WFH.teamOpen app
Back to remote jobs
Remote job detail

Senior Security Engineer, Detection & Response

Flexport

LocationUnited States
SenioritySenior
CompanyFlexport
Verified recentlyChecked today
Compensation

$138k-$252k

Salary details are shown when available from the source listing. Sign in before applying so the role can be reviewed against your resume, salary goals, seniority, timezone, and location eligibility.

Requirements and working style

Decision details from the source listing

Experience

5-8 years stated

Education

High school

Schedule

flexible

Benefits stated
BonusEquityMedical benefitsDental benefitsFlexible time off

These fields are normalized from the employer's text. Confirm details on the employer site before applying.

WFH.team analysis

What this posting tells you

Senior Detection & Response Security Engineer role, remote in the United States. Owns security detections, incident response, automation, telemetry requirements, and threat hunting. The posting lists 5–8 years of typical experience and state-specific US base salary ranges from $138,196 to $252,000.

Role lane

Backend, Data, Design and creative, DevOps, Education, Healthcare admin, Legal, Product, QA and testing, Security, Software, Customer support, Writing and content

Where you can work

United States

Working hours

Timezone overlap is not stated.

Arrangement

Senior · contract

Required signals
Detection engineeringIncident responseThreat huntingProgramming in Python, Go, or a similar languageModern SIEM or detection pipeline experienceProduction detection logic development and tuning
Preferred signals
Detection-as-codeCI/CD and peer reviewTelemetry contract designCritical evaluation and validation of AI-assisted workCloud-native telemetryKubernetes telemetryFraud or financial-crime detection
Confirm before applying
  • Required timezone overlap is not stated
Market context

Backend hiring on WFH.team

3,766active related roles
1,072new in the latest period
164jobs per 100 candidates
$186kmedian of comparable listed ranges

This role's listed pay is near the median among 200 comparable roles shown here. Category counts come from WFH.team's latest published remote job market snapshot.

Explore the remote job market
Skills and signals
Detection engineeringIncident responseThreat huntingProgramming in Python, Go, or a similar languageModern SIEM or detection pipeline experienceProduction detection logic development and tuningDetection-as-codeCI/CD and peer reviewTelemetry contract designCritical evaluation and validation of AI-assisted workCloud-native telemetryKubernetes telemetryFraud or financial-crime detectionRemote within the United States
Job description

Senior Security Engineer, Detection & Response at Flexport

About Flexport

At Flexport, we believe global trade can move the human race forward. That’s why it’s our mission to make global commerce so easy there will be more of it. We’re shaping the future of a $10T industry with solutions powered by innovative technology and exceptional people. Today, companies of all sizes—from emerging brands to Fortune 500s—use Flexport technology to move more than $19B of merchandise across 112 countries a year.

The recent global supply chain crisis has put Flexport center stage as we continue to play a pivotal role in how goods move around the world. We are proud to have the support of the best investors in the game who believe in our mission, solutions and people. Ready to tackle global challenges that impact business, society, and the environment? Come join us.

What you'll do

There is no MSSP and no tier-1 queue here. Detection & Response engineers own their detections end to end: you write them, you tune them, and your team is paged when they fire. The security team is spread across the globe with a follow-the-sun pager rotation so nobody is paged at 3am local.

The adversaries are real. The business is growing fast and the threat surface is growing with it. Defining the necessary telemetry is part of the job.

Detection engineering

  • Build and tune detections across endpoint, identity, SaaS, and cloud , treating them as software: version-controlled, peer-reviewed, and shipped through the same CI/CD practices the rest of engineering uses.
  • Track detection quality as measured quantities : coverage against MITRE ATT&CK, precision, time-to-detect. We don’t build-and-forget here.

Response & automation

  • Own incident response: triage, contain, remediate, and write the retrospective that turns the incident into a systemic fix.
  • Build automation that removes toil from investigations, and partner closely with the US-based team so context carries across time zones instead of getting lost at handoff.

Telemetry & partnership

  • Define telemetry requirements for new systems before they ship , working with infrastructure and product teams to close visibility gaps rather than discovering them during an incident.
  • Threat hunt proactively across the estate , converting hypotheses into either new detections or documented coverage.

You Should Have

  • Typically 5–8 years of experience in detection engineering, incident response, or threat hunting, with real hands-on time writing and tuning detections. We care more about what you've built than the exact number.
  • Proficiency in at least one programming language (Python, Go, or similar) and comfort writing production-grade detection and automation code.
  • Experience with a modern SIEM or detection pipeline (Panther, Elastic, Splunk, or similar). What matters is that you've shipped and tuned detection logic in production.
  • Practical incident response experience : you've led or played a major role in triaging and closing out real security incidents.

Nice to have

  • Experience treating detections as code with CI/CD, peer review, and staged rollout.
  • Experience defining telemetry contracts for systems before they ship, rather than retrofitting logging after an incident.
  • A track record of critically evaluating and verifying AI-assisted work - testing, source-checking, validation - rather than trusting agent output by default. If you haven’t already spotted the em dashes in this job description and already thought about where the hiring manager (hi!) has put hands on keyboard and compared that to where they let the LLM watermarks through, you might not be the right person for the job.
  • Familiarity with cloud-native and Kubernetes telemetry.
  • Experience with fraud or financial-crime detection patterns.

How we work

  • We stay closely aligned with teammates on other continents via Slack, video, and async docs.
  • We have the latest hardware and software, including frontier AI models on day one.
  • We're agile, but not dogmatic. Teams decide how they work best.

Why this role is special

  • You own your detections end to end, no MSSP, no tier-1 queue, no handing your work to someone else to triage.
  • The consequences here are physical, not abstract: a containment decision can stop a customs filing or freight actually moving, which makes the stakes concrete in a way a SaaS control plane rarely is.
  • You'll inherit a real, established estate with legacy telemetry gaps to close, genuinely underexplored surface area, not a well-mined problem.

#LI-Remote

The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. Our salary ranges are determined by role, level, and location. Within the range displayed, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education and / or training. Base salary is just one part of our total rewards package at Flexport, which also includes bonus, equity, and comprehensive benefit offerings such as medical, dental, and flexible time off.

California Pay Range

$138,196 — $252,000 USD

Washington Pay Range

$183,272 — $229,091 USD

Colorado Pay Range

$138,196 — $172,746 USD

New York City Pay Range

$183,272 — $229,091 USD

Illinois Pay Range

$138,196 — $172,746 USD

Commitment to Equal Opportunity

At Flexport, our ability to fulfill our mission of making global commerce easy and accessible relies on having a diverse, dedicated and engaged workforce. All qualified applicants will receive consideration for employment regardless of race, color, religion, sex, national origin, age, physical and mental disability, health status, marital and family status, sexual orientation, gender identity and expression, military and veteran status, and any other characteristic protected by applicable law.

Global Data Privacy Notice for Job Candidates and Applicants

Depending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. By submitting your application, you are agreeing to our use and processing of your data as required. Please see our Privacy Notice available at www.flexport.com/privacy for additional information.

Company context

Working remotely at Flexport

Flexport is a full-service global freight forwarder and logistics platform using modern software to streamline and simplify global trade for businesses of all sizes.

Headquarters
United States
Team size
1001-5000
Founded
2013
Remote policy

Remote hiring signal is inferred from active confirmed-remote job listings.

Application process

Review current openings on Flexport's official careers page before applying.

React NativeRuby on RailsJavaRubyKotlinGraphQLgRPCSQLSnowflakeLooker
Research Flexport
Remote Senior Security Engineer, Detection & Response at Flexport | WFH.team