远程工作雷达

高级安全工程师,检测与响应

Senior Security Engineer, Detection & Response

开发工程全球可投
公司Flexport
薪资未公开
工作地点U.S. Remote
地域资格全球可投
时区要求无特别要求
用工类型未标注
发布时间23 天前
数据来源Greenhouse
前往企业招聘页投递 →
全球可投:该职位未限制候选人所在地区。仍需注意薪资可能按地区折算,以及实际签约方式(正式雇佣 / 独立合同)。

关于Flexport:

在Flexport,我们相信全球贸易可以推动人类进步。这就是我们的使命:让全球商业变得如此简单,从而促进其发展。我们正通过创新技术和优秀人才,塑造一个价值10万亿美元行业的未来。如今,各种规模的公司——从新兴品牌到财富500强——都在使用Flexport的技术,每年在112个国家间运输超过190亿美元的商品。

最近的全球供应链危机使Flexport成为焦点,我们继续在全球货物运输中发挥关键作用。我们很自豪获得业内最优秀投资者的支持,他们相信我们的使命、解决方案和团队。准备好应对影响商业、社会和环境的全球性挑战了吗?加入我们吧。

你将负责

这里没有MSSP,也没有一级支持队列。检测与响应工程师负责他们的检测从头到尾:你编写它们,调整它们,当它们触发时你的团队会被通知。安全团队遍布全球,采用跟随太阳的值班轮换制度,因此没有人会在当地时间凌晨3点被通知。

对手是真实的。业务增长迅速,威胁面也随之扩大。定义必要的遥测数据是工作的一部分。

检测工程

  • 在端点、身份、SaaS和云环境中构建并调整检测机制,将其视为软件:进行版本控制、同行评审,并通过与其他工程师相同的CI/CD流程进行发布。
  • 以可量化的指标跟踪检测质量:对MITRE ATT&CK的覆盖率、精确度、发现时间。我们在这里不采用“建立后就忘记”的方式。

响应与自动化

  • 负责事件响应:分类、隔离、修复,并撰写回顾文档,将事件转化为系统性解决方案。
  • 构建自动化工具,减少调查中的重复劳动,并与位于美国的团队紧密合作,确保跨时区的信息传递而不是在交接时丢失。

遥测与协作

  • 在新系统上线前定义遥测需求,与基础设施和产品团队合作,填补可见性缺口,而不是在事件发生时才发现。
  • 主动在整个系统范围内进行威胁狩猎,将假设转化为新的检测机制或已记录的覆盖范围。

你应具备

  • 通常有5至8年的检测工程、事件响应或威胁狩猎经验,有实际动手编写和调整检测机制的时间。我们更关注你所做的事情
查看英文原文

About Flexport:

At Flexport, we believe global trade can move the human race forward. That’s why it’s our mission to make global commerce so easy there will be more of it. We’re shaping the future of a $10T industry with solutions powered by innovative technology and exceptional people. Today, companies of all sizes—from emerging brands to Fortune 500s—use Flexport technology to move more than $19B of merchandise across 112 countries a year.

The recent global supply chain crisis has put Flexport center stage as we continue to play a pivotal role in how goods move around the world. We are proud to have the support of the best investors in the game who believe in our mission, solutions and people. Ready to tackle global challenges that impact business, society, and the environment? Come join us.

What you'll do

There is no MSSP and no tier-1 queue here. Detection & Response engineers own their detections end to end: you write them, you tune them, and your team is paged when they fire. The security team is spread across the globe with a follow-the-sun pager rotation so nobody is paged at 3am local.

The adversaries are real. The business is growing fast and the threat surface is growing with it. Defining the necessary telemetry is part of the job.

Detection engineering

  • Build and tune detections across endpoint, identity, SaaS, and cloud, treating them as software: version-controlled, peer-reviewed, and shipped through the same CI/CD practices the rest of engineering uses.
  • Track detection quality as measured quantities: coverage against MITRE ATT&CK, precision, time-to-detect. We don’t build-and-forget here.

Response & automation

  • Own incident response: triage, contain, remediate, and write the retrospective that turns the incident into a systemic fix.
  • Build automation that removes toil from investigations, and partner closely with the US-based team so context carries across time zones instead of getting lost at handoff.

Telemetry & partnership

  • Define telemetry requirements for new systems before they ship, working with infrastructure and product teams to close visibility gaps rather than discovering them during an incident.
  • Threat hunt proactively across the estate, converting hypotheses into either new detections or documented coverage.

You Should Have

  • Typically 5–8 years of experience in detection engineering, incident response, or threat hunting, with real hands-on time writing and tuning detections. We care more about what you've built than the exact number.
  • Proficiency in at least one programming language (Python, Go, or similar) and comfort writing production-grade detection and automation code.
  • Experience with a modern SIEM or detection pipeline (Panther, Elastic, Splunk, or similar). What matters is that you've shipped and tuned detection logic in production.
  • Practical incident response experience: you've led or played a major role in triaging and closing out real security incidents.

Nice to have

  • Experience treating detections as code with CI/CD, peer review, and staged rollout.
  • Experience defining telemetry contracts for systems before they ship, rather than retrofitting logging after an incident.
  • A track record of critically evaluating and verifying AI-assisted work - testing, source-checking, validation - rather than trusting agent output by default. If you haven’t already spotted the em dashes in this job description and already thought about where the hiring manager (hi!) has put hands on keyboard and compared that to where they let the LLM watermarks through, you might not be the right person for the job.
  • Familiarity with cloud-native and Kubernetes telemetry.
  • Experience with fraud or financial-crime detection patterns.

How we work

  • We're in the San Francisco office regularly to work through incidents and detection design in person.
  • We stay closely aligned with teammates on other continents via Slack, video, and async docs.
  • We have the latest hardware and software, including frontier AI models on day one.
  • We're agile, but not dogmatic. Teams decide how they work best.

Why this role is special

  • You own your detections end to end, no MSSP, no tier-1 queue, no handing your work to someone else to triage.
  • The consequences here are physical, not abstract: a containment decision can stop a customs filing or freight actually moving, which makes the stakes concrete in a way a SaaS control plane rarely is.
  • You'll inherit a real, established estate with legacy telemetry gaps to close, genuinely underexplored surface area, not a well-mined problem.

Where you'll work

This role is based in San Francisco, and we have a strong preference for candidates who are there or willing to relocate — we're deliberately building this team in one place. Relocation support is available for the right candidate.

Investing your time with Flexport means having immediate impact, all over the world. You're empowered to do what's best for everyone and trusted to make the right decisions when and where you need them. Join our collective of entrepreneurs and improve the world's experience in global trade.

#LI-Onsite

The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. Our salary ranges are determined by role, level, and location. Within the range displayed, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education and / or training. Base salary is just one part of our total rewards package at Flexport, which also includes bonus, equity, and comprehensive benefit offerings such as medical, dental, and flexible time off.

California Pay Range
$206,181—$252,000 USD

Washington Pay Range
$183,272—$229,091 USD

Colorado Pay Range
$138,196—$172,746 USD

New York City Pay Range
$183,272—$229,091 USD

Illinois Pay Range
$138,196—$172,746 USD

Commitment to Equal Opportunity

At Flexport, our ability to fulfill our mission of making global commerce easy and accessible relies on having a diverse, dedicated and engaged workforce. All qualified applicants will receive consideration for employment regardless of race, color, religion, sex, national origin, age, physical and mental disability, health status, marital and family status, sexual orientation, gender identity and expression, military and veteran status, and any other characteristic protected by applicable law.

Global Data Privacy Notice for Job Candidates and Applicants

Depending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. By submitting your application, you are agreeing to our use and processing of your data as required. Please see our Privacy Notice available at www.flexport.com/privacy for additional information.

本页面信息整理自 Greenhouse,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位