Flexport logo
FlexportPosted 2 months ago

Product Security Engineer II

On-siteAmsterdam, North Holland, The Netherlands

Full TimeLargeLogistics Software

Job Summary

Build guardrails and AI-accelerated patterns to make secure-by-default the path of least resistance for developers. Maintain security tooling and automation that scales product security while triaging, reproducing, and validating bug bounty submissions and internal reports. Partner with engineering teams to conduct threat modeling, design reviews, and code reviews, then guide developers through effective remediation of SAST, secrets, and vulnerability scanner noise. Write actionable security patterns, runbooks, and documentation to improve developer experience without slowing velocity. Respond to emerging threats and proactively analyze code to find flaws before attackers do. Work within the PSI team to establish conventions that reinforce Platform and Infrastructure efforts across hundreds of engineers.

Required Qualifications

  • 2–5 years of experience in product/application security or software development with a security focus
  • Strong grasp of web application security principles and common attack vectors (e.g., OWASP Top 10)
  • Proficiency with application testing tools such as Burp Suite, OWASP ZAP, or browser developer tools
  • Working knowledge of at least one modern programming language (e.g., Ruby, Java/Kotlin, TypeScript/JavaScript, Python)
  • Working knowledge of at least one major cloud provider (AWS, GCP, Azure)
  • Hands-on experience with SAST tools (Cycode, Semgrep, Snyk, or similar)
  • Experience improving developer experience (DevEx) security without slowing teams down
  • Clear, constructive communicator on technical risk - in writing, in code review, and in conversation
  • Collaborative by default: you partner with developers, SREs, and security peers rather than handing down mandates
  • Comfortable with security on-call rotation and picking up work across security disciplines when needed
  • Must be able to work in Amsterdam (implied by #LI-onsite and office attendance requirements)

Desired Qualifications

  • Hands-on experience with bug bounty platforms
  • Experience with cloud infrastructure security (AWS, GCP, Azure) and container technologies
  • Participation in CTF events or open-source security projects
  • Familiarity with threat modeling frameworks and secure SDLC best practices
  • Interest in contributing to internal developer security training programs

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce