Flox Logo

Flox

Security Engineer

Posted 5 Days Ago
Remote
Hiring Remotely in USA
160K-210K Annually
Mid level
Remote
Hiring Remotely in USA
160K-210K Annually
Mid level
Build and operate Flox's security program: deploy and manage SIEM/SOC, harden AWS and Cloudflare, implement IaC/CSPM/SAST/SCA scanning, manage endpoint protection, secure the software supply chain, run incident response, and own identity and access controls.
The summary above was generated by AI

THE ROLE

This is Flox’s first dedicated security hire. You’ll work directly with engineering leadership to stand up security practices that are pragmatic, developer-friendly, and right-sized for a company at our stage. The role is heavily weighted toward doing—you’ll be the one deploying tools, configuring controls, hardening infrastructure, and closing gaps, not just advising others to do so.

That said, you’ll have real input into how we think about controls, priorities, and our security roadmap as we grow. And because our product sits at the heart of the software supply chain—managing dependencies, environments, and build artifacts for some of the world’s largest engineering teams—security isn’t peripheral here. It’s core to the value we deliver.

If you want to build something from scratch, own it end-to-end, and have your work matter immediately, this is that job. If you want a large team, an existing program to slot into, or mostly governance work, it probably isn’t.

WHAT YOU’LL DO

Detection, Monitoring & Response

  • Help evaluate whether to stand up an internal SIEM or work with an outsourced SOC provider—then implement whichever path makes sense for where we are as a company. If building internally: deploy and configure the SIEM, write and tune detection rules, and own the alerting stack. If outsourcing: manage the SOC relationship, define what gets escalated and how, and ensure we’re getting signal not just noise

  • Build incident response runbooks and triage workflows—then actually test them (e.g. test backups in case needed for ransomware recovery)

  • Be the person who sees something and does something about it

Cloud & Infrastructure Security (AWS + Cloudflare)

  • Scan and harden our AWS posture hands-on: IAM policies, SCPs, security group hygiene, GuardDuty, Security Hub, and automated compliance guardrails need to be evaluated and maintained

  • Own Cloudflare configuration across WAF rules, DDoS protection, bot management, Zero Trust access, and DLP policies—keeping rules current and tuned as the product evolves

  • Implement IaC security scanning (Checkov, tfsec, or similar) directly into CI/CD pipelines

  • Own CSPM tooling—configure it, triage it, fix things, don’t just generate reports

Endpoint Protection

  • Deploy and manage endpoint protection across developer systems and production endpoints—covering EDR, device posture, behavior monitoring (including dynamic scans), DLP, and threat detection

  • Ensure developer machines (Mac-heavy environment typical of engineering teams) meet baseline security standards while minimizing friction that slows people down. Understand when and where detective controls suffice vs preventative controls based on thoughtful risk management and defense in depth

  • Define and enforce endpoint compliance policies, including disk encryption, patch posture, and application controls

  • Work with engineering to extend endpoint visibility into production infrastructure where applicable

Software Supply Chain

  • Secure our build and release pipelines

  • Consider SLSA framework adoption and supply chain integrity attestations for our catalog and environments

  • Stand up dependency vulnerability scanning and own the remediation workflow end-to-end for third-party services, libraries, middleware, operating systems, and SaaS

Application Security

  • Integrate SAST and SCA tooling (Semgrep, Snyk, GitHub Advanced Security) into developer workflows

  • Participate in security design reviews and threat modeling for new features

  • Work shoulder-to-shoulder with developers to find and fix vulnerabilities using a risk-based model instead of just vulnerability aging reports

Identity, Access & Entitlements

This is a priority area—but implemented right for a company at our size, not over-engineered for a company ten times larger.

  • Audit and rationalize IAM across AWS, Cloudflare, SaaS applications, and internal tooling; implement the fixes, not just the findings

  • Drive SSO consolidation, enforce MFA universally, and implement least-privilege access in practice, not just policy

  • Build a lightweight, repeatable access review process—something that actually runs on a cadence and produces real decisions

  • Own joiner/mover/leaver processes so that entitlements stay clean as the team grows

  • Evaluate and implement an appropriate identity governance solution for our stage—not an enterprise IGA platform, but something that gives us control and auditability

WHAT WE’RE LOOKING FOR

  • 3–5 years of hands-on security engineering experience, ideally at a software company or cloud-native environment

  • A demonstrable track record of implementing security tools and controls, not just scoping or recommending them

  • Solid working knowledge of AWS security services: IAM, SCPs, GuardDuty, Security Hub, CloudTrail, and related tooling

  • Hands-on experience with Cloudflare—WAF rule management, Zero Trust, DLP, or similar; comfort learning what you haven’t used yet

  • Experience deploying and managing endpoint protection (EDR/MDM) across a mixed developer and production environment

  • Familiarity with software supply chain concepts: SBOMs, dependency management, artifact signing, SLSA

  • Experience integrating SAST, SCA, or DAST tools into CI/CD pipelines

  • Comfort with scripting or light automation (Python, Bash, or similar) to build repeatable processes

  • Ability to work independently, ruthlessly prioritize, and operate without a playbook

  • The kind of person who is bothered when something is insecure and doesn’t wait for someone else to fix it

NICE TO HAVE

  • Familiarity with Nix, package management, or reproducible build systems

  • Experience evaluating or managing an outsourced SOC relationship

  • Prior SIEM deployment or detection engineering experience

  • Experience supporting a SOC 2 or ISO 27001 audit

  • Security certifications (CISSP, OSCP, AWS Security Specialty, etc.)

WHY FLOX

  • First dedicated security hire—you’ll build the program, not inherit someone else’s backlog

  • A product developers genuinely love, which makes working with the engineering team easier

  • Small team, short feedback loops, real ownership—your work will be visible immediately

  • Competitive salary, meaningful equity in a well-funded company, and a flexible hybrid environment

Similar Jobs

2 Hours Ago
Easy Apply
Remote or Hybrid
Easy Apply
110K-150K Annually
Senior level
110K-150K Annually
Senior level
Automotive • Greentech • HR Tech • Sales • Software
Own and improve enterprise security platforms, cloud and infrastructure security, identity governance, endpoint protection, vulnerability management, incident response, network controls, and DevSecOps practices. Lead complex security initiatives, compliance controls, vendor assessments, security architecture reviews, and AI security governance. Build automation with PowerShell and Python, partner with IT Operations and DevOps, reduce manual work, and serve as the senior escalation point for technical security incidents.
Top Skills: Amazon SesAuth0AWSAws Identity CenterAzureChatgpt EnterpriseCi/CdCisco DuoCisco MerakiCisco UmbrellaClaudeConditional AccessContainersCrowdstrikeDastDkimDmarcInfrastructure As CodeKnowbe4KubernetesMcpMicrosoft 365Microsoft Entra IdMicrosoft GraphNist CsfPimPowershellPythonRapid7 InsightappsecRapid7 InsightidrRapid7 InsightvmRapid7 MdrRest ApisSastScimSendgridSnykSoc 2SpfSsoVpn
2 Days Ago
Remote or Hybrid
TX, USA
70K-95K Annually
Entry level
70K-95K Annually
Entry level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Develops and strengthens threat detection, response, and remediation capabilities for CrowdStrike infrastructure. Responsibilities include researching attacker techniques, creating network and host-based detections, implementing security analytics and automation, investigating and remediating threats, supporting cloud security across major providers, tracking operational metrics, and collaborating on complex cross-functional programs. The role requires expertise in SIEM/SOAR technologies, cloud-native systems, programming, operating systems, networking, web security, and security engineering principles.
Top Skills: APIsDockerGoIaasKibanaKubernetesLinuxLogscalemacOSOauthOwaspPaasPythonSaaSSAMLSIEMSoarSplunkSsl/TlsTerraformWindowsXss
2 Days Ago
Remote or Hybrid
United States
80K-120K Annually
Mid level
80K-120K Annually
Mid level
Cloud • Insurance • Payments • Software • Business Intelligence • App development • Big Data Analytics
Secure LLMs, generative AI systems, ML infrastructure, training pipelines, and AI applications. Responsibilities include threat modeling, architecture reviews, security controls, hardening, vulnerability remediation, data privacy, incident response runbooks, vendor reviews, governance, policy development, and AI security training. The role also supports proof-of-concept security solutions and monitors emerging AI threats.
Top Skills: AnsibleBashETLGdprGenerative AiGoInfrastructure As CodeKubernetesLarge Language ModelsPythonPyTorchScikit-LearnSoc 2TensorFlowTerraform

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account