Security Engineer II

Security Engineer · Senior · Full Time · Remote

Mapbox Helsinki · RemoteUSD 165k – 220k4d ago
Apply for this role

Opens Mapbox's application page

Role

What you'll do.

Join Mapbox's Security & Compliance team as a Security Engineer II to architect and implement secure-by-default systems across a globally distributed AWS infrastructure serving 4+ million developers. This role combines cloud security expertise, threat detection systems development, and secure code review practices to protect Mapbox's real-time location platform across 7 global regions. You'll conduct AWS security assessments, build compliance automation, and partner with engineering teams to embed security into the product development lifecycle.

Responsibilities

  • AWS Security Architecture & Review: Conduct comprehensive AWS security reviews and deep-dive assessments of Mapbox's cloud environment across 7 global regions to validate adherence to security best practices. Analyze AWS services including GuardDuty, CloudTrail, IAM policies, Security Groups, CloudFront, CloudFormation, S3, ECS, Lambda, DynamoDB, and RDS to identify misconfigurations and security vulnerabilities.
  • Security Improvements & Implementation: Develop detailed security improvement recommendations and partner with production support teams to implement infrastructure hardening initiatives. Track remediation efforts across cloud deployments, manage risk prioritization, and ensure security controls align with business objectives and compliance requirements.
  • Security Tools & Automation: Collaborate with the Lead Security Architect to develop, maintain, and fix custom-built security scanning and threat detection systems and bots. Build automation frameworks to monitor and enforce security standards and compliance certifications across Mapbox's container-based infrastructure and digital assets.
  • Application Security & Code Review: Conduct in-depth security code reviews of application source code, working closely with product engineers to identify vulnerabilities early in the development lifecycle. Provide actionable guidance on secure coding practices, threat modeling, and secure-by-default design patterns for development teams.
  • Product Security Integration: Partner with internal product teams and engineering organizations to embed security requirements into product roadmaps, design processes, and deployment pipelines. Facilitate secure-by-default architecture adoption and establish security standards that become foundational to platform development.
  • On-Call Response & Incident Management: Participate in rotating on-call responsibilities to ensure continuous availability and rapid response to security incidents affecting customer-facing systems. Respond to incidents 24/7 including evenings and weekends, conduct incident analysis, and implement post-incident remediation to prevent recurrence.
  • Compliance & Risk Assessment: Conduct thorough risk assessments of new vendor integrations and product launches before production deployment. Facilitate security researcher engagement through bug bounty program operations, coordinate vulnerability disclosure processes, and maintain compliance documentation for relevant certifications.

Qualifications

What we look for.

Technical

  • AWS Cloud Security Expertise

    Advanced proficiency with AWS security services and architecture patterns including GuardDuty for threat detection, CloudTrail for audit logging and forensics, IAM for identity and access management, Security Groups for network segmentation, CloudFront for edge security, CloudFormation for infrastructure-as-code security, S3 bucket policies and encryption, ECS container orchestration security, Lambda function security, DynamoDB and RDS database security configurations, and VPC isolation strategies.

  • Programming Language Proficiency

    Strong proficiency in at least one programming language such as Python, JavaScript, Node.js, or TypeScript for developing security tools, automation scripts, threat detection systems, and integration utilities. Demonstrate ability to write secure, maintainable, and testable code with comprehensive documentation.

  • Application Security & Secure Code Review

    Demonstrated expertise in identifying common application vulnerabilities (OWASP Top 10), secure coding principles, threat modeling methodologies, and secure-by-default architecture patterns. Ability to conduct thorough security code reviews and provide actionable remediation guidance to development teams.

  • Container & Infrastructure Security

    Hands-on experience with containerized workloads, container orchestration platforms, and infrastructure-as-code tools. Understanding of supply chain security, image scanning, secrets management, and runtime security controls in container-based environments.

  • Security Monitoring & Detection

    Experience building or operating security scanning systems, threat detection platforms, and security monitoring tools. Familiarity with log analysis, security event correlation, anomaly detection methodologies, and security metrics collection for continuous threat monitoring.

  • Testing & Documentation Practices

    Proficiency in automated security testing frameworks, unit testing, integration testing, and security test automation. Strong documentation skills including security design documentation, runbooks, security policies, and compliance documentation creation.

Education

  • Bachelor's Degree in Computer Science or Related Field

    Bachelor's degree or higher qualification in Computer Science, Cybersecurity, Computer Engineering, Information Security, or a closely related technical discipline. Equivalent professional certifications and demonstrated security expertise may be considered as alternatives.

Experience

  • 5+ Years of Security & Software Engineering Experience

    Five or more years of professional experience in application security, product security, cloud security, or related software engineering roles. Experience should demonstrate progression in security responsibilities, including secure architecture design, vulnerability assessment, threat modeling, and security tooling development.

  • Cloud Infrastructure Security

    Proven hands-on experience securing cloud infrastructure, particularly Amazon Web Services (AWS). Direct experience with containerized deployments, multi-region architectures, infrastructure monitoring, and cloud security best practices implementation across production environments.

  • Risk Assessment & Security Leadership

    Demonstrated ability to conduct comprehensive security risk assessments, prioritize vulnerabilities and risks based on business impact, and communicate security findings to technical and non-technical stakeholders. Experience working with cross-functional teams to drive security improvements and compliance initiatives.

Skills

Required

  • AWS Security Services

    Expert-level proficiency with AWS GuardDuty, CloudTrail, IAM, Security Groups, CloudFront, CloudFormation, S3, ECS, Lambda, DynamoDB, and RDS security configurations and best practices.

  • Python Programming

    Strong Python development skills for writing security automation tools, threat detection systems, scripts, and integrations. Experience with popular Python security libraries and frameworks.

  • Application Security Assessment

    Ability to identify vulnerabilities in source code through manual review and automated tools. Knowledge of OWASP Top 10, CWE, and secure coding patterns. Experience providing remediation guidance to development teams.

  • Cloud Security Architecture

    Expertise in designing and implementing secure cloud architectures, network segmentation, identity management, and encryption strategies for multi-region AWS deployments.

  • Threat Detection & Monitoring

    Hands-on experience building or operating threat detection systems, security monitoring platforms, SIEM tools, and security analytics systems for continuous threat identification.

  • Container Security

    Proficiency with container security practices including image scanning, runtime security, secrets management, and security controls for ECS, Docker, and containerized application deployments.

Preferred

  • TypeScript/Node.js Development

    Nice to have

    Experience developing security tools and integrations using TypeScript or Node.js to complement Python-based security automation and expand technology ecosystem expertise.

  • Security Compliance & Certifications

    Nice to have

    Knowledge of security frameworks including SOC 2, ISO 27001, PCI-DSS, HIPAA, or other compliance standards. Experience implementing controls to maintain compliance certifications and passing security audits.

  • Bug Bounty Program Management

    Nice to have

    Experience coordinating with security researchers, managing vulnerability disclosures, operating bug bounty platforms, and facilitating responsible disclosure processes with external security communities.

  • Infrastructure-as-Code Security

    Nice to have

    Hands-on experience with CloudFormation, Terraform, or other IaC tools for implementing security controls through code. Experience scanning IaC configurations for security misconfigurations.

  • Incident Response & Forensics

    Nice to have

    Background in security incident response, forensic analysis, threat investigation, and root cause analysis. Experience managing on-call rotations and responding to security emergencies in production environments.

  • Security Automation & CI/CD Integration

    Nice to have

    Experience integrating security scanning and testing into continuous integration and continuous deployment pipelines. Knowledge of DevSecOps practices and shifting security left in the development lifecycle.

  • Secure Development Lifecycle

    Nice to have

    Familiarity with secure SDLC methodologies, threat modeling frameworks, security design reviews, and integrating security requirements into product development processes from inception.

  • Security Leadership & Communication

    Nice to have

    Demonstrated ability to influence engineers through technical expertise, mentor junior team members, and communicate complex security concepts to both technical and non-technical audiences effectively.

Tech stack

Languages

PythonJavaScript/TypeScript

Frameworks

AWS SDKBoto3CloudFormation

Databases

DynamoDBRDS

Tools

AWS GuardDutyAWS CloudTrailAWS IAM (Identity and Access Management)AWS CloudFrontAWS ECS (Elastic Container Service)AWS LambdaAWS S3 (Simple Storage Service)Security Scanning Tools

Other

Docker & Container TechnologiesGit & Version ControlCI/CD PipelinesOWASP & Security StandardsThreat Modeling

Compensation

Pay and benefits.

Base·USD 165,000 – 220,000

Full posting

Original listing.

Mapbox is the leading real-time location platform for a new generation of location-aware businesses. Mapbox is the only platform that equips organizations with the full set of tools to power the navigation of people, packages, and vehicles everywhere. More than 4 million registered developers have chosen Mapbox because of the platform’s flexibility, security and privacy compliance. Organizations use Mapbox applications, data, SDKs and APIs to create customized and immersive experiences that delight their customers. 

What We Do

Mapbox is looking for a Senior Software Engineer to join our Security & Compliance team. As a member of our diverse and globally distributed team, you’ll help all Mapbox engineers build secure-by-default systems. Engineers on the Security & Compliance team build scanning and threat detection systems to monitor Mapbox’s cloud deployment (AWS-native, mainly container-based, 7 global regions including China) and other digital assets. They conduct risk assessments of new vendor integrations and product launches, and facilitate a bug bounty program that leverages the diverse expertise of a global community of security researchers. Lastly, they build and maintain core standards around security, quality, and privacy—reflected in our compliance certifications—and the automation to monitor and enforce these standards across Mapbox.

 

What You'll Do

We’re excited to share our passion for scalable, engineering-driven, security with you, and for your perspective to help shape our team’s goals. You will be responsible for contributing to, operating, and improving all things related to our security and compliance services. In this role, you can expect to:

  • Conduct AWS security reviews (deep dive into our AWS environment to validate security best practices are being followed).

  • Make security improvements recommendations and work with our production support teams to implement security improvement in AWS.

  • Partner with the Lead Security Architect in fixing custom-built security tools bots.

  • Conduct in-depth security reviews of application code, working closely with developers to code securely from the outset and address issues early during coding and testing phases.

  • Partner with internal product teams to implement a secure-by-default design into their own products.

  • Participate in an on-call rotation to ensure our systems remain available to customers 24/7. Team members alternate as the on-call primary responder, which may require immediate response outside normal working hours, including weekends.

 

What We Believe are Important for This Role

  • Bachelor’s or higher degree in Computer Science or similar

  • 5+ years of experience in product or application security and related software engineering roles

  • Experience with AWS services like GuardDuty, CloudTrail log review, IAM, Security Groups, CloudFront, CloudFormation, S3, ECS, Lambda, DynamoDB and RDS.

  • Proficiency in a programming language (e.g. Python, JavaScript or Node.js or TypeScript), testing practices, and documentation.

  • Subject matter expertise in security best practices and the ability to quickly make correct risk assessments that prioritize the overall benefit to the company.

 

What We Value

In addition to our core values, which are not unique to this position and are necessary for Mapbox leaders:

  • We value high-performing creative individuals who dig into problems and opportunities.

  • We believe in individuals being their whole selves at work. We commit to this through supportive health care, parental leave, flexibility for the things that come up in life, and innovating on how we think about supporting our people.

  • We emphasize an environment of teaching and learning to equip employees with the tools needed to be successful in their function and the company.

  • We strongly believe in the value of growing a diverse team and encourage people of all backgrounds, genders, ethnicities, abilities, and sexual orientations to apply.

 

How We Support You

  • Hybrid/Remote Options: Enjoy flexibility to work comfortably from home or periodically from an office where applicable.

  • Comprehensive Healthcare: Private medical coverage for you and your dependents.

  • Family-First Support: Generous maternity and paternity leave policies to support your growing family.

  • Fertility & Family Building: Inclusive fertility support. Grow your family on your terms.

  • Lifestyle Spending Account: Contributions to support your health, wellness, and personal growth.

  • Balance & Brainpower: Mental health support for you and your dependents.

  • Rest & Recharge: Flexible paid time away, company holidays, and generous absence policies.

  • Time Off to Give Back: Dedicated paid volunteering time in addition to your standard PTO.

  • Invest & Grow: Retirement plans with competitive matching.

 

By applying for this position, you acknowledge that you have received the Mapbox Non-US Privacy Notice for applicants, which is linked here. Completing this application requires you to provide personal data, such as your name and contact information, which is mandatory for Mapbox to process your application.

We are committed to a fair and equitable hiring process. We do not discriminate against any protected class.

#LI-Remote

Redirects to Mapbox's application page.

Other roles

More at Mapbox.

View all 7 roles