SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Arca is a Series A wealth management platform built with AI, backed by General Catalyst, Index Ventures, and Venrock. The company has raised $64M and operates a small, engineering-heavy team of 12 based in Flatiron, NYC, working fully in-office five days a week. Arca manages over $1B in client assets and is rebuilding wealth management from the ground up, combining human advisors with AI-powered tools that handle low-leverage work and maintain living client profiles.
As Member of Technical Staff focused on Security, you will be Arca's first dedicated security hire, owning security across the entire company—AWS infrastructure, applications, and the IT environment. This is a foundational role where you set security posture, standards, and culture from the ground up.
Key responsibilities include:
**Infrastructure Security**: Design and harden the AWS environment end-to-end—VPC and VPN peering, network segmentation, IAM, secrets management, and guardrails that enable fast shipping without compromising safety. Make the secure path the easy path for eight engineers moving quickly.
**Application Security**: Own security across web and desktop clients and backend systems. Conduct threat modeling on new features, implement dependency and supply-chain controls, and embed appsec into design and code review processes so issues touching client assets are caught before shipping.
**Identity and Access Control**: Build SSO, RBAC, and least-privilege access for both humans and AI agents. Ensure agents can access exactly the client data their tasks require—nothing more—with full auditability and clear records of all actions.
**IT Security**: Partner with the IT MSP to secure devices, endpoints, and team access. Own and level up this critical relationship.
**Compliance and Trust Programs**: Establish bug bounty and vulnerability disclosure programs, manage pentester relationships, and build the audit trails and compliance infrastructure that prove security to clients, partners, and auditors.
Example problems you'll tackle: making agent activity fully auditable and reconstructable; hardening AWS while keeping the secure default also the fastest one; extending least-privilege thinking to non-human actors; threat-modeling features across web and desktop; and standing up external security programs that stress-test the platform.
You'll work with a team of eight engineers from Stripe, Ramp, Rippling, Plaid, Doordash, and Glean. This role is ideal for a senior security engineer who wants to build security culture and infrastructure from scratch at a well-funded, mission-driven fintech company handling sensitive financial data at scale.