Founding Product Security Engineer
Leads product security strategy, designs and implements identity, auth, and secure inference paths for a large-scale AI evaluation platform. Requires 6+ years securing user-facing systems with backend proficiency and threat modeling expertise.
About the job
Responsibilities
- Own the product security vision for Arena, ensuring security and trust are core to every stage of our product lifecycle
- Design and implement the identity, authentication, authorization, and account-lifecycle systems that protect Arena against credential stuffing, account takeover, and API-key compromise
- Secure the model inference path end-to-end — provider credential handling, API gateway, rate limiting, quota enforcement, and protections against secret and prompt exfiltration
- Lead threat modeling and security architecture reviews for new and existing product features
- Collaborate with infrastructure and product engineering to design secure APIs, data flows, and identity systems that scale
- Improve developer velocity by creating secure-by-default frameworks, libraries, and tooling for internal teams
- Apply adversarial thinking to continuously test and evolve platform defenses
- Partner with incident response to quickly assess, contain, and remediate security events, and lead deep postmortems to improve defenses
- Stay ahead of the curve by monitoring emerging attack techniques and applying cutting-edge security research to our platform
- Mentor engineers across the company on secure coding practices, architecture trade-offs, and operational security
Requirements
- 6+ years of experience in software engineering or security engineering, including staff-level scope in securing large-scale, user-facing platforms
- Strong experience with threat modeling, secure architecture design, and risk assessment
- Hands-on experience building security features into production systems at scale (millions of DAU / billions of requests)
- Deep knowledge of authentication, authorization, and identity systems, including session management and credential-abuse resistance
- Strong knowledge of distributed systems security, API security, and secure data-pipeline design
- Proficiency in backend development (Node.js, TypeScript, Python, or Go) and willingness to work across the stack when needed
- Excellent communication skills, able to build alignment across engineering, product, and leadership teams
Nice-to-Haves
- Experience securing AI/ML inference paths, API gateways, or high-volume public APIs
- Experience building behavioral-signal or fingerprinting platforms used by trust & safety or abuse teams
- Contributions to open-source security tools or research
- Background in securing real-time, interactive platforms at scale
- Experience leading security incident response end-to-end, including blameless postmortems at a company with meaningful external exposure
Skills
Threat Modeling, Authentication, Authorization, Identity Systems, Api Security, Node.js, TypeScript, Python, Go, Distributed Systems, Api Gateway, Rate Limiting, Secure Coding, Incident Response, Security Architecture
Similar jobs
Security Engineering jobsOwns production-edge security for enterprise financial-institution connectivity, including PKI, mTLS, AWS networking, webhook security, and vulnerability remediation. Requires 6+ years of hands-on platform, infrastructure, or network security engineering experience.
Build secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.
Leads enterprise network architecture, cloud connectivity, security, operations, and incident response across corporate and manufacturing environments. Requires 10+ years of network engineering experience, people leadership, AWS networking expertise, and strong network security knowledge.
Own detection engineering and lead incident response across corporate and production environments, building cloud, endpoint, runtime, and Kubernetes coverage. The role requires 6+ years in security, hands-on detection development, and end-to-end incident leadership.
Own and advance the security of Anyscale’s production and multi-cloud infrastructure, including hardening, segmentation, Kubernetes runtime protection, and access controls. Requires 8+ years of security engineering experience and hands-on expertise with AWS, Azure, Kubernetes, and cloud security tooling.