# Security Engineer II
**Company:** [Mapbox](https://scaleengineer.com/companies/mapbox)
Join Mapbox's Security & Compliance team as a Security Engineer II to build secure-by-default systems across a global AWS-native infrastructure serving 4+ million developers. In this role, you'll conduct comprehensive AWS security reviews, perform in-depth application security code reviews, operate custom-built security tooling, and partner with product teams to embed security into their infrastructure and design processes. This position requires 5+ years of product/application security experience, deep AWS expertise across services like GuardDuty and CloudTrail, and proficiency in programming languages such as Python, JavaScript, or TypeScript.
**Role:** Security Engineer
**Seniority:** Senior
**Locations:** Mapbox US
**Salary:** 161500–218500 USD
[Apply](https://jobs.ashbyhq.com/mapbox/c7e03478-078e-4865-bbba-cb03c28d1dc6)
Canonical: https://scaleengineer.com/jobs/mapbox/security-engineer-ii
---
## Responsibilities

- Conduct AWS Security Reviews: Perform deep-dive security assessments of Mapbox's AWS environment spanning 7 global regions to validate adherence to security best practices, including evaluation of IAM policies, Security Groups, CloudFormation templates, and container-based ECS deployments. Identify misconfigurations and architectural security gaps in AWS-native infrastructure.
- Security Improvement Implementation: Develop and recommend security enhancement strategies tailored to AWS deployments. Collaborate with production support teams to implement security improvements, including remediation of vulnerabilities, hardening of cloud resources, and optimization of security controls within the AWS environment.
- Custom Security Tools Development and Maintenance: Partner with the Lead Security Architect to develop, deploy, and maintain custom-built security scanning and threat detection bots that monitor cloud deployments and digital assets. Contribute to automation tools that enforce security standards across Mapbox infrastructure.
- Application Security Code Reviews: Conduct thorough security code reviews across application codebases, identifying vulnerabilities, secure coding violations, and design flaws early in development cycles. Work closely with engineering teams to provide actionable security guidance and establish secure-by-default coding practices.
- Secure-by-Default Design Partnership: Collaborate with internal product teams to integrate security considerations into product architecture and design from inception. Facilitate threat modeling sessions, provide security architecture consultation, and establish security requirements for new product launches and vendor integrations.
- Threat Detection and Monitoring: Operate and improve scanning and threat detection systems that monitor Mapbox's global cloud deployment for security incidents, anomalies, and compliance violations. Maintain vigilance across AWS services including GuardDuty and CloudTrail to detect and respond to potential threats.
- Compliance and Standards Oversight: Build, maintain, and enforce core security, quality, and privacy standards reflected in Mapbox's compliance certifications. Develop automation to monitor and enforce standards across the organization and conduct risk assessments for new vendor integrations.
- Bug Bounty Program Facilitation: Support and facilitate Mapbox's bug bounty program, engaging with the global community of security researchers to identify and address security vulnerabilities through coordinated disclosure processes.

## Requirements

### education

- {"name":"Bachelor's Degree in Computer Science or Related Field","description":"Formal education in Computer Science, Cybersecurity, Information Security, Software Engineering, or equivalent discipline demonstrating foundational knowledge in computing principles, security theory, and software development methodologies."}

### technical

- {"name":"AWS Security Services Expertise","description":"Deep proficiency with AWS security services including GuardDuty for threat detection, CloudTrail for logging and auditing, CloudFront for DDoS protection, CloudFormation for infrastructure-as-code security, S3 bucket policies and encryption, ECS container security, Lambda function security, DynamoDB encryption, and RDS database security. Experience with IAM policy design, Security Groups configuration, and cross-region security architecture."}
- {"name":"Programming Language Proficiency","description":"Production-level expertise in at least one programming language such as Python, JavaScript, Node.js, or TypeScript. Ability to write security automation scripts, develop security tooling, review application code for vulnerabilities, and contribute to security infrastructure as code."}
- {"name":"Security Code Analysis","description":"Hands-on experience with static and dynamic code analysis techniques, vulnerability scanning tools, and secure code review methodologies. Familiarity with common vulnerability patterns (OWASP Top 10), injection attacks, authentication/authorization flaws, and cryptographic implementation issues."}
- {"name":"Cloud Security Architecture","description":"Demonstrated experience designing and implementing security architectures for cloud environments, including network segmentation, encryption strategies (in-transit and at-rest), identity and access management, secrets management, and zero-trust principles."}
- {"name":"Container and Kubernetes Security","description":"Experience with container security in AWS ECS environments, including image scanning, runtime security, secrets management in containers, and container orchestration security considerations."}

### experience

- {"name":"Product/Application Security Experience","description":"Minimum 5+ years of professional experience in product security, application security, or closely related software engineering security roles. This should include hands-on security vulnerability assessment, secure code review, and security architecture design experience."}
- {"name":"AWS Cloud Security Operations","description":"Proven track record of 3+ years managing and securing AWS cloud infrastructure at scale, including operational security, threat detection, incident response in cloud environments, and compliance monitoring."}
- {"name":"Security Tooling and Automation","description":"Experience building, deploying, and maintaining security automation tools, scanning solutions, or threat detection systems that operate continuously across infrastructure environments."}
- {"name":"Cross-Functional Security Collaboration","description":"Demonstrated ability to work effectively with development, operations, and product teams to integrate security into development lifecycles, conduct security training, and advocate for security best practices across technical organizations."}

## Skills

### required

- {"name":"AWS Security Services","description":"GuardDuty, CloudTrail, CloudFront, CloudFormation, S3, ECS, Lambda, DynamoDB, RDS, IAM, Security Groups"}
- {"name":"Application Security","description":"Secure code review, vulnerability assessment, threat modeling, OWASP principles, secure SDLC integration"}
- {"name":"Programming Languages","description":"Python, JavaScript, Node.js, TypeScript, or equivalent for automation and tooling"}
- {"name":"Testing Practices","description":"Security testing methodologies, unit testing, integration testing, penetration testing fundamentals"}
- {"name":"Technical Documentation","description":"Clear communication of complex security concepts, architecture documentation, security policies, and runbooks"}
- {"name":"Risk Assessment","description":"Ability to evaluate security risks, prioritize remediation efforts, and communicate risk impact to stakeholders"}

### preferred

- {"name":"Kubernetes Security","description":"Experience securing Kubernetes clusters, RBAC configuration, network policies, and container orchestration security"}
- {"name":"Infrastructure-as-Code Security","description":"Scanning and securing IaC templates (Terraform, CloudFormation) for configuration drift and compliance"}
- {"name":"Security Compliance Certifications","description":"Knowledge of SOC 2, ISO 27001, HIPAA, GDPR, or other compliance frameworks relevant to SaaS platforms"}
- {"name":"Incident Response","description":"Experience responding to security incidents, conducting root cause analysis, and implementing preventive controls"}
- {"name":"Bug Bounty Program Experience","description":"Familiarity with coordinating vulnerability disclosures, managing researcher communications, and bug bounty platforms"}
- {"name":"Go Programming Language","description":"Experience with Go for building performance-critical security tools and infrastructure components"}
- {"name":"Cloud Security Certifications","description":"AWS Certified Security - Specialty, CISSP, CCSK, or equivalent industry-recognized cloud security credentials"}

## Tech stack

### tools

- {"name":"Amazon GuardDuty","description":"AWS threat detection service for identifying malicious activity and unauthorized behavior in cloud environments"}
- {"name":"AWS CloudTrail","description":"Logging and auditing service for tracking API calls and monitoring compliance across AWS accounts and regions"}
- {"name":"AWS IAM","description":"Identity and access management service for enforcing least-privilege access and authentication controls"}
- {"name":"Amazon CloudFront","description":"CDN service requiring security configuration for DDoS protection and content delivery security"}
- {"name":"AWS Lambda","description":"Serverless compute service used for security automation and threat response functions"}
- {"name":"Amazon ECS","description":"Container orchestration service for deploying and securing containerized security scanning and detection systems"}

### others

- {"name":"Static Application Security Testing (SAST)","description":"Tools for automated source code analysis to identify security vulnerabilities during development"}
- {"name":"Dynamic Application Security Testing (DAST)","description":"Runtime security testing tools for identifying vulnerabilities in running applications and APIs"}
- {"name":"Container Security Scanning","description":"Image scanning and runtime security monitoring for containerized workloads in ECS"}
- {"name":"Cloud Security Posture Management (CSPM)","description":"Tools for continuous monitoring of cloud configuration compliance and security best practices"}
- {"name":"Threat Modeling","description":"Systematic approach to identifying and mitigating security threats in systems and applications"}

### databases

- {"name":"Amazon DynamoDB","description":"NoSQL database service used in Mapbox platform with security considerations including encryption and access control"}
- {"name":"Amazon RDS","description":"Relational database service requiring security hardening, backup strategies, and encryption implementation"}
- {"name":"Amazon S3","description":"Object storage service requiring secure bucket policies, encryption, versioning, and access logging configuration"}

### languages

- {"name":"Python","description":"Primary language for security automation, threat detection scripts, and security tool development at Mapbox"}
- {"name":"JavaScript/TypeScript","description":"Used for security tooling, API security, and backend service security implementations"}
- {"name":"Go","description":"Emerging language for high-performance security scanning and infrastructure tooling"}

### frameworks

- {"name":"AWS CloudFormation","description":"Infrastructure-as-code framework for defining and securing AWS resources across Mapbox's 7 global regions"}
- {"name":"AWS CDK","description":"Infrastructure-as-code development kit for programmatic security infrastructure deployment"}

## Benefits

### benefits

- {"name":"Comprehensive Health Insurance Coverage","description":"Supportive healthcare benefits designed to ensure all Mapbox employees have access to medical, dental, and vision coverage with company contributions"}
- {"name":"Parental Leave","description":"Flexible and generous parental leave policies to support employees navigating major life changes and family responsibilities"}
- {"name":"Work Flexibility","description":"Remote work options and flexible scheduling to accommodate the varying needs that arise in life, supporting work-life balance"}
- {"name":"Professional Development and Learning","description":"Emphasis on continuous learning culture with opportunities for skill development, training, and career progression in security and cloud technologies"}
- {"name":"Diverse and Inclusive Workplace","description":"Commitment to building a diverse team that values and encourages individuals of all backgrounds, genders, ethnicities, abilities, and sexual orientations"}
- {"name":"Equity and Stock Options","description":"Stock options and equity participation opportunities allowing security engineers to share in company growth and success"}

## Compensation

- **max:** 218500
- **min:** 161500
- **currency:** USD
- **stockOptions:** true

## Interview process

### steps

- {"name":"Initial Recruiter Screening","description":"Phone or video conversation with Mapbox recruiter to discuss background, experience in security engineering, AWS expertise, and alignment with team needs. This 30-minute call assesses your professional journey and motivation for joining the Security & Compliance team."}
- {"name":"Technical Screening Interview","description":"Deep technical discussion with a Security Engineer from the team covering AWS security architecture, specific service knowledge (GuardDuty, CloudTrail, IAM), hands-on experience with security tools, and approach to threat assessment. Prepare to discuss specific projects demonstrating your AWS security expertise."}
- {"name":"Hands-On Security Assessment","description":"Technical challenge or case study exercise evaluating your ability to conduct AWS security reviews, identify configuration vulnerabilities, recommend remediation strategies, and write security automation code. May involve code review tasks or security architecture design scenarios."}
- {"name":"Team and Manager Interview","description":"Extended conversations with your potential manager and security team members to assess collaboration style, security philosophy, communication approach, and cultural fit. Discussions typically cover your approach to working with developers, cross-functional security partnerships, and security advocacy."}
- {"name":"Final Executive/Leadership Round","description":"Meeting with senior security leadership or engineering leadership to discuss broader security strategy, industry trends, your vision for cloud security, and your understanding of Mapbox's security challenges serving 4+ million developers."}

## Full description
Mapbox is the leading real-time location platform for a new generation of location-aware businesses. Mapbox is the only platform that equips organizations with the full set of tools to power the navigation of people, packages, and vehicles everywhere. More than 4 million registered developers have chosen Mapbox because of the platform’s flexibility, security and privacy compliance. Organizations use Mapbox applications, data, SDKs and APIs to create customized and immersive experiences that delight their customers. 

## **What We Do**

Mapbox is looking for a Senior Cloud Security Engineer to join our Security & Compliance team. As a member of our diverse and globally distributed team, you’ll help all Mapbox engineers build secure-by-default systems. Engineers on the Security & Compliance team build scanning and threat detection systems to monitor Mapbox’s cloud deployment (AWS-native, mainly container-based, 7 global regions including China) and other digital assets. They conduct risk assessments of new vendor integrations and product launches, and facilitate a bug bounty program that leverages the diverse expertise of a global community of security researchers. Lastly, they build and maintain core standards around security, quality, and privacy—reflected in our compliance certifications—and the automation to monitor and enforce these standards across Mapbox.

## **What You'll Do**

We’re excited to share our passion for scalable, engineering-driven, security with you, and for your perspective to help shape our team’s goals. You will be responsible for contributing to, operating, and improving all things related to our security and compliance services. In this role, you can expect to:

* Conduct AWS security reviews (deep dive into our AWS environment to validate security best practices are being followed).
* Make security improvements recommendations and work with our production support teams to implement security improvement in AWS.
* Partner with the Lead Security Architect in fixing custom-built security tools bots.
* Conduct in-depth security reviews of application code, working closely with developers to code securely from the outset and address issues early during coding and testing phases.
* Partner with internal product teams to implement a secure-by-default design into their own products.

## What We Believe are Important for This Role

* Bachelor’s or higher degree in Computer Science or similar
* 5+ years of experience in product or application security and related software engineering roles
* Experience with AWS services like GuardDuty, CloudTrail log review, IAM, Security Groups, CloudFront, CloudFormation, S3, ECS, Lambda, DynamoDB and RDS.
* Proficiency in a programming language (e.g. Python, JavaScript or Node.js or TypeScript), testing practices, and documentation.
* Subject matter expertise in security best practices and the ability to quickly make correct risk assessments that prioritize the overall benefit to the company.

## **What We Value**

In addition to [our core values](https://www.mapbox.com/about/values/), which are not unique to this position and are necessary for Mapbox leaders:

* We value high-performing creative individuals who dig into problems and opportunities.
* We believe in individuals being their whole selves at work. We commit to this through supportive health care, parental leave, flexibility for the things that come up in life, and innovating on how we think about supporting our people.
* We emphasize an environment of teaching and learning to equip employees with the tools needed to be successful in their function and the company.
* We strongly believe in the value of growing a diverse team and encourage people of all backgrounds, genders, ethnicities, abilities, and sexual orientations to apply.

Our annual base compensation for this role ranges from $161,500 - $218,500 for most US locations and 5% to 10% higher for US locations with a higher cost of labor. Job level and actual compensation will be decided based on factors including, but not limited to, individual qualifications objectively assessed during the interview process (including skills and prior relevant experience, potential impact, and scope of role), market demands, and specific work location. Please discuss your specific work location with your recruiter for more information.

_By applying for this position, you acknowledge that you agree to the_ [_Mapbox Privacy Policy_](https://www.mapbox.com/legal/privacy) _which is linked here._

_Mapbox participates in E-Verify to confirm employee work authorization. Please refer to the_ [_Notice of E-Verify Participation_](https://drive.google.com/file/d/1rVYht6vc6QJmVzwML1rlh3BFboC-JkGe/view?usp=drive%5Flink) _and_ [_Right to Work_](https://drive.google.com/file/d/1Pnzz1t8ueq8iPftJ7kqPOGoTnD5mqi0H/view?usp=drive%5Flink) _posters for more information._

_We are committed to a fair and equitable hiring process. We do not discriminate against any protected class._

#LI-Remote
