# Security Engineer II
**Company:** [Mapbox](https://scaleengineer.com/companies/mapbox)
Join Mapbox's Security & Compliance team as a Security Engineer II to architect and implement secure-by-default systems across a globally distributed AWS infrastructure serving 4+ million developers. This role combines cloud security expertise, threat detection systems development, and secure code review practices to protect Mapbox's real-time location platform across 7 global regions. You'll conduct AWS security assessments, build compliance automation, and partner with engineering teams to embed security into the product development lifecycle.
**Role:** Security Engineer
**Seniority:** Senior
**Locations:** Mapbox Helsinki
**Remote:** yes
**Salary:** 165000–220000 USD
[Apply](https://jobs.ashbyhq.com/mapbox/edb270f5-fe93-49ee-9dd9-98cf7e32fbad)
Canonical: https://scaleengineer.com/jobs/mapbox/security-engineer-ii-edb270f5
---
## Responsibilities

- AWS Security Architecture & Review: Conduct comprehensive AWS security reviews and deep-dive assessments of Mapbox's cloud environment across 7 global regions to validate adherence to security best practices. Analyze AWS services including GuardDuty, CloudTrail, IAM policies, Security Groups, CloudFront, CloudFormation, S3, ECS, Lambda, DynamoDB, and RDS to identify misconfigurations and security vulnerabilities.
- Security Improvements & Implementation: Develop detailed security improvement recommendations and partner with production support teams to implement infrastructure hardening initiatives. Track remediation efforts across cloud deployments, manage risk prioritization, and ensure security controls align with business objectives and compliance requirements.
- Security Tools & Automation: Collaborate with the Lead Security Architect to develop, maintain, and fix custom-built security scanning and threat detection systems and bots. Build automation frameworks to monitor and enforce security standards and compliance certifications across Mapbox's container-based infrastructure and digital assets.
- Application Security & Code Review: Conduct in-depth security code reviews of application source code, working closely with product engineers to identify vulnerabilities early in the development lifecycle. Provide actionable guidance on secure coding practices, threat modeling, and secure-by-default design patterns for development teams.
- Product Security Integration: Partner with internal product teams and engineering organizations to embed security requirements into product roadmaps, design processes, and deployment pipelines. Facilitate secure-by-default architecture adoption and establish security standards that become foundational to platform development.
- On-Call Response & Incident Management: Participate in rotating on-call responsibilities to ensure continuous availability and rapid response to security incidents affecting customer-facing systems. Respond to incidents 24/7 including evenings and weekends, conduct incident analysis, and implement post-incident remediation to prevent recurrence.
- Compliance & Risk Assessment: Conduct thorough risk assessments of new vendor integrations and product launches before production deployment. Facilitate security researcher engagement through bug bounty program operations, coordinate vulnerability disclosure processes, and maintain compliance documentation for relevant certifications.

## Requirements

### education

- {"name":"Bachelor's Degree in Computer Science or Related Field","description":"Bachelor's degree or higher qualification in Computer Science, Cybersecurity, Computer Engineering, Information Security, or a closely related technical discipline. Equivalent professional certifications and demonstrated security expertise may be considered as alternatives."}

### technical

- {"name":"AWS Cloud Security Expertise","description":"Advanced proficiency with AWS security services and architecture patterns including GuardDuty for threat detection, CloudTrail for audit logging and forensics, IAM for identity and access management, Security Groups for network segmentation, CloudFront for edge security, CloudFormation for infrastructure-as-code security, S3 bucket policies and encryption, ECS container orchestration security, Lambda function security, DynamoDB and RDS database security configurations, and VPC isolation strategies."}
- {"name":"Programming Language Proficiency","description":"Strong proficiency in at least one programming language such as Python, JavaScript, Node.js, or TypeScript for developing security tools, automation scripts, threat detection systems, and integration utilities. Demonstrate ability to write secure, maintainable, and testable code with comprehensive documentation."}
- {"name":"Application Security & Secure Code Review","description":"Demonstrated expertise in identifying common application vulnerabilities (OWASP Top 10), secure coding principles, threat modeling methodologies, and secure-by-default architecture patterns. Ability to conduct thorough security code reviews and provide actionable remediation guidance to development teams."}
- {"name":"Container & Infrastructure Security","description":"Hands-on experience with containerized workloads, container orchestration platforms, and infrastructure-as-code tools. Understanding of supply chain security, image scanning, secrets management, and runtime security controls in container-based environments."}
- {"name":"Security Monitoring & Detection","description":"Experience building or operating security scanning systems, threat detection platforms, and security monitoring tools. Familiarity with log analysis, security event correlation, anomaly detection methodologies, and security metrics collection for continuous threat monitoring."}
- {"name":"Testing & Documentation Practices","description":"Proficiency in automated security testing frameworks, unit testing, integration testing, and security test automation. Strong documentation skills including security design documentation, runbooks, security policies, and compliance documentation creation."}

### experience

- {"name":"5+ Years of Security & Software Engineering Experience","description":"Five or more years of professional experience in application security, product security, cloud security, or related software engineering roles. Experience should demonstrate progression in security responsibilities, including secure architecture design, vulnerability assessment, threat modeling, and security tooling development."}
- {"name":"Cloud Infrastructure Security","description":"Proven hands-on experience securing cloud infrastructure, particularly Amazon Web Services (AWS). Direct experience with containerized deployments, multi-region architectures, infrastructure monitoring, and cloud security best practices implementation across production environments."}
- {"name":"Risk Assessment & Security Leadership","description":"Demonstrated ability to conduct comprehensive security risk assessments, prioritize vulnerabilities and risks based on business impact, and communicate security findings to technical and non-technical stakeholders. Experience working with cross-functional teams to drive security improvements and compliance initiatives."}

## Skills

### required

- {"name":"AWS Security Services","description":"Expert-level proficiency with AWS GuardDuty, CloudTrail, IAM, Security Groups, CloudFront, CloudFormation, S3, ECS, Lambda, DynamoDB, and RDS security configurations and best practices."}
- {"name":"Python Programming","description":"Strong Python development skills for writing security automation tools, threat detection systems, scripts, and integrations. Experience with popular Python security libraries and frameworks."}
- {"name":"Application Security Assessment","description":"Ability to identify vulnerabilities in source code through manual review and automated tools. Knowledge of OWASP Top 10, CWE, and secure coding patterns. Experience providing remediation guidance to development teams."}
- {"name":"Cloud Security Architecture","description":"Expertise in designing and implementing secure cloud architectures, network segmentation, identity management, and encryption strategies for multi-region AWS deployments."}
- {"name":"Threat Detection & Monitoring","description":"Hands-on experience building or operating threat detection systems, security monitoring platforms, SIEM tools, and security analytics systems for continuous threat identification."}
- {"name":"Container Security","description":"Proficiency with container security practices including image scanning, runtime security, secrets management, and security controls for ECS, Docker, and containerized application deployments."}

### preferred

- {"name":"TypeScript/Node.js Development","description":"Experience developing security tools and integrations using TypeScript or Node.js to complement Python-based security automation and expand technology ecosystem expertise."}
- {"name":"Security Compliance & Certifications","description":"Knowledge of security frameworks including SOC 2, ISO 27001, PCI-DSS, HIPAA, or other compliance standards. Experience implementing controls to maintain compliance certifications and passing security audits."}
- {"name":"Bug Bounty Program Management","description":"Experience coordinating with security researchers, managing vulnerability disclosures, operating bug bounty platforms, and facilitating responsible disclosure processes with external security communities."}
- {"name":"Infrastructure-as-Code Security","description":"Hands-on experience with CloudFormation, Terraform, or other IaC tools for implementing security controls through code. Experience scanning IaC configurations for security misconfigurations."}
- {"name":"Incident Response & Forensics","description":"Background in security incident response, forensic analysis, threat investigation, and root cause analysis. Experience managing on-call rotations and responding to security emergencies in production environments."}
- {"name":"Security Automation & CI/CD Integration","description":"Experience integrating security scanning and testing into continuous integration and continuous deployment pipelines. Knowledge of DevSecOps practices and shifting security left in the development lifecycle."}
- {"name":"Secure Development Lifecycle","description":"Familiarity with secure SDLC methodologies, threat modeling frameworks, security design reviews, and integrating security requirements into product development processes from inception."}
- {"name":"Security Leadership & Communication","description":"Demonstrated ability to influence engineers through technical expertise, mentor junior team members, and communicate complex security concepts to both technical and non-technical audiences effectively."}

## Tech stack

### tools

- {"name":"AWS GuardDuty","description":"AWS managed threat detection service for continuous monitoring and identification of suspicious activity in AWS accounts. Used for threat intelligence analysis and security alert investigation."}
- {"name":"AWS CloudTrail","description":"AWS logging and monitoring service providing audit trails of API calls and account activity. Essential for forensic analysis, compliance auditing, and security investigations across multi-region environments."}
- {"name":"AWS IAM (Identity and Access Management)","description":"Core AWS service for managing identity, access policies, and permissions. Deep expertise required for implementing least-privilege access controls and access governance across cloud infrastructure."}
- {"name":"AWS CloudFront","description":"AWS content delivery network with security features including DDoS protection, WAF integration, and edge-level access controls. Understanding of configuration security and threat mitigation capabilities."}
- {"name":"AWS ECS (Elastic Container Service)","description":"AWS container orchestration service for managing containerized workloads. Expertise in container security configurations, task role policies, secrets management, and runtime security monitoring."}
- {"name":"AWS Lambda","description":"Serverless compute service used for building security automation, event-driven threat detection functions, and security tool backends. Understanding of Lambda security controls and function-level access policies."}
- {"name":"AWS S3 (Simple Storage Service)","description":"AWS object storage service with emphasis on security configuration including bucket policies, access control lists, encryption, versioning, and public access prevention controls."}
- {"name":"Security Scanning Tools","description":"Experience with software composition analysis (SCA), static application security testing (SAST), dynamic application security testing (DAST), and container image scanning platforms for identifying vulnerabilities."}

### others

- {"name":"Docker & Container Technologies","description":"Containerization expertise for securing containerized applications, understanding container security best practices, image scanning, runtime security, and supply chain security for container deployments."}
- {"name":"Git & Version Control","description":"Proficiency with Git version control systems, GitOps workflows, and secure repository management. Understanding of code review processes and access controls for secure development practices."}
- {"name":"CI/CD Pipelines","description":"Experience integrating security checks into continuous integration and continuous deployment pipelines. Understanding of security gates, artifact scanning, and automated compliance enforcement in deployment workflows."}
- {"name":"OWASP & Security Standards","description":"Deep knowledge of OWASP Top 10 vulnerabilities, CWE classifications, secure coding standards, and industry security best practices frameworks applicable to modern cloud-native development."}
- {"name":"Threat Modeling","description":"Ability to conduct threat modeling exercises for new products, features, and infrastructure changes. Experience identifying attack vectors, assessing risk exposure, and recommending security controls."}

### databases

- {"name":"DynamoDB","description":"AWS NoSQL database service for security event storage, audit logging, and threat detection data management. Understanding of DynamoDB security configurations including encryption, access control, and point-in-time recovery."}
- {"name":"RDS","description":"AWS relational database service for storing security-sensitive application data. Expertise in RDS security controls including encryption at-rest and in-transit, IAM authentication, and database activity monitoring."}

### languages

- {"name":"Python","description":"Primary language for developing security automation tools, threat detection systems, security scanning utilities, and integrations. Used extensively for building custom security bots and monitoring frameworks."}
- {"name":"JavaScript/TypeScript","description":"Modern JavaScript and TypeScript for security tooling development, Node.js-based backend services, and cross-platform security integrations across Mapbox's ecosystem."}

### frameworks

- {"name":"AWS SDK","description":"AWS Software Development Kit for programmatic interaction with AWS services. Essential for automation, security auditing, and building custom tools that interact with GuardDuty, CloudTrail, IAM, and other security services."}
- {"name":"Boto3","description":"AWS SDK for Python enabling infrastructure automation, cloud security assessments, and custom security tool development for AWS resource inspection and configuration validation."}
- {"name":"CloudFormation","description":"Infrastructure-as-code framework for defining and deploying secure AWS infrastructure. Used for security control implementation, secure baseline configuration, and infrastructure standardization."}

## Benefits

### benefits

## Compensation

- **max:** 0
- **min:** 0
- **currency:** 
- **stockOptions:** false

## Interview process

### steps

## Full description
Mapbox is the leading real-time location platform for a new generation of location-aware businesses. Mapbox is the only platform that equips organizations with the full set of tools to power the navigation of people, packages, and vehicles everywhere. More than 4 million registered developers have chosen Mapbox because of the platform’s flexibility, security and privacy compliance. Organizations use Mapbox applications, data, SDKs and APIs to create customized and immersive experiences that delight their customers. 

## **What We Do**

Mapbox is looking for a Senior Software Engineer to join our Security & Compliance team. As a member of our diverse and globally distributed team, you’ll help all Mapbox engineers build secure-by-default systems. Engineers on the Security & Compliance team build scanning and threat detection systems to monitor Mapbox’s cloud deployment (AWS-native, mainly container-based, 7 global regions including China) and other digital assets. They conduct risk assessments of new vendor integrations and product launches, and facilitate a bug bounty program that leverages the diverse expertise of a global community of security researchers. Lastly, they build and maintain core standards around security, quality, and privacy—reflected in our compliance certifications—and the automation to monitor and enforce these standards across Mapbox.

## **What You'll Do**

We’re excited to share our passion for scalable, engineering-driven, security with you, and for your perspective to help shape our team’s goals. You will be responsible for contributing to, operating, and improving all things related to our security and compliance services. In this role, you can expect to:

* Conduct AWS security reviews (deep dive into our AWS environment to validate security best practices are being followed).
* Make security improvements recommendations and work with our production support teams to implement security improvement in AWS.
* Partner with the Lead Security Architect in fixing custom-built security tools bots.
* Conduct in-depth security reviews of application code, working closely with developers to code securely from the outset and address issues early during coding and testing phases.
* Partner with internal product teams to implement a secure-by-default design into their own products.
* Participate in an on-call rotation to ensure our systems remain available to customers 24/7\. Team members alternate as the on-call primary responder, which may require immediate response outside normal working hours, including weekends.

## What We Believe are Important for This Role

* Bachelor’s or higher degree in Computer Science or similar
* 5+ years of experience in product or application security and related software engineering roles
* Experience with AWS services like GuardDuty, CloudTrail log review, IAM, Security Groups, CloudFront, CloudFormation, S3, ECS, Lambda, DynamoDB and RDS.
* Proficiency in a programming language (e.g. Python, JavaScript or Node.js or TypeScript), testing practices, and documentation.
* Subject matter expertise in security best practices and the ability to quickly make correct risk assessments that prioritize the overall benefit to the company.

## **What We Value**

In addition to [our core values](https://www.mapbox.com/about/values/), which are not unique to this position and are necessary for Mapbox leaders:

* We value high-performing creative individuals who dig into problems and opportunities.
* We believe in individuals being their whole selves at work. We commit to this through supportive health care, parental leave, flexibility for the things that come up in life, and innovating on how we think about supporting our people.
* We emphasize an environment of teaching and learning to equip employees with the tools needed to be successful in their function and the company.
* We strongly believe in the value of growing a diverse team and encourage people of all backgrounds, genders, ethnicities, abilities, and sexual orientations to apply.

## How We Support You

* **Hybrid/Remote Options:** Enjoy flexibility to work comfortably from home or periodically from an office where applicable.
* **Comprehensive Healthcare:** Private medical coverage for you and your dependents.
* **Family-First Support:** Generous maternity and paternity leave policies to support your growing family.
* **Fertility & Family Building:** Inclusive fertility support. Grow your family on your terms.
* **Lifestyle Spending Account:** Contributions to support your health, wellness, and personal growth.
* **Balance & Brainpower:** Mental health support for you and your dependents.
* **Rest & Recharge:** Flexible paid time away, company holidays, and generous absence policies.
* **Time Off to Give Back:** Dedicated paid volunteering time in addition to your standard PTO.
* **Invest & Grow:** Retirement plans with competitive matching.

By applying for this position, you acknowledge that you have received the [Mapbox Non-US Privacy Notice](https://www.mapbox.com/legal/applicant-privacy-notice/) for applicants, which is linked here. Completing this application requires you to provide personal data, such as your name and contact information, which is mandatory for Mapbox to process your application.

_We are committed to a fair and equitable hiring process. We do not discriminate against any protected class._

#LI-Remote
