Magic

Member of Technical Staff, Defensive Security Engineer

Magic · San Francisco, California, United States · $225K–$550K/yr

Software Development · 51-200 employees

7 h ago
Senior (5-10 yrs) Full-time Visa sponsorship United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will build security tooling, automation, and infrastructure to protect models and systems from cyber threats. You will also collaborate with engineering and research teams to implement secure practices and respond to security incidents.

What they look for

Defensive security Software engineering Rust Go Python C++ Kotlin TypeScript Cloud infrastructure Distributed systems Linux Security automation Incident response Threat modeling CI/CD security AI safety

Requirements

Candidates must have strong software engineering experience in languages like Rust, Go, or Python and a deep understanding of modern security architectures. Experience in securing distributed systems and cloud infrastructure is required, along with 24/7 on-call readiness.

Benefits

401(k) plan with 6% salary matching Health insurance Dental insurance Vision insurance Unlimited paid time off Visa sponsorship Relocation stipend Equity

Full description

Magic’s mission is to build safe AGI that accelerates humanity’s progress on the world’s most important problems. We believe the most promising path to safe AGI lies in automating research and code generation to improve models and solve alignment more reliably than humans can alone. Our approach combines frontier-scale pre-training, domain-specific RL, ultra-long context, and inference-time compute to achieve this goal.

About the role:

As our first dedicated Defensive Security Engineer at Magic, you will build the software, automation, and infrastructure that protect our models, systems, and engineering organization from both traditional and frontier AI cyber threats. You will respond to security threats, help us build good practices around security incident/threat response.

The role sits at the intersection of software engineering, infrastructure, and security. You will work closely with researchers, infrastructure engineers, and platform teams to reduce risk while considering the productivity impact. You will help us make the secure path the easy, productive path.

The threat landscape is changing, supply chain attacks are a major concern, prompt injections and other LLM-native attack vectors are worrying. As frontier AI systems become increasingly capable, security is evolving beyond defending infrastructure alone. Modern models can autonomously discover vulnerabilities, chain exploits across multiple systems, manipulate agents through prompt injection, and escape “secure” containment.

AI safety is extremely important to us at Magic. You will collaborate with our alignment team on whatever they might need to ensure that Magic's models are a safe net-benefit to the world.

What you might work on: 

  • Design, build, and maintain security tooling and automation used by Magic's engineering teams
  • Secure developer infrastructure, CI/CD pipelines, build systems, and production services and make the platform tools easy to use
  • Support our sandboxes team with building secure sandboxing and isolation for untrusted code, agent and model execution
  • Build guardrails against emerging AI attack vectors, including prompt injection, tool abuse, exploit chaining, and autonomous model behavior
  • Protect model weights, research artifacts, datasets, and production infrastructure from unauthorized access, lateral movement, and exfiltration
  • Respond to security incidents and live threats

What we’re looking for: 

  • Software engineering skills with experience building production systems in Rust, Go, Python, C++, Kotlin, TypeScript, or similar languages
  • A very good understanding of modern MITRE att&ck techniques
  • Actively engaged in the role of LLMs in securing and attacking software systems
  • On-call readiness 24/7, assisted by our team
  • Experience securing distributed systems, cloud infrastructure, or large-scale production environments
  • Ability to develop high-complexity cloud Linux-based exploits
  • Deep understanding of UNIX or other operating systems, networking, authentication, authorization, and modern security architecture
  • Experience building automation and tooling to secure fast paced organizations
  • Track record of exceptional personal integrity, accountability and trustworthiness in high autonomy environments

Compensation, benefits, and perks (US):

  • Annual salary ranges between $225K - $550K based on experience
  • Equity is a significant part of total compensation, in addition to salary
  • 401(k) plan with 6% salary matching
  • Generous health, dental and vision insurance for you and your dependents
  • Unlimited paid time off
  • Visa sponsorship and relocation stipend to bring you to SF, if possible
  • A small, fast-paced, highly focused team

Magic strives to be the place where high-potential individuals can do their best work. We value quick learning and grit just as much as skill and experience.

Our culture

  • Integrity. Words and actions should be aligned
  • Hands-on. At Magic, everyone is building
  • Teamwork. We move as one team, not N individuals
  • Focus. Safely deploy AGI. Everything else is noise
  • Quality. Magic should feel like magic