Senior Security Engineer, Detection & Response
Flexport is hiring a Senior Security Engineer, Detection & Response in Amsterdam, Netherlands. Level rates it ; you can apply on Level.
AI in this role
About Flexport:
At Flexport, we believe global trade can move the human race forward. That’s why it’s our mission to make global commerce so easy there will be more of it. We’re shaping the future of a $10T industry with solutions powered by innovative technology and exceptional people. Today, companies of all sizes—from emerging brands to Fortune 500s—use Flexport technology to move more than $19B of merchandise across 112 countries a year.
The recent global supply chain crisis has put Flexport center stage as we continue to play a pivotal role in how goods move around the world. We are proud to have the support of the best investors in the game who believe in our mission, solutions and people. Ready to tackle global challenges that impact business, society, and the environment? Come join us.
There is no MSSP and no tier-1 queue here. Detection & Response engineers own their detections end to end: you write them, you tune them, and your team is paged when they fire. The security team is spread across the globe with a follow-the-sun pager rotation so nobody is paged at 3am local.
The adversaries are real. The business is growing fast and the threat surface is growing with it. Defining the necessary telemetry is part of the job.
What You'll Do
Detection engineering
- Build and tune detections across endpoint, identity, SaaS, and cloud, treating them as software: version-controlled, peer-reviewed, and shipped through the same CI/CD practices the rest of engineering uses.
- Track detection quality as measured quantities: coverage against MITRE ATT&CK, precision, time-to-detect. We don’t build-and-forget here.
Response & automation
- Own EMEA-hours incident response: triage, contain, remediate, and write the retrospective that turns the incident into a systemic fix.
- Build automation that removes toil from investigations, and partner closely with the US-based team so context carries across time zones instead of getting lost at handoff.
Telemetry & partnership
- Define telemetry requirements for new systems before they ship, working with infrastructure and product teams to close visibility gaps rather than discovering them during an incident.
- Threat hunt proactively across the estate, converting hypotheses into either new detections or documented coverage.
You Should Have
- Typically 5–8 years of experience in detection engineering, incident response, or threat hunting, with real hands-on time writing and tuning detections. We care more about what you've built than the exact number.
- Proficiency in at least one programming language (Python, Go, or similar) and comfort writing production-grade detection and automation code.
- Experience with a modern SIEM or detection pipeline (Panther, Elastic, Splunk, or similar). What matters is that you've shipped and tuned detection logic in production.
- Practical incident response experience: you've led or played a major role in triaging and closing out real security incidents.
Nice to Have
- Experience treating detections as code with CI/CD, peer review, and staged rollout.
- Experience defining telemetry contracts for systems before they ship.
- A track record of critically evaluating and verifying AI-assisted work — testing, source-checking, validation — rather than trusting agent output by default. If you haven’t already spotted the em dashes in this job description and already thought about where the hiring manager (hi!) has put hands on keyboard and compared that to where they let the LLM watermarks through, you might not be the right person for the job.
- Familiarity with EU data-residency and cross-border data-handling considerations.
- Experience with fraud or financial-crime detection patterns.
How We Work
- In Amsterdam we come to the office 3 times a week to hang out, whiteboard, and ship together.
- We stay closely aligned with our coworkers on other continents.
- We have the latest hardware and software, including frontier AI models on day one.
- We're agile, but not dogmatic. Teams decide how they work best.
Why This Role Is Special
- You own your detections end to end. No MSSP, no tier-1 queue, and real authority over incident response rather than a night-shift triage seat.
- The consequences here are physical, not abstract: a containment decision can stop a customs filing or freight actually moving.
- You'll inherit a real, established estate with legacy telemetry gaps to close — genuinely underexplored surface area, not a well-mined problem.
- We sponsor visas for the right candidate.
What's in it for you
- An opportunity to contribute to one of the fastest-growing companies, where you'll have the chance to create a global impact while being part of a thriving multinational environment
- Daily catered lunches incl. vegetarian options, breakfast, snacks and soft drinks available in our office on a daily basis
- Commute expenses: Flexport will cover home-office commuting costs for employees living outside of Amsterdam
- 25 working days as vacation days based on full-time employment
- Health insurance: Flexport offers a collective health insurance plan including a basic package and any available additional packages. Your monthly premium is fully paid by Flexport.
- A defined pension contribution scheme
- Equity program: every team member becomes a shareholder, aligning our success with yours. As a private company in a multi-trillion dollar industry, you have a direct stake in our collective growth and success.
- Employee Assistance Program through Aetna Resources for Living: Flexport provides an employer-sponsored program at no cost to you and your household members
- Parental leave benefit: Flexport is here to support you and your family during one of the most important times in life — the birth of a child. Our parental leave program allows both mothers and partners to take time off from work for pregnancy, childbirth, and to bond with your new child.
Commitment to Equal Opportunity
At Flexport, our ability to fulfill our mission of making global commerce easy and accessible relies on having a diverse, dedicated and engaged workforce. All qualified applicants will receive consideration for employment regardless of race, color, religion, sex, national origin, age, physical and mental disability, health status, marital and family status, sexual orientation, gender identity and expression, military and veteran status, and any other characteristic protected by applicable law.
Global Data Privacy Notice for Job Candidates and Applicants
Depending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. By submitting your application, you are agreeing to our use and processing of your data as required. Please see our Privacy Notice available at www.flexport.com/privacy for additional information.
How we rate this
Senior Security Engineer, Detection & Response at Flexport rates 37 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.
Little AI. AI is not part of the work.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Get new cybersecurity jobs by email
One email a week with the new cybersecurity jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Security roles that involve little AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step