- Are you the kind of person who is comfortable getting hands-on with technical work - reviewing a firewall ruleset, hardening an endpoint fleet, triaging a SIEM alert - and equally at ease with documenting evidence needed to pass a compliance audit?
- Do you want the kind of role where security is yours to shape, not just operate?
- Would you like to cooperate with top professionals in our industry?
If your answers are mostly yes, then you should keep reading. At Nomagic, we're on a mission to teach robots the real world. We're now looking for a Security & Compliance Engineer to own security and compliance across the company - from our corporate environment to the edge stations we deploy at customer sites.
Own security and compliance hands-on at a scaling robotics company
Work across cloud, edge, and on-prem infrastructure
Equity for every employee
Relocation package
No late evening calls - the entire eng team is based in Europe :)
English-speaking environment
Hybrid work from Warsaw - you'll be in the office regularly, as the role benefits from presence
We get to be creative
We're still pretty small, so everyone has a direct impact on the final result
Nothing is written in stone, we can easily change the tools and processes we use (if the requirements change)
We take security and compliance seriously as operational reality, not as a checkbox
You won't be alone — you'll have a strong DevOps/Infrastructure team for cloud and edge topics, outsourced IT support for day-to-day administration, and security consultants for specialized work
The CEO and part of the management are experienced infrastructure engineers who created the foundations of Google Cloud Platform
We combine world-class research with top-notch engineering and apply it to solve real problems
Owning our ISO 27001 and SOC 2 compliance posture day-to-day on Vanta — evidence, controls, audits, and closing gaps as we grow
Co-create policy for AI tooling usage — be at the forefront of how AI can boost productivity at Nomagic, while applying best security practices around evaluation, access, and data handling
Defining the security standards for our endpoints, identity, and network — and verifying that our outsourced IT provider implements them correctly
Running the third-party risk process — assessing vendor security posture and handling customer security questionnaires
Monitoring and responding to security events — SIEM, alert triage, investigation, and improving detection over time
Working with the DevOps/Infrastructure team on security topics that span cloud, edge, and OT environments
5+ years of hands-on experience in information security, IT security, or a similar role
Practical understanding of endpoint and identity security - MDM, SSO, SAML, access control models
Solid understanding of network security architecture - segmentation, trust boundaries, and secure remote access
Hands-on experience with a GRC framework (ISO 27001, SOC 2, or similar), including third-party risk assessment and security questionnaires
Comfortable writing and reviewing security policies
Scripting ability for automation - Python, Bash, PowerShell, or similar
Fluent communication in English
Nice to have:
Experience with Vanta or a similar GRC platform (Drata, Tugboat Logic) — matches our current stack
Familiarity with SIEM tooling, especially Wazuh — matches our current stack
Exposure to OT, industrial, or edge/hardware environments
Cloud security experience (GCP preferred)
Background in a tech scaleup
30 minutes call with a Recruiter
45 minutes Hiring Manager interview
60 minutes Technical Interview
Onsites - half a day of interviews & discussions at the office
Important: Feedback after completing the recruitment process.
See a short sneak peek of our product here: