Security Engineer III

15 Minutes ago • 5 Years + • $192,950 PA - $261,050 PA
Cyber Security

Job Description

Mapbox is seeking a Staff Security Engineer to join its Security & Compliance team. This role involves advising across the company, helping engineers build secure systems, and triaging vulnerabilities. The team develops scanning and threat detection systems for Mapbox's AWS cloud deployment, conducts risk assessments for new integrations, manages a bug bounty program, and maintains security, quality, and privacy standards. The engineer will contribute to, operate, and improve security and compliance services, focusing on AWS security reviews, application code reviews, and partnering with product teams for secure-by-default designs and incident resolution.
Good To Have:
  • Experience with SOC compliance standards
  • Experience with GDPR compliance standards
  • Experience with ISO compliance standards
Must Have:
  • Bachelor’s or higher degree in Computer Science or similar
  • 5+ years of experience in product or application security and related software engineering roles
  • Extensive experience with AWS services
  • Strong proficiency in a programming language (e.g. JavaScript, Node.js, Python)
  • Subject matter expertise in security best practices and risk assessments
  • Conduct AWS security reviews
  • Make security improvement recommendations
  • Partner with Lead Security Architect on security tools
  • Conduct in-depth security reviews of application code
  • Partner with internal product teams for secure-by-default design
  • Partner with engineering teams to resolve security incidents
Perks:
  • Supportive health care
  • Parental leave
  • Flexibility for life events
  • Innovating on supporting employees
  • Environment of teaching and learning

Add these skills to join the top 1% applicants for this job

game-texts
aws
node.js
python
javascript

What We Do

Mapbox is looking for a Staff Security Engineer to join our Security & Compliance team. As a member of our diverse and globally distributed team, you’ll play an advisory role across the whole company. You will help all Mapbox engineers build secure-by-default systems and triage and mend vulnerabilities on their systems. Engineers on the Security & Compliance team build scanning and threat detection systems to monitor Mapbox’s cloud deployment (AWS-native, mainly container-based, 7 global regions including China) and other digital assets. They conduct risk assessments of new vendor integrations and product launches, and facilitate a bug bounty program that leverages the diverse expertise of a global community of security researchers. Lastly, they build and maintain core standards around security, quality, and privacy—reflected in our compliance certifications —and the automation to monitor and enforce these standards across Mapbox.

What You'll Do

We’re excited to share our passion for scalable, engineering-driven, security with you, and for your perspective to help shape our team’s goals. You will be responsible for contributing to, operating, and improving all things related to our security and compliance services.

In this role, you can expect to:

  • Conduct AWS security reviews (deep dive into our AWS environment to validate security best practices are being followed).
  • Make security improvements recommendations and work with our production support teams to implement security improvement in AWS.
  • Partner with the Lead Security Architect in fixing custom-built security tools bots.
  • Conduct in-depth security reviews of application code, working closely with developers to code securely from the outset and address issues early during coding and testing phases.
  • Partner with internal product teams to implement a secure-by-default design into their own products.
  • Partner with Mapbox engineering teams to understand and resolve security incidents that arise on their services.

What We Believe are Important Traits for This Role

  • Bachelor’s or higher degree in Computer Science or similar
  • 5+ years of experience in product or application security and related software engineering roles
  • Extensive experience with AWS services like API Gateway, CodeBuild, GuardDuty, CloudTrail log review, IAM, Security Groups, CloudFront, VPCs, Inspector, CloudFormation, ECS, Lambda, DynamoDB, S3, Athena, and Glue.
  • Strong proficiency in a programming language (e.g. JavaScript or Node.js or Python), testing practices, and thorough documentation.
  • Subject matter expertise in security best practices and the ability to quickly make correct risk assessments that prioritize the overall benefit to the company.
  • Experience with SOC, GDPR, and ISO compliance standards is a plus.

What We Value

In addition to our core values , which are not unique to this position and are necessary for Mapbox leaders:

  • We value high-performing creative individuals who dig into problems and opportunities.
  • We believe in individuals being their whole selves at work. We commit to this through supportive health care, parental leave, flexibility for the things that come up in life, and innovating on how we think about supporting our people.
  • We emphasize an environment of teaching and learning to equip employees with the tools needed to be successful in their function and the company.
  • We strongly believe in the value of growing a diverse team and encourage people of all backgrounds, genders, ethnicities, abilities, and sexual orientations to apply.

Our annual base compensation for this role ranges from $192,950 - $261,050 for most US locations and 5% to 10% higher for US locations with a higher cost of labor. Job level and actual compensation will be decided based on factors including, but not limited to, individual qualifications objectively assessed during the interview process (including skills and prior relevant experience, potential impact, and scope of role), market demands, and specific work location. Please discuss your specific work location with your recruiter for more information.

By applying for this position, you acknowledge that you agree to the Mapbox Privacy Policy which is linked here._

Mapbox participates in E-Verify to confirm employee work authorization. Please refer to the Notice of E-Verify Participation and Right to Work posters for more information.

We are committed to a fair and equitable hiring process. We do not discriminate against any protected class.

#LI-Remote

Apply for this Job

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Set alerts for more jobs like Security Engineer III
Set alerts for new jobs by Mapbox
Set alerts for new Cyber Security jobs in United States
Set alerts for new jobs in United States
Set alerts for Cyber Security (Remote) jobs

Contact Us
hello@outscal.com
Made in INDIA 💛💙