Member of Technical Staff, Defensive Security Engineer at Magic | CA, US | Rezi

Member of Technical Staff, Defensive Security Engineer at Magic

Member of Technical Staff, Defensive Security Engineer

Magic · CA, US

3 weeks ago

Member of Technical Staff, Defensive Security Engineer

Magic · CA, US

23 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

As the first dedicated Defensive Security Engineer, you will build and maintain the software, automation, and infrastructure to protect our models, systems, and engineering organization from traditional and frontier AI cyber threats. You will respond to security threats and help establish robust security incident and threat response practices. This role is at the intersection of software engineering, infrastructure, and security, requiring collaboration with researchers, infrastructure engineers, and platform teams to mitigate risk while considering productivity impacts. You will help make the secure path the easy and productive one, addressing evolving threats like supply chain attacks, prompt injections, and LLM-native attack vectors.

Responsibilities

  • Design, build, and maintain security tooling and automation used by Magic's engineering teams
  • Secure developer infrastructure, CI/CD pipelines, build systems, and production services, ensuring platform tools are user-friendly
  • Support the sandboxes team in developing secure sandboxing and isolation for untrusted code, agent, and model execution
  • Build guardrails against emerging AI attack vectors, including prompt injection, tool abuse, exploit chaining, and autonomous model behavior
  • Protect model weights, research artifacts, datasets, and production infrastructure from unauthorized access, lateral movement, and exfiltration
  • Respond to security incidents and live threats

Requirements

  • Software engineering skills with experience building production systems in Rust, Go, Python, C++, Kotlin, TypeScript, or similar languages
  • A very good understanding of modern MITRE ATT&CK techniques
  • Actively engaged in the role of LLMs in securing and attacking software systems
  • On-call readiness 24/7, assisted by our team
  • Experience securing distributed systems, cloud infrastructure, or large-scale production environments
  • Ability to develop high-complexity cloud Linux-based exploits
  • Deep understanding of UNIX or other operating systems, networking, authentication, authorization, and modern security architecture
  • Experience building automation and tooling to secure fast-paced organizations
  • Track record of exceptional personal integrity, accountability, and trustworthiness in high autonomy environments

Skills

  • Rust
  • Go
  • Python
  • C++
  • Kotlin
  • TypeScript
  • MITRE ATT&CK
  • LLM security
  • Cloud security
  • Linux exploit development
  • UNIX
  • Networking
  • Authentication
  • Authorization
  • Security architecture
  • Automation
  • Tooling

Location

  • SF

Work Type

  • Onsite
  • Full-time

Experience Level

  • Mid-level
  • Senior

Salary/Compensations

  • $225K - $550K

Benefits

  • Equity is a significant part of total compensation
  • 401(k) plan with 6% salary matching
  • Generous health, dental and vision insurance for you and your dependents
  • Unlimited paid time off
  • Visa sponsorship
  • Relocation stipend

About the Company

  • Magic’s mission is to build safe AGI that accelerates humanity’s progress on the world’s most important problems.
  • We believe the most promising path to safe AGI lies in automating research and code generation to improve models and solve alignment more reliably than humans can alone.
  • Our approach combines frontier-scale pre-training, domain-specific RL, ultra-long context, and inference-time compute to achieve this goal.
  • AI safety is extremely important to us at Magic.
  • Magic strives to be the place where high-potential individuals can do their best work.
  • We value quick learning and grit just as much as skill and experience.
  • Integrity. Words and actions should be aligned
  • Hands-on. At Magic, everyone is building
  • Teamwork. We move as one team, not N individuals
  • Focus. Safely deploy AGI. Everything else is noise
  • Quality. Magic should feel like magic