Here's some documentation to get you started.
https://www.mongodb.com/blog/post/how-to-avoid-a-malicious-a...
https://docs.mongodb.com/manual/administration/security-chec...
https://www.mongodb.com/collateral/mongodb-security-architec...
This really should have been titled "the importance of good DBA's..."