Security Engineer
Flox
| Company | Flox |
| Category | Engineering |
| Location | Remote |
| Remote | Remote |
| Employment | Not stated |
| Level | Not stated |
| Salary | USD 160k–210k |
| Posted | 28 Apr 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (ashby) |
Description
THE ROLE
This is Flox’s first dedicated security hire. You’ll work directly with engineering leadership to stand up security practices that are pragmatic, developer-friendly, and right-sized for a company at our stage. The role is heavily weighted toward doing—you’ll be the one deploying tools, configuring controls, hardening infrastructure, and closing gaps, not just advising others to do so.
That said, you’ll have real input into how we think about controls, priorities, and our security roadmap as we grow. And because our product sits at the heart of the software supply chain—managing dependencies, environments, and build artifacts for some of the world’s largest engineering teams—security isn’t peripheral here. It’s core to the value we deliver.
If you want to build something from scratch, own it end-to-end, and have your work matter immediately, this is that job. If you want a large team, an existing program to slot into, or mostly governance work, it probably isn’t.
WHAT YOU’LL DO
Detection, Monitoring & Response
- Help evaluate whether to stand up an internal SIEM or work with an outsourced SOC provider—then implement whichever path makes sense for where we are as a company. If building internally: deploy and configure the SIEM, write and tune detection rules, and own the alerting stack. If outsourcing: manage the SOC relationship, define what gets escalated and how, and ensure we’re getting signal not just noise
- Build incident response runbooks and triage workflows—then actually test them (e.g. test backups in case needed for ransomware recovery)
- Be the person who sees something and does something about it
Cloud & Infrastructure Security (AWS + Cloudflare)
- Scan and harden our AWS posture hands-on: IAM policies, SCPs, security group hygiene, GuardDuty, Security Hub, and automated compliance guardrails need to be evaluated and maintained
- Own Cloudflare configuration across WAF rules, DDoS protection, bot management, Zero Trust access, and DLP policies—keeping rules current and tuned as the product evolves
- Implement IaC security scanning (Checkov, tfsec, or similar) directly into CI/CD pipelines
- Own CSPM tooling—configure it, triage it, fix things, don’t just generate reports
Endpoint Protection
- Deploy and manage endpoint protection across developer systems and production endpoints—covering EDR, device posture, behavior monitoring (including dynamic scans), DLP, and threat detection
- Ensure developer machines (Mac-heavy environment typical of engineering teams) meet baseline security standards while minimizing friction that slows people down. Understand when and where detective controls suffice vs preventative controls based on thoughtful risk management and defense in depth
- Define and enforce endpoint compliance policies, including disk encryption, patch posture, and application controls
- Work with engineering to extend endpoint visibility into production infrastructure where applicable
Software Supply Chain
- Secure our build and release pipelines
- Consider SLSA framework adoption and supply chain integrity attestations for our catalog and environments
- Stand up dependency vulnerability scanning and own the remediation workflow end-to-end for third-party services, libraries, middleware, operating systems, and SaaS
Application Security
- Integrate SAST and SCA tooling (Semgrep, Snyk, GitHub Advanced Security) into developer workflows
- Participate in security design reviews and threat modeling for new features
- Work shoulder-to-shoulder with developers to find and fix vulnerabilities using a risk-based model instead of just vulnerability aging reports
Identity, Access & Entitlements
This is a priority area—but implemented right for a company at our size, not over-engineered for a company ten times larger.
- Audit and rationalize IAM across AWS, Cloudflare, SaaS applications, and internal tooling; implement the fix
1,014,484 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →