Security Engineer II

Security Engineer · Senior · Full Time

Mapbox USUSD 162k – 219k1mo ago
Apply for this role

Opens Mapbox's application page

Role

What you'll do.

Join Mapbox's Security & Compliance team as a Security Engineer II to build secure-by-default systems across a global AWS-native infrastructure serving 4+ million developers. In this role, you'll conduct comprehensive AWS security reviews, perform in-depth application security code reviews, operate custom-built security tooling, and partner with product teams to embed security into their infrastructure and design processes. This position requires 5+ years of product/application security experience, deep AWS expertise across services like GuardDuty and CloudTrail, and proficiency in programming languages such as Python, JavaScript, or TypeScript.

Responsibilities

  • Conduct AWS Security Reviews: Perform deep-dive security assessments of Mapbox's AWS environment spanning 7 global regions to validate adherence to security best practices, including evaluation of IAM policies, Security Groups, CloudFormation templates, and container-based ECS deployments. Identify misconfigurations and architectural security gaps in AWS-native infrastructure.
  • Security Improvement Implementation: Develop and recommend security enhancement strategies tailored to AWS deployments. Collaborate with production support teams to implement security improvements, including remediation of vulnerabilities, hardening of cloud resources, and optimization of security controls within the AWS environment.
  • Custom Security Tools Development and Maintenance: Partner with the Lead Security Architect to develop, deploy, and maintain custom-built security scanning and threat detection bots that monitor cloud deployments and digital assets. Contribute to automation tools that enforce security standards across Mapbox infrastructure.
  • Application Security Code Reviews: Conduct thorough security code reviews across application codebases, identifying vulnerabilities, secure coding violations, and design flaws early in development cycles. Work closely with engineering teams to provide actionable security guidance and establish secure-by-default coding practices.
  • Secure-by-Default Design Partnership: Collaborate with internal product teams to integrate security considerations into product architecture and design from inception. Facilitate threat modeling sessions, provide security architecture consultation, and establish security requirements for new product launches and vendor integrations.
  • Threat Detection and Monitoring: Operate and improve scanning and threat detection systems that monitor Mapbox's global cloud deployment for security incidents, anomalies, and compliance violations. Maintain vigilance across AWS services including GuardDuty and CloudTrail to detect and respond to potential threats.
  • Compliance and Standards Oversight: Build, maintain, and enforce core security, quality, and privacy standards reflected in Mapbox's compliance certifications. Develop automation to monitor and enforce standards across the organization and conduct risk assessments for new vendor integrations.
  • Bug Bounty Program Facilitation: Support and facilitate Mapbox's bug bounty program, engaging with the global community of security researchers to identify and address security vulnerabilities through coordinated disclosure processes.

Qualifications

What we look for.

Technical

  • AWS Security Services Expertise

    Deep proficiency with AWS security services including GuardDuty for threat detection, CloudTrail for logging and auditing, CloudFront for DDoS protection, CloudFormation for infrastructure-as-code security, S3 bucket policies and encryption, ECS container security, Lambda function security, DynamoDB encryption, and RDS database security. Experience with IAM policy design, Security Groups configuration, and cross-region security architecture.

  • Programming Language Proficiency

    Production-level expertise in at least one programming language such as Python, JavaScript, Node.js, or TypeScript. Ability to write security automation scripts, develop security tooling, review application code for vulnerabilities, and contribute to security infrastructure as code.

  • Security Code Analysis

    Hands-on experience with static and dynamic code analysis techniques, vulnerability scanning tools, and secure code review methodologies. Familiarity with common vulnerability patterns (OWASP Top 10), injection attacks, authentication/authorization flaws, and cryptographic implementation issues.

  • Cloud Security Architecture

    Demonstrated experience designing and implementing security architectures for cloud environments, including network segmentation, encryption strategies (in-transit and at-rest), identity and access management, secrets management, and zero-trust principles.

  • Container and Kubernetes Security

    Experience with container security in AWS ECS environments, including image scanning, runtime security, secrets management in containers, and container orchestration security considerations.

Education

  • Bachelor's Degree in Computer Science or Related Field

    Formal education in Computer Science, Cybersecurity, Information Security, Software Engineering, or equivalent discipline demonstrating foundational knowledge in computing principles, security theory, and software development methodologies.

Experience

  • Product/Application Security Experience

    Minimum 5+ years of professional experience in product security, application security, or closely related software engineering security roles. This should include hands-on security vulnerability assessment, secure code review, and security architecture design experience.

  • AWS Cloud Security Operations

    Proven track record of 3+ years managing and securing AWS cloud infrastructure at scale, including operational security, threat detection, incident response in cloud environments, and compliance monitoring.

  • Security Tooling and Automation

    Experience building, deploying, and maintaining security automation tools, scanning solutions, or threat detection systems that operate continuously across infrastructure environments.

  • Cross-Functional Security Collaboration

    Demonstrated ability to work effectively with development, operations, and product teams to integrate security into development lifecycles, conduct security training, and advocate for security best practices across technical organizations.

Skills

Required

  • AWS Security Services

    GuardDuty, CloudTrail, CloudFront, CloudFormation, S3, ECS, Lambda, DynamoDB, RDS, IAM, Security Groups

  • Application Security

    Secure code review, vulnerability assessment, threat modeling, OWASP principles, secure SDLC integration

  • Programming Languages

    Python, JavaScript, Node.js, TypeScript, or equivalent for automation and tooling

  • Testing Practices

    Security testing methodologies, unit testing, integration testing, penetration testing fundamentals

  • Technical Documentation

    Clear communication of complex security concepts, architecture documentation, security policies, and runbooks

  • Risk Assessment

    Ability to evaluate security risks, prioritize remediation efforts, and communicate risk impact to stakeholders

Preferred

  • Kubernetes Security

    Nice to have

    Experience securing Kubernetes clusters, RBAC configuration, network policies, and container orchestration security

  • Infrastructure-as-Code Security

    Nice to have

    Scanning and securing IaC templates (Terraform, CloudFormation) for configuration drift and compliance

  • Security Compliance Certifications

    Nice to have

    Knowledge of SOC 2, ISO 27001, HIPAA, GDPR, or other compliance frameworks relevant to SaaS platforms

  • Incident Response

    Nice to have

    Experience responding to security incidents, conducting root cause analysis, and implementing preventive controls

  • Bug Bounty Program Experience

    Nice to have

    Familiarity with coordinating vulnerability disclosures, managing researcher communications, and bug bounty platforms

  • Go Programming Language

    Nice to have

    Experience with Go for building performance-critical security tools and infrastructure components

  • Cloud Security Certifications

    Nice to have

    AWS Certified Security - Specialty, CISSP, CCSK, or equivalent industry-recognized cloud security credentials

Tech stack

Languages

PythonJavaScript/TypeScriptGo

Frameworks

AWS CloudFormationAWS CDK

Databases

Amazon DynamoDBAmazon RDSAmazon S3

Tools

Amazon GuardDutyAWS CloudTrailAWS IAMAmazon CloudFrontAWS LambdaAmazon ECS

Other

Static Application Security Testing (SAST)Dynamic Application Security Testing (DAST)Container Security ScanningCloud Security Posture Management (CSPM)Threat Modeling

Compensation

Pay and benefits.

Base·USD 161,500 – 218,500

Equity·Stock options

Benefits

  • Comprehensive Health Insurance Coverage

    Supportive healthcare benefits designed to ensure all Mapbox employees have access to medical, dental, and vision coverage with company contributions

  • Parental Leave

    Flexible and generous parental leave policies to support employees navigating major life changes and family responsibilities

  • Work Flexibility

    Remote work options and flexible scheduling to accommodate the varying needs that arise in life, supporting work-life balance

  • Professional Development and Learning

    Emphasis on continuous learning culture with opportunities for skill development, training, and career progression in security and cloud technologies

  • Diverse and Inclusive Workplace

    Commitment to building a diverse team that values and encourages individuals of all backgrounds, genders, ethnicities, abilities, and sexual orientations

  • Equity and Stock Options

    Stock options and equity participation opportunities allowing security engineers to share in company growth and success

Process

Interview steps.

  1. 01

    Initial Recruiter Screening

    Phone or video conversation with Mapbox recruiter to discuss background, experience in security engineering, AWS expertise, and alignment with team needs. This 30-minute call assesses your professional journey and motivation for joining the Security & Compliance team.

  2. 02

    Technical Screening Interview

    Deep technical discussion with a Security Engineer from the team covering AWS security architecture, specific service knowledge (GuardDuty, CloudTrail, IAM), hands-on experience with security tools, and approach to threat assessment. Prepare to discuss specific projects demonstrating your AWS security expertise.

  3. 03

    Hands-On Security Assessment

    Technical challenge or case study exercise evaluating your ability to conduct AWS security reviews, identify configuration vulnerabilities, recommend remediation strategies, and write security automation code. May involve code review tasks or security architecture design scenarios.

  4. 04

    Team and Manager Interview

    Extended conversations with your potential manager and security team members to assess collaboration style, security philosophy, communication approach, and cultural fit. Discussions typically cover your approach to working with developers, cross-functional security partnerships, and security advocacy.

  5. 05

    Final Executive/Leadership Round

    Meeting with senior security leadership or engineering leadership to discuss broader security strategy, industry trends, your vision for cloud security, and your understanding of Mapbox's security challenges serving 4+ million developers.

Full posting

Original listing.

Mapbox is the leading real-time location platform for a new generation of location-aware businesses. Mapbox is the only platform that equips organizations with the full set of tools to power the navigation of people, packages, and vehicles everywhere. More than 4 million registered developers have chosen Mapbox because of the platform’s flexibility, security and privacy compliance. Organizations use Mapbox applications, data, SDKs and APIs to create customized and immersive experiences that delight their customers. 

What We Do

Mapbox is looking for a Senior Cloud Security Engineer to join our Security & Compliance team. As a member of our diverse and globally distributed team, you’ll help all Mapbox engineers build secure-by-default systems. Engineers on the Security & Compliance team build scanning and threat detection systems to monitor Mapbox’s cloud deployment (AWS-native, mainly container-based, 7 global regions including China) and other digital assets. They conduct risk assessments of new vendor integrations and product launches, and facilitate a bug bounty program that leverages the diverse expertise of a global community of security researchers. Lastly, they build and maintain core standards around security, quality, and privacy—reflected in our compliance certifications—and the automation to monitor and enforce these standards across Mapbox.

What You'll Do

We’re excited to share our passion for scalable, engineering-driven, security with you, and for your perspective to help shape our team’s goals. You will be responsible for contributing to, operating, and improving all things related to our security and compliance services. In this role, you can expect to:

  • Conduct AWS security reviews (deep dive into our AWS environment to validate security best practices are being followed).

  • Make security improvements recommendations and work with our production support teams to implement security improvement in AWS.

  • Partner with the Lead Security Architect in fixing custom-built security tools bots.

  • Conduct in-depth security reviews of application code, working closely with developers to code securely from the outset and address issues early during coding and testing phases.

  • Partner with internal product teams to implement a secure-by-default design into their own products.

What We Believe are Important for This Role

  • Bachelor’s or higher degree in Computer Science or similar

  • 5+ years of experience in product or application security and related software engineering roles

  • Experience with AWS services like GuardDuty, CloudTrail log review, IAM, Security Groups, CloudFront, CloudFormation, S3, ECS, Lambda, DynamoDB and RDS.

  • Proficiency in a programming language (e.g. Python, JavaScript or Node.js or TypeScript), testing practices, and documentation.

  • Subject matter expertise in security best practices and the ability to quickly make correct risk assessments that prioritize the overall benefit to the company.

 What We Value

In addition to our core values, which are not unique to this position and are necessary for Mapbox leaders:

  • We value high-performing creative individuals who dig into problems and opportunities.

  • We believe in individuals being their whole selves at work. We commit to this through supportive health care, parental leave, flexibility for the things that come up in life, and innovating on how we think about supporting our people.

  • We emphasize an environment of teaching and learning to equip employees with the tools needed to be successful in their function and the company.

  • We strongly believe in the value of growing a diverse team and encourage people of all backgrounds, genders, ethnicities, abilities, and sexual orientations to apply.

Our annual base compensation for this role ranges from $161,500 - $218,500 for most US locations and 5% to 10% higher for US locations with a higher cost of labor. Job level and actual compensation will be decided based on factors including, but not limited to, individual qualifications objectively assessed during the interview process (including skills and prior relevant experience, potential impact, and scope of role), market demands, and specific work location. Please discuss your specific work location with your recruiter for more information.

By applying for this position, you acknowledge that you agree to the Mapbox Privacy Policy which is linked here.

Mapbox participates in E-Verify to confirm employee work authorization. Please refer to the Notice of E-Verify Participation and Right to Work posters for more information.

We are committed to a fair and equitable hiring process. We do not discriminate against any protected class.

#LI-Remote

Redirects to Mapbox's application page.

Other roles

More at Mapbox.

View all 7 roles