initiatives. • Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes. • Other related duties as needed.

United States
Job Closed
Full TimeRemoteTeam 11-50H1B Sponsor

• Develop and implement a security program: design, promote and implement organization-wide security solutions which align to the business strategy focusing on application and platform service development, technology infrastructure, and overall Cyber Security. • Plan the implementation of the security tooling. Choose specific tooling that best fits into Triple's processes, constraints and objectives, with specific proposals of configurations. Collaborate with Engineering for the implementation of the required changes. • Engage with Sales and Customer Engineering team members and other business units in response to relevant inquiries and requests regarding risk and security requirements • Be on top of communications with customer security teams • Answer RFPs, Questionnaires and Forms from integrations, explaining Triple Security practices to customers • Lead the promotion of security practices throughout the organization • Collaboration with key business and IT leaders to ensure that security policies and standards are implemented, enforced, and enhanced where appropriate. • Collaboration and coordination with leadership across all departments on risk and security related matters • Develop and implement guidelines that cover: risk assessments, issues and event management, impact analysis, monitoring and reporting. • Evaluate complex business problems to ensure risks and exposures are properly mitigated • Identify potential areas of vulnerability and risk; develop/implement corrective action plans for resolution of issues, and provide general guidance on how to prevent or address similar situations in the future • Lead certification processes and own the audit structure for ISO 27001, SOC 2, GDPR, CSA etc. • Develops and implements security frameworks for agentic AI, and builds production-grade security tooling. • Monitors AI systems to detect vulnerabilities and fraudulent activity

Spain
AddSales logo

Sales Development Representative, Cyber Security

AddSales

🟢 Ensure your D-A-CH go-to-market sales strategy and scale with our sales professionals (SDRs/AEs/CSMs) 🟢

Full TimeRemoteTeam 11-50Since 2022H1B No Sponsor

• Independently conduct acquisition activities for a variety of exciting projects in the cyber security sector. • Identify potential customers and markets, analyze market requirements, and develop targeted customer acquisition strategies. • Build and maintain long-term customer relationships through regular communication and personal support. • Conduct sales meetings and contract negotiations through to successful closing. • Work closely with management to continuously improve sales processes and optimize customer satisfaction. • Participate in trade shows, conferences and other events to present our company and generate new customer contacts.

Germany
€42K - €65K / year
Nutrium logo

Security & Compliance Specialist

Nutrium

Promoting wellbeing by making 1:1 dietitian-led, comprehensive nutrition care globally accessible.

Full TimeRemoteTeam 11-50Since 2015H1B No Sponsor

• Own compliance execution across Nutrium's security and privacy frameworks (ISO 27001, ISO 27701, SOC 2, ISO 9001, HIPAA, and GDPR) • Manage Nutrium's GRC platform end to end: controls, evidence, tasks, audits, and remediation plans • Prepare for and support internal and external audits, from scoping to evidence collection • Maintain and improve internal policies, procedures, controls, and compliance documentation • Partner with internal teams (Engineering, Legal and Operations), and external consultants, to turn requirements into practical implementation • Respond to security questionnaires and due diligence requests from prospects and clients • Support meetings with national and international clients on security, privacy, compliance, and data flows • Provide operational legal support, when needed.

Portugal
€19.6K - €29.4K / year