Security Engineer II
Security Engineer · Senior · Full Time
Opens Mapbox's application page
Role
What you'll do.
Join Mapbox's Security & Compliance team as a Security Engineer II to build secure-by-default systems across a global AWS-native infrastructure serving 4+ million developers. In this role, you'll conduct comprehensive AWS security reviews, perform in-depth application security code reviews, operate custom-built security tooling, and partner with product teams to embed security into their infrastructure and design processes. This position requires 5+ years of product/application security experience, deep AWS expertise across services like GuardDuty and CloudTrail, and proficiency in programming languages such as Python, JavaScript, or TypeScript.
Responsibilities
- Conduct AWS Security Reviews: Perform deep-dive security assessments of Mapbox's AWS environment spanning 7 global regions to validate adherence to security best practices, including evaluation of IAM policies, Security Groups, CloudFormation templates, and container-based ECS deployments. Identify misconfigurations and architectural security gaps in AWS-native infrastructure.
- Security Improvement Implementation: Develop and recommend security enhancement strategies tailored to AWS deployments. Collaborate with production support teams to implement security improvements, including remediation of vulnerabilities, hardening of cloud resources, and optimization of security controls within the AWS environment.
- Custom Security Tools Development and Maintenance: Partner with the Lead Security Architect to develop, deploy, and maintain custom-built security scanning and threat detection bots that monitor cloud deployments and digital assets. Contribute to automation tools that enforce security standards across Mapbox infrastructure.
- Application Security Code Reviews: Conduct thorough security code reviews across application codebases, identifying vulnerabilities, secure coding violations, and design flaws early in development cycles. Work closely with engineering teams to provide actionable security guidance and establish secure-by-default coding practices.
- Secure-by-Default Design Partnership: Collaborate with internal product teams to integrate security considerations into product architecture and design from inception. Facilitate threat modeling sessions, provide security architecture consultation, and establish security requirements for new product launches and vendor integrations.
- Threat Detection and Monitoring: Operate and improve scanning and threat detection systems that monitor Mapbox's global cloud deployment for security incidents, anomalies, and compliance violations. Maintain vigilance across AWS services including GuardDuty and CloudTrail to detect and respond to potential threats.
- Compliance and Standards Oversight: Build, maintain, and enforce core security, quality, and privacy standards reflected in Mapbox's compliance certifications. Develop automation to monitor and enforce standards across the organization and conduct risk assessments for new vendor integrations.
- Bug Bounty Program Facilitation: Support and facilitate Mapbox's bug bounty program, engaging with the global community of security researchers to identify and address security vulnerabilities through coordinated disclosure processes.
Qualifications
What we look for.
Technical
AWS Security Services Expertise
Deep proficiency with AWS security services including GuardDuty for threat detection, CloudTrail for logging and auditing, CloudFront for DDoS protection, CloudFormation for infrastructure-as-code security, S3 bucket policies and encryption, ECS container security, Lambda function security, DynamoDB encryption, and RDS database security. Experience with IAM policy design, Security Groups configuration, and cross-region security architecture.
Programming Language Proficiency
Production-level expertise in at least one programming language such as Python, JavaScript, Node.js, or TypeScript. Ability to write security automation scripts, develop security tooling, review application code for vulnerabilities, and contribute to security infrastructure as code.
Security Code Analysis
Hands-on experience with static and dynamic code analysis techniques, vulnerability scanning tools, and secure code review methodologies. Familiarity with common vulnerability patterns (OWASP Top 10), injection attacks, authentication/authorization flaws, and cryptographic implementation issues.
Cloud Security Architecture
Demonstrated experience designing and implementing security architectures for cloud environments, including network segmentation, encryption strategies (in-transit and at-rest), identity and access management, secrets management, and zero-trust principles.
Container and Kubernetes Security
Experience with container security in AWS ECS environments, including image scanning, runtime security, secrets management in containers, and container orchestration security considerations.
Education
Bachelor's Degree in Computer Science or Related Field
Formal education in Computer Science, Cybersecurity, Information Security, Software Engineering, or equivalent discipline demonstrating foundational knowledge in computing principles, security theory, and software development methodologies.
Experience
Product/Application Security Experience
Minimum 5+ years of professional experience in product security, application security, or closely related software engineering security roles. This should include hands-on security vulnerability assessment, secure code review, and security architecture design experience.
AWS Cloud Security Operations
Proven track record of 3+ years managing and securing AWS cloud infrastructure at scale, including operational security, threat detection, incident response in cloud environments, and compliance monitoring.
Security Tooling and Automation
Experience building, deploying, and maintaining security automation tools, scanning solutions, or threat detection systems that operate continuously across infrastructure environments.
Cross-Functional Security Collaboration
Demonstrated ability to work effectively with development, operations, and product teams to integrate security into development lifecycles, conduct security training, and advocate for security best practices across technical organizations.
Skills
Required
AWS Security Services
GuardDuty, CloudTrail, CloudFront, CloudFormation, S3, ECS, Lambda, DynamoDB, RDS, IAM, Security Groups
Application Security
Secure code review, vulnerability assessment, threat modeling, OWASP principles, secure SDLC integration
Programming Languages
Python, JavaScript, Node.js, TypeScript, or equivalent for automation and tooling
Testing Practices
Security testing methodologies, unit testing, integration testing, penetration testing fundamentals
Technical Documentation
Clear communication of complex security concepts, architecture documentation, security policies, and runbooks
Risk Assessment
Ability to evaluate security risks, prioritize remediation efforts, and communicate risk impact to stakeholders
Preferred
Kubernetes Security
Nice to haveExperience securing Kubernetes clusters, RBAC configuration, network policies, and container orchestration security
Infrastructure-as-Code Security
Nice to haveScanning and securing IaC templates (Terraform, CloudFormation) for configuration drift and compliance
Security Compliance Certifications
Nice to haveKnowledge of SOC 2, ISO 27001, HIPAA, GDPR, or other compliance frameworks relevant to SaaS platforms
Incident Response
Nice to haveExperience responding to security incidents, conducting root cause analysis, and implementing preventive controls
Bug Bounty Program Experience
Nice to haveFamiliarity with coordinating vulnerability disclosures, managing researcher communications, and bug bounty platforms
Go Programming Language
Nice to haveExperience with Go for building performance-critical security tools and infrastructure components
Cloud Security Certifications
Nice to haveAWS Certified Security - Specialty, CISSP, CCSK, or equivalent industry-recognized cloud security credentials
Tech stack
Languages
Frameworks
Databases
Tools
Other
Compensation
Pay and benefits.
Base·USD 161,500 – 218,500
Equity·Stock options
Benefits
Comprehensive Health Insurance Coverage
Supportive healthcare benefits designed to ensure all Mapbox employees have access to medical, dental, and vision coverage with company contributions
Parental Leave
Flexible and generous parental leave policies to support employees navigating major life changes and family responsibilities
Work Flexibility
Remote work options and flexible scheduling to accommodate the varying needs that arise in life, supporting work-life balance
Professional Development and Learning
Emphasis on continuous learning culture with opportunities for skill development, training, and career progression in security and cloud technologies
Diverse and Inclusive Workplace
Commitment to building a diverse team that values and encourages individuals of all backgrounds, genders, ethnicities, abilities, and sexual orientations
Equity and Stock Options
Stock options and equity participation opportunities allowing security engineers to share in company growth and success
Process
Interview steps.
- 01
Initial Recruiter Screening
Phone or video conversation with Mapbox recruiter to discuss background, experience in security engineering, AWS expertise, and alignment with team needs. This 30-minute call assesses your professional journey and motivation for joining the Security & Compliance team.
- 02
Technical Screening Interview
Deep technical discussion with a Security Engineer from the team covering AWS security architecture, specific service knowledge (GuardDuty, CloudTrail, IAM), hands-on experience with security tools, and approach to threat assessment. Prepare to discuss specific projects demonstrating your AWS security expertise.
- 03
Hands-On Security Assessment
Technical challenge or case study exercise evaluating your ability to conduct AWS security reviews, identify configuration vulnerabilities, recommend remediation strategies, and write security automation code. May involve code review tasks or security architecture design scenarios.
- 04
Team and Manager Interview
Extended conversations with your potential manager and security team members to assess collaboration style, security philosophy, communication approach, and cultural fit. Discussions typically cover your approach to working with developers, cross-functional security partnerships, and security advocacy.
- 05
Final Executive/Leadership Round
Meeting with senior security leadership or engineering leadership to discuss broader security strategy, industry trends, your vision for cloud security, and your understanding of Mapbox's security challenges serving 4+ million developers.
Full posting
Original listing.
Mapbox is the leading real-time location platform for a new generation of location-aware businesses. Mapbox is the only platform that equips organizations with the full set of tools to power the navigation of people, packages, and vehicles everywhere. More than 4 million registered developers have chosen Mapbox because of the platform’s flexibility, security and privacy compliance. Organizations use Mapbox applications, data, SDKs and APIs to create customized and immersive experiences that delight their customers.
What We Do
Mapbox is looking for a Senior Cloud Security Engineer to join our Security & Compliance team. As a member of our diverse and globally distributed team, you’ll help all Mapbox engineers build secure-by-default systems. Engineers on the Security & Compliance team build scanning and threat detection systems to monitor Mapbox’s cloud deployment (AWS-native, mainly container-based, 7 global regions including China) and other digital assets. They conduct risk assessments of new vendor integrations and product launches, and facilitate a bug bounty program that leverages the diverse expertise of a global community of security researchers. Lastly, they build and maintain core standards around security, quality, and privacy—reflected in our compliance certifications—and the automation to monitor and enforce these standards across Mapbox.
What You'll Do
We’re excited to share our passion for scalable, engineering-driven, security with you, and for your perspective to help shape our team’s goals. You will be responsible for contributing to, operating, and improving all things related to our security and compliance services. In this role, you can expect to:
Conduct AWS security reviews (deep dive into our AWS environment to validate security best practices are being followed).
Make security improvements recommendations and work with our production support teams to implement security improvement in AWS.
Partner with the Lead Security Architect in fixing custom-built security tools bots.
Conduct in-depth security reviews of application code, working closely with developers to code securely from the outset and address issues early during coding and testing phases.
Partner with internal product teams to implement a secure-by-default design into their own products.
What We Believe are Important for This Role
Bachelor’s or higher degree in Computer Science or similar
5+ years of experience in product or application security and related software engineering roles
Experience with AWS services like GuardDuty, CloudTrail log review, IAM, Security Groups, CloudFront, CloudFormation, S3, ECS, Lambda, DynamoDB and RDS.
Proficiency in a programming language (e.g. Python, JavaScript or Node.js or TypeScript), testing practices, and documentation.
Subject matter expertise in security best practices and the ability to quickly make correct risk assessments that prioritize the overall benefit to the company.
What We Value
In addition to our core values, which are not unique to this position and are necessary for Mapbox leaders:
We value high-performing creative individuals who dig into problems and opportunities.
We believe in individuals being their whole selves at work. We commit to this through supportive health care, parental leave, flexibility for the things that come up in life, and innovating on how we think about supporting our people.
We emphasize an environment of teaching and learning to equip employees with the tools needed to be successful in their function and the company.
We strongly believe in the value of growing a diverse team and encourage people of all backgrounds, genders, ethnicities, abilities, and sexual orientations to apply.
Our annual base compensation for this role ranges from $161,500 - $218,500 for most US locations and 5% to 10% higher for US locations with a higher cost of labor. Job level and actual compensation will be decided based on factors including, but not limited to, individual qualifications objectively assessed during the interview process (including skills and prior relevant experience, potential impact, and scope of role), market demands, and specific work location. Please discuss your specific work location with your recruiter for more information.
By applying for this position, you acknowledge that you agree to the Mapbox Privacy Policy which is linked here.
Mapbox participates in E-Verify to confirm employee work authorization. Please refer to the Notice of E-Verify Participation and Right to Work posters for more information.
We are committed to a fair and equitable hiring process. We do not discriminate against any protected class.
#LI-Remote
Redirects to Mapbox's application page.
Other roles
More at Mapbox.
Security Engineer II
Senior
Software Development Engineer I (Data Engineer), HD Maps
Junior
Senior/Lead Software Data Engineer (Roads Team)
Senior
Senior/Lead Software Data Engineer (Roads Team)
Senior
Software Development Engineer II (Full-stack Engineer)
Senior