Mapbox

Security Engineer II

MapboxYesterday
Location

Mapbox US

Type

Full Time

Salary

USD 161,500 – 218,500

Level

Senior

Role

Security Engineer

Posted

Jul 24, 2026

Full TimeSenior

The role

Summary

Join Mapbox's Security & Compliance team as a Security Engineer II to build secure-by-default systems across a global AWS-native infrastructure serving 4+ million developers. In this role, you'll conduct comprehensive AWS security reviews, perform in-depth application security code reviews, operate custom-built security tooling, and partner with product teams to embed security into their infrastructure and design processes. This position requires 5+ years of product/application security experience, deep AWS expertise across services like GuardDuty and CloudTrail, and proficiency in programming languages such as Python, JavaScript, or TypeScript.

What you'll do

Conduct AWS Security Reviews: Perform deep-dive security assessments of Mapbox's AWS environment spanning 7 global regions to validate adherence to security best practices, including evaluation of IAM policies, Security Groups, CloudFormation templates, and container-based ECS deployments. Identify misconfigurations and architectural security gaps in AWS-native infrastructure.
Security Improvement Implementation: Develop and recommend security enhancement strategies tailored to AWS deployments. Collaborate with production support teams to implement security improvements, including remediation of vulnerabilities, hardening of cloud resources, and optimization of security controls within the AWS environment.
Custom Security Tools Development and Maintenance: Partner with the Lead Security Architect to develop, deploy, and maintain custom-built security scanning and threat detection bots that monitor cloud deployments and digital assets. Contribute to automation tools that enforce security standards across Mapbox infrastructure.
Application Security Code Reviews: Conduct thorough security code reviews across application codebases, identifying vulnerabilities, secure coding violations, and design flaws early in development cycles. Work closely with engineering teams to provide actionable security guidance and establish secure-by-default coding practices.
Secure-by-Default Design Partnership: Collaborate with internal product teams to integrate security considerations into product architecture and design from inception. Facilitate threat modeling sessions, provide security architecture consultation, and establish security requirements for new product launches and vendor integrations.
Threat Detection and Monitoring: Operate and improve scanning and threat detection systems that monitor Mapbox's global cloud deployment for security incidents, anomalies, and compliance violations. Maintain vigilance across AWS services including GuardDuty and CloudTrail to detect and respond to potential threats.
Compliance and Standards Oversight: Build, maintain, and enforce core security, quality, and privacy standards reflected in Mapbox's compliance certifications. Develop automation to monitor and enforce standards across the organization and conduct risk assessments for new vendor integrations.
Bug Bounty Program Facilitation: Support and facilitate Mapbox's bug bounty program, engaging with the global community of security researchers to identify and address security vulnerabilities through coordinated disclosure processes.

What we look for

Technical

AWS Security Services ExpertiseDeep proficiency with AWS security services including GuardDuty for threat detection, CloudTrail for logging and auditing, CloudFront for DDoS protection, CloudFormation for infrastructure-as-code security, S3 bucket policies and encryption, ECS container security, Lambda function security, DynamoDB encryption, and RDS database security. Experience with IAM policy design, Security Groups configuration, and cross-region security architecture.
Programming Language ProficiencyProduction-level expertise in at least one programming language such as Python, JavaScript, Node.js, or TypeScript. Ability to write security automation scripts, develop security tooling, review application code for vulnerabilities, and contribute to security infrastructure as code.
Security Code AnalysisHands-on experience with static and dynamic code analysis techniques, vulnerability scanning tools, and secure code review methodologies. Familiarity with common vulnerability patterns (OWASP Top 10), injection attacks, authentication/authorization flaws, and cryptographic implementation issues.
Cloud Security ArchitectureDemonstrated experience designing and implementing security architectures for cloud environments, including network segmentation, encryption strategies (in-transit and at-rest), identity and access management, secrets management, and zero-trust principles.
Container and Kubernetes SecurityExperience with container security in AWS ECS environments, including image scanning, runtime security, secrets management in containers, and container orchestration security considerations.

Education

Bachelor's Degree in Computer Science or Related FieldFormal education in Computer Science, Cybersecurity, Information Security, Software Engineering, or equivalent discipline demonstrating foundational knowledge in computing principles, security theory, and software development methodologies.

Experience

Product/Application Security ExperienceMinimum 5+ years of professional experience in product security, application security, or closely related software engineering security roles. This should include hands-on security vulnerability assessment, secure code review, and security architecture design experience.
AWS Cloud Security OperationsProven track record of 3+ years managing and securing AWS cloud infrastructure at scale, including operational security, threat detection, incident response in cloud environments, and compliance monitoring.
Security Tooling and AutomationExperience building, deploying, and maintaining security automation tools, scanning solutions, or threat detection systems that operate continuously across infrastructure environments.
Cross-Functional Security CollaborationDemonstrated ability to work effectively with development, operations, and product teams to integrate security into development lifecycles, conduct security training, and advocate for security best practices across technical organizations.

Skills

Required skills

AWS Security ServicesGuardDuty, CloudTrail, CloudFront, CloudFormation, S3, ECS, Lambda, DynamoDB, RDS, IAM, Security Groups
Application SecuritySecure code review, vulnerability assessment, threat modeling, OWASP principles, secure SDLC integration
Programming LanguagesPython, JavaScript, Node.js, TypeScript, or equivalent for automation and tooling
Testing PracticesSecurity testing methodologies, unit testing, integration testing, penetration testing fundamentals
Technical DocumentationClear communication of complex security concepts, architecture documentation, security policies, and runbooks
Risk AssessmentAbility to evaluate security risks, prioritize remediation efforts, and communicate risk impact to stakeholders

Nice to have

Kubernetes SecurityExperience securing Kubernetes clusters, RBAC configuration, network policies, and container orchestration security
Infrastructure-as-Code SecurityScanning and securing IaC templates (Terraform, CloudFormation) for configuration drift and compliance
Security Compliance CertificationsKnowledge of SOC 2, ISO 27001, HIPAA, GDPR, or other compliance frameworks relevant to SaaS platforms
Incident ResponseExperience responding to security incidents, conducting root cause analysis, and implementing preventive controls
Bug Bounty Program ExperienceFamiliarity with coordinating vulnerability disclosures, managing researcher communications, and bug bounty platforms
Go Programming LanguageExperience with Go for building performance-critical security tools and infrastructure components
Cloud Security CertificationsAWS Certified Security - Specialty, CISSP, CCSK, or equivalent industry-recognized cloud security credentials

Compensation & benefits

Salary

USD 161,500 – 218,500 (annual)

Stock options

Available

Benefits

Comprehensive Health Insurance Coverage

Supportive healthcare benefits designed to ensure all Mapbox employees have access to medical, dental, and vision coverage with company contributions

Parental Leave

Flexible and generous parental leave policies to support employees navigating major life changes and family responsibilities

Work Flexibility

Remote work options and flexible scheduling to accommodate the varying needs that arise in life, supporting work-life balance

Professional Development and Learning

Emphasis on continuous learning culture with opportunities for skill development, training, and career progression in security and cloud technologies

Diverse and Inclusive Workplace

Commitment to building a diverse team that values and encourages individuals of all backgrounds, genders, ethnicities, abilities, and sexual orientations

Equity and Stock Options

Stock options and equity participation opportunities allowing security engineers to share in company growth and success


Interview process

  1. 1
    Initial Recruiter Screening Phone or video conversation with Mapbox recruiter to discuss background, experience in security engineering, AWS expertise, and alignment with team needs. This 30-minute call assesses your professional journey and motivation for joining the Security & Compliance team.
  2. 2
    Technical Screening Interview Deep technical discussion with a Security Engineer from the team covering AWS security architecture, specific service knowledge (GuardDuty, CloudTrail, IAM), hands-on experience with security tools, and approach to threat assessment. Prepare to discuss specific projects demonstrating your AWS security expertise.
  3. 3
    Hands-On Security Assessment Technical challenge or case study exercise evaluating your ability to conduct AWS security reviews, identify configuration vulnerabilities, recommend remediation strategies, and write security automation code. May involve code review tasks or security architecture design scenarios.
  4. 4
    Team and Manager Interview Extended conversations with your potential manager and security team members to assess collaboration style, security philosophy, communication approach, and cultural fit. Discussions typically cover your approach to working with developers, cross-functional security partnerships, and security advocacy.
  5. 5
    Final Executive/Leadership Round Meeting with senior security leadership or engineering leadership to discuss broader security strategy, industry trends, your vision for cloud security, and your understanding of Mapbox's security challenges serving 4+ million developers.

Apply for this position

You'll be redirected to the company's application page


Mapbox

Mapbox

View all jobs

Mapbox is an American mapping platform providing location data and customization tools.

Washington, D.C., United StatesFounded 2010mapbox.com

Tech Stack

Languages
PythonJavaScript/TypeScriptGo
Frameworks
AWS CloudFormationAWS CDK
Databases
Amazon DynamoDBAmazon RDSAmazon S3
Tools
Amazon GuardDutyAWS CloudTrailAWS IAMAmazon CloudFrontAWS LambdaAmazon ECS
Other
Static Application Security Testing (SAST)Dynamic Application Security Testing (DAST)Container Security ScanningCloud Security Posture Management (CSPM)Threat Modeling

Interview Guides

8 guides available for Mapbox

Apply Now