Jobs / United States / Flexport INC

Senior Security Engineer, Detection & Response

Flexport INC · 🇺🇸 San Francisco, California, United States

Sponsorship verdict

Sponsorship possible

One solid signal, not two — worth applying, and worth asking about sponsorship early.

  • Employer is on a government sponsor recordThe US Department of Labor certified 28 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest May 2026) — the step every H-1B hire needs first. USCIS also records 39 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
  • The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
  • No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
  • What Flexport INC paid sponsored hires in similar roles2 certified filings for “Senior Software Engineer” (Software Developers) in CA: $165k–$215k, median $190k. Most were filed at wage level I (100%) — 1 lottery entry, ≈15% projected selection odds for cap-subject employers. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
  • Confirmed live todayWhen a source last listed this job as open.

US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).

A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.

Start free →

Or apply yourself on the official page →

Sponsor Radar — Flexport INC

28 H-1B filings certified since Oct 2025

The US Department of Labor certified 28 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest May 2026) — the step every H-1B hire needs first. USCIS also records 39 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).

Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Flexport INC →

About the role

About Flexport: At Flexport, we believe global trade can move the human race forward. That’s why it’s our mission to make global commerce so easy there will be more of it. We’re shaping the future of a $10T industry with solutions powered by innovative technology and exceptional people. Today, companies of all sizes—from emerging brands to Fortune 500s—use Flexport technology to move more than $19B of merchandise across 112 countries a year. The recent global supply chain crisis has put Flexport center stage as we continue to play a pivotal role in how goods move around the world. We are proud to have the support of the best investors in the game who believe in our mission, solutions and people. Ready to tackle global challenges that impact business, society, and the environment? Come join us. What you'll do There is no MSSP and no tier-1 queue here. Detection & Response engineers own their detections end to end: you write them, you tune them, and your team is paged when they fire. The security team is spread across the globe with a follow-the-sun pager rotation so nobody is paged at 3am local. The adversaries are real. The business is growing fast and the threat surface is growing with it. Defining the necessary telemetry is part of the job. Detection engineering • Build and tune detections across endpoint, identity, SaaS, and cloud , treating them as software: version-controlled, peer-reviewed, and shipped through the same CI/CD practices the rest of engineering uses. • Track detection quality as measured quantities : coverage against MITRE ATT&CK, precision, time-to-detect. We don’t build-and-forget here. Response & automation • Own incident response: triage, contain, remediate, and write the retrospective that turns the incident into a systemic fix. • Build automation that removes toil from investigations, and partner closely with the US-based team so context carries across time zones instead of getting lost at handoff. Telemetry & partnership • Define telemetry requirements for new systems before they ship , working with infrastructure and product teams to close visibility gaps rather than discovering them during an incident. • Threat hunt proactively across the estate , converting hypotheses into either new detections or documented coverage. You Should Have • Typically 5–8 years of experience in detection engineering, incident response, or threat hunting, with real hands-on time writing and tuning detections. We care more about what you've built than the exact number. • Proficiency in at least one programming language (Python, Go, or similar) and comfort writing production-grade detection and automation code. • Experience with a modern SIEM or detection pipeline (Panther, Elastic, Splunk, or similar). What matters is that you've shipped and tuned detection logic in production. • Practical incident response experience : you've led or played a major role in triaging and closing out real security incidents. Nice to have • Experience treating detections as code with CI/CD, peer review, and staged rollout. • Experience defining telemetry contracts for systems before they ship, rather than retrofitting logging after an incident. • A track record of critically evaluating and verifying AI-assisted work - testing, source-checking, validation - rather than trusting agent output by default. If you haven’t already spotted the em dashes in this job description and already thought about where the hiring manager (hi!) has put hands on keyboard and compared that to where they let the LLM watermarks through, you might not be the right person for the job. • Familiarity with cloud-native and Kubernetes telemetry. • Experience with fraud or financial-crime detection patterns. How we work • We're in the San Francisco o

View the official posting →

Source: Greenhouse (employer board) First seen: 2026-08-27 Last confirmed: 2026-10-03 How our data works → Report this job

Similar opportunities