
Founding Product Security Engineer
Arena Intelligence, Inc.9 months ago
Base Salary
$210k - $320k/yr
Responsibilities
- Own Arena’s product security vision and embed security and trust throughout the product lifecycle.
- Design and implement identity, authentication, authorization, and account-lifecycle systems to defend against credential stuffing, account takeover, and API-key compromise.
- Secure the model-inference path, including provider credential handling, API gateway controls, rate limiting, quota enforcement, and protections against secret and prompt exfiltration.
- Lead threat modeling and security architecture reviews for product features.
- Partner with infrastructure and product engineering on secure APIs, data flows, and identity systems.
- Build secure-by-default frameworks, libraries, and tooling to improve developer velocity.
- Continuously test and evolve platform defenses through adversarial thinking.
- Partner with incident response to assess, contain, and remediate security events and lead postmortems.
- Monitor emerging attack techniques and apply security research to the platform.
- Mentor engineers on secure coding, architecture trade-offs, and operational security.
Requirements
- 6+ years of software engineering or security engineering experience, including staff-level scope securing large-scale, user-facing platforms.
- Strong experience with threat modeling, secure architecture design, and risk assessment.
- Hands-on experience building security features into production systems at scale, including millions of daily active users and billions of requests.
- Deep knowledge of authentication, authorization, identity systems, session management, and credential-abuse resistance.
- Strong knowledge of distributed systems security, API security, and secure data-pipeline design.
- Proficiency in backend development with Node.js, TypeScript, Python, or Go, and willingness to work across the stack when needed.
- Ability to communicate effectively and build alignment across engineering, product, and leadership teams.
- Experience securing AI/ML inference paths, API gateways, or high-volume public APIs is a bonus.
- Experience building behavioral-signal or fingerprinting platforms for trust and safety or abuse teams is a bonus.
- Contributions to open-source security tools or research are a bonus.
- Experience securing real-time, interactive platforms at scale is a bonus.
- Experience leading end-to-end security incident response and blameless postmortems at a company with meaningful external exposure is a bonus.
Benefits
- Competitive compensation and equity aligned to the candidate’s permanent work location, with base salary depending on location.
- Comprehensive medical, dental, vision, and additional wellness support programs.
- Opportunity to work on cutting-edge AI with a small, mission-driven team.
- Transparency-, trust-, and community-focused culture.
About Arena Intelligence, Inc.
Created by researchers from UC Berkeley, Arena (formerly LMArena) is a community-powered platform to measure and advance the frontier of AI for real-world use. Tens of millions of builders, researchers, and creative professionals come to Arena to use frontier models and give feedback on their responses, shaping a public leaderboard grounded in real-world use.