Security Engineer III

Mapbox
11dRemote

About The Position

Mapbox is looking for a Staff Cloud Security Engineer to join our Security & Compliance team. As a member of our diverse and globally distributed team, you’ll help all Mapbox engineers build secure-by-default systems. Engineers on the Security & Compliance team build scanning and threat detection systems to monitor Mapbox’s cloud deployment (AWS-native, mainly container-based, 7 global regions including China) and other digital assets. They conduct risk assessments of new vendor integrations and product launches, and facilitate a bug bounty program that leverages the diverse expertise of a global community of security researchers. Lastly, they build and maintain core standards around security, quality, and privacy—reflected in our compliance certifications—and the automation to monitor and enforce these standards across Mapbox. What We Do We’re excited to share our passion for scalable, engineering-driven, security with you, and for your perspective to help shape our team’s goals. You will be responsible for contributing to, operating, and improving all things related to our security and compliance services.

Requirements

  • Bachelor’s or higher degree in Computer Science or similar
  • 5+ years of experience in product or application security and related software engineering roles
  • Experience with AWS services like GuardDuty, CloudTrail log review, IAM, Security Groups, CloudFront, CloudFormation, S3, ECS, Lambda, DynamoDB and RDS.
  • Proficiency in a programming language (e.g. Python, JavaScript or Node.js or TypeScript), testing practices, and documentation.
  • Subject matter expertise in security best practices and the ability to quickly make correct risk assessments that prioritize the overall benefit to the company.

Nice To Haves

  • Additional experience with AWS services like API Gateway, CodeBuild, VPCs, Inspector, Advanced Shield, Athena, and Glue.
  • Strong proficiency in a programming language (e.g. JavaScript or Node.js or Python), testing practices, and thorough documentation.
  • Experience with SOC 2, GDPR, and ISO 9001 or ISO 27001 compliance standards a plus

Responsibilities

  • Conduct AWS security reviews (deep dive into our AWS environment to validate security best practices are being followed).
  • Make security improvements recommendations and work with our production support teams to implement security improvement in AWS.
  • Partner with the Lead Security Architect in fixing custom-built security tools bots.
  • Conduct in-depth security reviews of application code, working closely with developers to code securely from the outset and address issues early during coding and testing phases.
  • Partner with internal product teams to implement a secure-by-default design into their own products.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service