Flox gives platform teams one declared environment that stays reproducible for every developer and agent, from the first commit through to production. Backed by NEA.
About the role
This is Flox’s first dedicated security hire. You’ll work directly with engineering leadership to stand up security practices that are pragmatic, developer-friendly, and right-sized for a company at our stage. The role is heavily weighted toward doing—you’ll be the one deploying tools, configuring controls, hardening infrastructure, and closing gaps, not just advising others to do so.
What they're looking for
- 3–5 years of hands-on security engineering experience, ideally at a software company or cloud-native environment
- A demonstrable track record of implementing security tools and controls, not just scoping or recommending them
- Solid working knowledge of AWS security services: IAM, SCPs, GuardDuty, Security Hub, CloudTrail, and related tooling
- Hands-on experience with Cloudflare—WAF rule management, Zero Trust, DLP, or similar, comfort learning what you haven’t used yet
- Experience deploying and managing endpoint protection (EDR/MDM) across a mixed developer and production environment
- Familiarity with software supply chain concepts: SBOMs, dependency management, artifact signing, SLSA
More about this role
This is Flox’s first dedicated security hire. You’ll work directly with engineering leadership to stand up security practices that are pragmatic, developer-friendly, and right-sized for a company at our stage. The role is heavily weighted toward doing—you’ll be the one deploying tools, configuring controls, hardening infrastructure, and closing gaps, not just advising others to do so.
That said, you’ll have real input into how we think about controls, priorities, and our security roadmap as we grow. And because our product sits at the heart of the software supply chain—managing dependencies, environments, and build artifacts for some of the world’s largest engineering teams—security isn’t peripheral here. It’s core to the value we deliver.
If you want to build something from scratch, own it end-to-end, and have your work matter immediately, this is that job. If you want a large team, an existing program to slot into, or mostly governance work, it probably isn’t.
Help evaluate whether to stand up an internal SIEM or work with an outsourced SOC provider—then implement whichever path makes sense for where we are as a company. If building internally: deploy and configure the SIEM,...
Browse similar: Startup jobs · Remote jobs