Product Security Engineer II

Flexport

Netherlands

On-site

EUR 70,000 - 90,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Catered lunches
Health insurance
Pension contribution
Equity program
Parental leave benefit
Employee Assistance Program

Job summary

Flexport is looking for a Product Security Engineer II in the Netherlands. This role involves identifying security risks, building security tools, and collaborating closely with product teams to ensure secure software development. You will work on enhancing product security by developing innovative solutions and addressing emerging threats.

Join Flexport and contribute to making global trade secure while enjoying benefits such as health insurance, equity programs, and opportunities for professional growth.

Qualifications

  • 2-5 years of experience in product/application security or software development with a security focus.
  • Strong grasp of web application security principles and common attack vectors (e.g., OWASP Top 10).
  • Proficiency with application testing tools such as Burp Suite, OWASP ZAP, or browser developer tools.
  • Working knowledge of at least one modern programming language (e.g., Ruby, Java/Kotlin, TypeScript/JavaScript, Python).
  • Working knowledge of at least one major cloud provider (AWS, GCP, Azure).
  • Hands-on experience with SAST tools (Cycode, Semgrep, Snyk, or similar).
  • Experience improving developer experience (DevEx) security without slowing teams down.
  • Clear, constructive communicator on technical risk – in writing, in code review, and in conversation.
  • Collaborative by default: you partner with developers, SREs, and security peers rather than handing down mandates.
  • Comfortable with security on-call rotation and picking up work across security disciplines when needed.

Responsibilities

  • Build guardrails and AI-accelerated patterns that make secure-by-default the path of least resistance.
  • Build and maintain security tooling and automation that scales product security.
  • Respond to emerging threats.
  • Contribute to threat modeling, design reviews, and code reviews.
  • Partner with engineering to security-review and test new features and services.
  • Triage, reproduce, and validate incoming bug bounty submissions and internal security reports.
  • Cut through SAST and vulnerability scanner noise to prioritize real issues.
  • Write clear, actionable security patterns for developers.
  • Stay current on web and cloud security trends.

Skills

Product/application security experience
Web application security principles
Application testing tools proficiency
Modern programming language knowledge
Cloud provider knowledge
SAST tools experience
Developer experience security improvement
Clear communication on technical risk
Collaborative mindset

Tools

Burp Suite
OWASP ZAP
Browser developer tools

Job description

Product Security Engineer II

Flexport is looking for Product Security Engineers to help Flexport establish itself as the most trusted company in the global trade ecosystem. As a Product Security Engineer, you’ll develop a deep understanding of product development and strategy, and will be able to quickly identify and communicate security risks to diverse audiences while offering alternative solutions.

All security disciplines work under the umbrella of the PSI (Platform, Security & Infrastructure) team: we build the paved path and tooling that hundreds of engineers around the world rely on every day to ship. Security gains massive leverage by working hand in hand with Platform and Infrastructure, with every element of the team reinforcing each of the others.

This is not a role where you wait for tickets. You’ll build the tools that our product teams reach for when they want a secure‑by‑default solution. You’ll discover what tools to build by working with our product teams at every stage of the software development lifecycle, and you’ll proactively analyze what they produce to find the flaws before the bad guys do.

What You’ll Do

Strategy & Foundations

  • Build guardrails and AI‑accelerated patterns that make secure‑by‑default the path of least resistance for developers.
  • Build and maintain security tooling and automation that scales product security.
  • Respond to emerging threats.

Design‑time & Review

  • Contribute to threat modeling, design reviews, and code reviews with pragmatic guidance that balances risk against velocity.
  • Partner with engineering to security‑review and test new features and services as they’re built.

Vulnerability Management

  • Triage, reproduce, and validate incoming bug bounty submissions and internal security reports.
  • Cut through SAST, secrets, and vulnerability scanner noise to prioritize real issues and guide developers to effective fixes.
  • Partner with development teams to drive remediation and track issues through closure.

Developer Enablement

  • Write clear, actionable security patterns that let developers ship fast and stay secure.
  • Write and maintain runbooks, developer guidelines, and security documentation that scale the team's practices.
  • Stay current on web and cloud security trends and bring new findings into product discussions.
You Should Have
  • 2‑5 years of experience in product/application security or software development with a security focus.
  • Strong grasp of web application security principles and common attack vectors (e.g., OWASP Top 10).
  • Proficiency with application testing tools such as Burp Suite, OWASP ZAP, or browser developer tools.
  • Working knowledge of at least one modern programming language (e.g., Ruby, Java/Kotlin, TypeScript/JavaScript, Python).
  • Working knowledge of at least one major cloud provider (AWS, GCP, Azure).
  • Hands‑on experience with SAST tools (Cycode, Semgrep, Snyk, or similar).
  • Experience improving developer experience (DevEx) security without slowing teams down.
  • Clear, constructive communicator on technical risk – in writing, in code review, and in conversation.
  • Collaborative by default: you partner with developers, SREs, and security peers rather than handing down mandates.
  • Comfortable with security on‑call rotation and picking up work across security disciplines when needed.
Nice to Have
  • Hands‑on experience with bug bounty platforms.
  • Experience with cloud infrastructure security (AWS, GCP, Azure) and container technologies.
  • Participation in CTF events or open‑source security projects.
  • Familiarity with threat modeling frameworks and secure SDLC best practices.
  • Interest in contributing to internal developer security training programs.
How We Work
  • In Amsterdam we come to the office three times a week to hang out, whiteboard, and ship together.
  • We stay closely aligned with our coworkers on other continents.
  • We have the latest hardware and software, including frontier AI models on day one.
  • We’re agile, but not dogmatic. Teams decide how they work best.
Why This Role Is Special
  • Massive leverage: every improvement you ship is multiplied across hundreds of engineers and thousands of deploys a day.
  • Full ownership: from developer research to production rollout to measuring impact, it’s yours.
  • You shape the paved path: the conventions you set and decisions you make become how Flexport engineering builds for years to come.
What’s in it for you
  • An opportunity to contribute to one of the fastest‑growing companies, where you’ll have the chance to create a global impact while being a part of a thriving multinational environment.
  • Daily catered lunches incl. vegetarian options, breakfast, snacks and soft drinks available in our office on a daily basis.
  • Commute expenses: Flexport will cover home‑office commuting costs for employees living outside of Amsterdam.
  • 25 working days as vacation days based on full time employment.
  • Health insurance: Flexport offers a collective health insurance plan including a basic package and any available additional packages. Your monthly premium is fully paid by Flexport.
  • A defined pension contribution scheme.
  • Equity program: every team member becomes a shareholder, aligning our success with yours. As a private company in a multi‑trillion dollar industry, you have a direct stake in our collective growth and success.
  • Employee Assistance Program through Aetna Resources for Living: Flexport provides an employer‑sponsored program at no cost to you and your household members.
  • Parental leave benefit: Flexport is here to support you and your families in one of the most important times in life – the birth of a child! Our parental leave program allows both mothers and partners to take time off from work for pregnancy, childbirth, and to bond with your new child.
Commitment to Equal Opportunity

At Flexport, our ability to fulfill our mission of making global commerce easy and accessible relies on having a diverse, dedicated and engaged workforce. All qualified applicants will receive consideration for employment regardless of race, color, religion, sex, national origin, age, physical and mental disability, health status, marital and family status, sexual orientation, gender identity and expression, military and veteran status, and any other characteristic protected by applicable law.

Global Data Privacy Notice for Job Candidates and Applicants

Depending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. By submitting your application, you are agreeing to our use and processing of your data as required. Please see our Privacy Notice available at https://www.flexport.com/privacy for additional information.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Security Engineer II
Product Security Engineer II

Voiceflow • Amsterdam

Hybrid
EUR 65,000 - 90,000
Daily catered lunches
Commute expenses covered
Health insurance
+2
Senior Software Engineer: Platform
Senior Software Engineer: Platform

Voiceflow • Amsterdam

On-site
EUR 70,000 - 90,000
Daily catered lunches
Health insurance
Pension contribution
+1
Senior Software Engineer: Data Infrastructure
Senior Software Engineer: Data Infrastructure

Flexport • Amsterdam

On-site
EUR 55,000 - 75,000
Daily catered lunches
Commute expenses covered
Health insurance
+3
Senior Software Engineer: Data Infrastructure
Senior Software Engineer: Data Infrastructure

Voiceflow • Amsterdam

Hybrid
EUR 65,000 - 85,000
Daily catered lunches
Health insurance with premium covered
25 working days of vacation
+2
Senior Software Engineer, Applied AI
Senior Software Engineer, Applied AI

Flexport • Amsterdam

On-site
EUR 130,000 - 190,000
Daily catered lunches
Commuting costs covered
Health insurance
+5
Staff Software Engineer: Applied AI
Staff Software Engineer: Applied AI

Flexport • Amsterdam

On-site
EUR 75,000 - 95,000
Daily catered lunches
Commuting costs covered
25 working days of vacation
+3
Senior Software Engineer, Customs
Senior Software Engineer, Customs

Flexport • Amsterdam

On-site
EUR 120,000 - 180,000
Health insurance
Equity program
Pension contribution
+4
Staff Software Engineer: Applied AI
Staff Software Engineer: Applied AI

Voiceflow • Amsterdam

On-site
EUR 80,000 - 120,000
Daily catered lunches
Health insurance
Parental leave benefit
+1
Account Executive, Enterprise
Account Executive, Enterprise

Flexport • Amsterdam

On-site
EUR 45,000 - 65,000
Daily catered lunches
Health insurance
Equity program
+1
Senior Software Engineer: Applied AI
Senior Software Engineer: Applied AI

Voiceflow • Amsterdam

On-site
EUR 70,000 - 90,000
Agile working environment
Latest hardware
Career growth opportunities