Skip to main content
Back to jobs

Core Software Engineer, Security & Platform

External
CARTO logoCarto · Worldwide
Full-timeRemoteToday
Platform EngineeringCloud SecurityDevSecOpsPlatform Security EngineerSecurity Platform Engineer
Cover LetterConnect

Prepare for this interview

Elite

AI-generated questions, company research, and talking points tailored to this role


About the role

Everything happens somewhere - which is why spatial analytics is fundamental to companies trying to understand the "where" and the "why" of their business. CARTO is the world's leading cloud-native spatial analytics platform, built to break down the silos of traditional GIS. Trusted by data scientists, analysts, and developers from global brands such as IKEA, Coca-Cola, T-Mobile, Swiss Re, and AXA, CARTO enables organizations to run scalable spatial analysis directly on their cloud data warehouse. Our platform powers critical use cases such as site selection, catastrophe modeling, network planning, geomarketing, supply chain optimization, and AI-driven spatial analysis. Built by a diverse team of over 150 people across the US, APAC, and Europe, CARTO 's cloud-native Agentic GIS platform provides a modern, future-proof alternative to legacy GIS. Backed by Insight Partners, Accel, Salesforce Ventures, Earlybird, and others, CARTO is fundamentally changing the way location data is analyzed, making it an integrated and accessible part of modern data and AI workflows. What are we looking for? Over the years, CARTO has built a powerful and sophisticated platform. Like any mature software company, that also means we have accumulated complexity, legacy decisions, and areas of technical and security debt that need to be revisited with fresh eyes. At the same time, AI is changing the security landscape. Defending a modern software platform can no longer be limited to audits, checklists, or isolated security reviews. It needs to be embedded in the way the platform is designed, built, refactored, and operated. We are looking for a Senior Software Engineer focused on Security & Platform Hardening to join our Core Team. This is a role for someone who is comfortable jumping between layers and domains, has a bias for automation, and gets genuine satisfaction from making the whole organization more secure and more productive at the same time. You'll touch many different technologies and codebases, and your impact will be felt across the whole company. Location This is a remote-first role, open to candidates based anywhere in Europe. We have offices in Madrid and Seville if you prefer to work in person or want a place to collaborate occasionally, but there is no expectation to use them. You will Improve the security of the platform through code. Work directly in the CARTO codebase to identify, prioritize, and fix security weaknesses. This may involve refactoring existing components, redesigning risky flows, improving authorization boundaries, strengthening input validation, removing unsafe patterns, or building new platform capabilities that make secure development easier for everyone. Strengthen our cloud and infrastructure foundations. Work with our infrastructure and platform teams to harden CARTO 's cloud-native environments across GCP and AWS. You will contribute to areas such as IAM, Kubernetes, containerized workloads, networking, workload isolation, Infrastructure as Code, and secure-by-default deployment patterns. Make security part of the development workflow. Build and improve tools, checks, libraries, CI/CD integrations, and engineering practices that help developers catch security issues early. The goal is not to create gates that slow teams down, but to make the secure path the easiest path. Improve supply-chain security. Help protect CARTO from modern supply-chain attacks by improving dependency management, build integrity, container security, artifact provenance, CI/CD security, and automated scanning. Stay up to date with emerging attack techniques and translate that knowledge into practical protections. Use AI to improve security. Experiment with the latest AI models and tools to assess and improve CARTO 's security posture. This could include AI-assisted code review, automated vulnerability discovery, codebase analysis, threat modeling, dependency analysis, or internal agents that continuously look for risky patterns and misconfigurations. Secure AI and agentic systems. CARTO is building an Agentic GIS platform, which creates new security challenges. You will help us reason about and defend against risks such as prompt injection, tool misuse, data leakage, privilege escalation through agents, untrusted content flowing into automated workflows, and unsafe model/tool interactions. Raise the security bar across engineering. Partner with engineering teams to review designs, identify risks, and implement improvements. Help make every team more security-aware while remaining pragmatic, collaborative, and focused on enabling product velocity. You offer 5+ years of experience as a software engineer, platform engineer, infrastructure engineer, or security-focused engineer. Strong hands-on programming skills in at least one of TypeScript, Python, or Go, and the ability to work across a large production codebase. Experience designing, refactoring, and operating complex cloud-native software systems. Strong unders


Your Match

How well this role fits your profile.

Company Intel

What employees say

Worked at CARTO? Share your experience

Interested in this role?

Apply on the company's website.

Cover LetterConnect