# Security Engineer at flox

- Company: flox
- What the company does: Flox gives platform teams one declared environment that stays reproducible for every developer and agent, from the first commit through to production. Backed by NEA.
- Company website: https://floxdev.com/
- Type: Startups
- Level: Mid level
- Location: Remote
- Work setup: Remote
- Pay: $160K to $210K base salary per year (USD)
- Posted: 2026-04-28
- Apply by: 2026-10-08
- Apply: https://jobs.ashbyhq.com/flox/37ec9578-4fab-432f-88f1-c130ffe13ac8
- Page: https://www.1752.vc/careers/jobs/flox-security-engineer/

## About the role

This is Flox’s first dedicated security hire. You’ll work directly with engineering leadership to stand up security practices that are pragmatic, developer-friendly, and right-sized for a company at our stage. The role is heavily weighted toward doing—you’ll be the one deploying tools, configuring controls, hardening infrastructure, and closing gaps, not just advising others to do so.

## What they're looking for

- 3–5 years of hands-on security engineering experience, ideally at a software company or cloud-native environment
- A demonstrable track record of implementing security tools and controls, not just scoping or recommending them
- Solid working knowledge of AWS security services: IAM, SCPs, GuardDuty, Security Hub, CloudTrail, and related tooling
- Hands-on experience with Cloudflare—WAF rule management, Zero Trust, DLP, or similar, comfort learning what you haven’t used yet
- Experience deploying and managing endpoint protection (EDR/MDM) across a mixed developer and production environment
- Familiarity with software supply chain concepts: SBOMs, dependency management, artifact signing, SLSA

Tags: Engineering
