Magic logo

Senior Security Engineer

Magic

About the Role

Magic's security team is critical – it is responsible for safeguarding Magic’s tools and products. We are looking for a Senior Security Engineer to play a pivotal role in expanding our security program. The Senior Security Engineer will also work on some of the most challenging and high-visibility risks the company is facing. You will identify and mitigate security risks in our product and infrastructure, in addition to conducting security assessments, and assist with investigations. The ideal candidate will be an innovative self-starter, who is motivated by our mission and results-driven, and will be able to extract, assimilate, and correlate a wide variety of data in order to surface and disrupt threat actors across multiple spaces.

This is a fully remote position for US and Canada-based candidates.

Responsibilities

  • Contribute to further securing our SDLC, to include secure coding practices, CI/CD pipelines, and regression tests.
  • Lead and grow our vulnerability management program, which spans across our cloud infrastructure (AWS) and endpoint machines (macOS).
  • Collaborate with Engineering teams to harden our frontend and backend systems (Next.js, Typescript, AWS, Python).
  • Foster your extensive experience securing a cloud microservices platform like Kubernetes, including ingress/egress, and container communication.
  • Manage our external bug bounty program and be able to technically contribute to mitigations.
  • Support compliance standards like NIST, ISO 27001, SOC 2 Type 2, and GDPR.
  • Build a security mindset across the organization by providing security guidance and best practices.
  • Take a holistic approach towards security, ensuring coverage from code quality up and out to our edge services including Cloudflare and Vercel.
  • Participate in 24/7 on-call and security incidents, acting as Incident Manager.

Requirements

  • 6+ years of security engineering or software security experience in either frontend or backend environments.
  • Experience with programming and scripting languages such as Python, Golang, or TypeScript.
  • Excellent Incident Management skills to navigate and lead incidents adeptly to ensure platform uptime.

Bonus Points

  • Have previously built or managed a SIEM like OpenSearch or Splunk.
  • Built out modular authentication flows including WebAuthn OAuth.
  • Experience with Web3 protocol or smart contract security auditing.

Benefits

  • Fully remote team and flexible working hours
  • Competitive salary and stock options
  • Unlimited paid time off
  • Health, Vision, Dental, Disability, and Life Insurance
  • 401(k) program
  • Top of the line equipment
  • $300 monthly budget for home office needs and professional development
  • Annual team meetups

At Magic, we believe building a team full of diverse perspectives and experiences is vital to success. Therefore, we strongly encourage anyone historically underrepresented in tech to apply for this role. Magic does not discriminate based on gender, sexual orientation, race, religion, citizenship status, age, or physical ability. Empathy, authenticity, and inclusivity are at the core of all we do.

Benefits
Extracted with AI

  • Disability insurance
  • 401(k)
  • Fully remote team and flexible working hours
  • Competitive salary and stock options
  • Unlimited paid time off
  • Health, Vision, Dental, Disability, and Life Insurance
  • Top of the line equipment
  • $300 monthly budget for home office needs and professional development
  • Annual team meetups

Similar jobs

Last update: 23 minutes ago

Magic logo
Magic

Senior Security Engineer

Senior Security Engineer role focusing on web3 security, remote work, with extensive benefits including 401(k) and health insurance.

Magic logo
Magic

Software Engineer - TypeScript

Join Magic as a Software Engineer in San Francisco, focusing on TypeScript and AI development. Equity, 401(k), and health benefits included.

Magic Eden logo
Magic Eden

Senior Backend Engineer

Join Magic Eden as a Senior Backend Engineer to build scalable systems using Node.js and cloud technologies.

Magic logo
Magic

Software Engineer - Pretraining Data

Join Magic as a Software Engineer to develop robust pipelines for multimodal datasets, focusing on distributed computing and data quality.

Magical logo
Magical

Senior Full Stack Software Engineer (Hybrid, San Francisco/Toronto)

Join Magical as a Senior Full Stack Software Engineer in San Francisco or Toronto. Work on innovative projects with a focus on productivity.

DeepL logo
DeepL

Security Engineer

Join DeepL as a Security Engineer to enhance cybersecurity and network security in a dynamic AI-driven environment.

Magic Eden logo
Magic Eden

Senior Frontend Engineer

Join Magic Eden as a Senior Frontend Engineer to innovate and build on a multi-chain NFT platform using Angular, JavaScript, and more.

Magic Eden logo
Magic Eden

Senior Backend Engineer - Node.js, Microservices

Senior Backend Engineer role at Magic Eden, focusing on Node.js and Microservices in a remote setting.

Seedify logo
Seedify

Senior Game Security Engineer

Senior Game Security Engineer for Seedify, specializing in UGC platform security with expertise in DevSecOps, SSDLC, and Unreal Engine.

MagicLinks logo
MagicLinks

Senior Fullstack Engineer

Join MagicLinks as a Senior Fullstack Engineer to build and scale platforms using Ruby on Rails, ReactJS, and more.

Magic Eden logo
Magic Eden

Staff Full Stack Engineer, Frontend

Join Magic Eden as a Staff Full Stack Engineer focusing on frontend, leveraging top technologies in a dynamic team environment.

Magical logo
Magical

Senior Full Stack React Software Engineer

Join Magical as a Senior Full Stack React Engineer in San Francisco. Revolutionize productivity with cutting-edge tech and a dynamic team.

Personio logo
Personio

Senior Product Security Engineer

Join Personio as a Senior Product Security Engineer to enhance security controls and automation practices in Munich.

Magic Eden logo
Magic Eden

Senior Backend Engineer

Senior Backend Engineer at Magic Eden, specializing in Node.JS, microservices, and cloud technology. Remote work with competitive benefits.

Squarespace logo
Squarespace

Senior Security Engineer

Join Squarespace as a Senior Security Engineer in Dublin, focusing on cybersecurity, incident response, and threat detection.

Seedify logo
Seedify

Senior Game Security Engineer

Senior Game Security Engineer for Seedify, specializing in UGC platform security, remote position, EMEA preference.

HackerOne logo
HackerOne

Senior Software Engineer IV (Assessments)

Join HackerOne as a Senior Software Engineer IV to lead technical projects in cybersecurity, working remotely in the US or Canada.

Swile logo
Swile

Senior Security Engineer - Application Security

Join Swile as a Senior Security Engineer focusing on application security, threat modeling, and vulnerability management.

Magic Eden logo
Magic Eden

Senior Mobile Engineer

Senior Mobile Engineer at Magic Eden, specializing in Android and iOS development with blockchain integration.

Dayforce logo
Dayforce

Senior C# Backend Developer – Security Engineering

Senior C# Backend Developer focused on Security Engineering, remote work, extensive experience with .NET, React, Angular, and cybersecurity.

Meta logo
Meta

Security Engineering Manager, Investigations

Lead a team focused on child safety and human exploitation investigations at Meta, leveraging technology and innovative research.

Appgate logo
Appgate

Senior Fullstack Engineer

Join Appgate as a Senior Fullstack Engineer to develop cutting-edge security solutions using C#, JavaScript, and Python.

c/side logo
c/side

Senior Back-end Engineer

Senior Backend Engineer needed to enhance security systems, work with TypeScript, Go, Kubernetes, and AWS. Fully remote position.

Meta logo
Meta

Security Detection Engineer, Insider Trust

Join Meta as a Security Detection Engineer to tackle insider threats, leveraging threat modeling and advanced detection solutions.