Arcjet
Series A
Product Focused Security Engineer
· Not specified
- Annual base salary
- See listed compensation
- Equity
- Equity offered
- Commitment
- Not specified
- Company stage
- Series A
Compensation as listed
Competitive VC-backed startup salary ($174K - $249K) + equity.
About the role
Arcjet is hiring a product focused security engineer to help build the future of developer security.
This is an unusual role that sits across two core disciplines - security and product engineering. We’re looking for someone with a security background, particularly with bot protection and attack detection, who wants to write and deploy code as a key part of the team building an innovative new security product.
Did you (or would you) stop by the appsec or cloud villages? Do you have a particular interest in 🦀 Rust, 🦫 Go, 🏗️ WebAssembly, and/or 👾 developer native security? If so, we want to talk to you.
About Arcjet
Arcjet’s mission is to be the default security layer for all apps
Arcjet helps developers protect their apps in just a few lines of code. Bot detection. Rate limiting. Email validation. Attack protection. Data redaction. A developer-first approach to security.
Developers care about security, but it’s often a pain amongst all the many other things on their todo list. Arcjet helps developers protect their apps against a range of security risks so they can get on with everything else.
Priority 0: Developer experience
Arcjet's top priority is developer experience. This is what sets us apart from other security companies. We want to remove the pain of dealing with security challenges and we’re failing if developers are not delighted by the Arcjet experience.
What does that mean?
- A native SDK experience → Each SDK should be designed with the specific language and tech stack in mind, ensuring that its ergonomics are tailored to the expectations of developers native to that ecosystem.
- It works → Too many products have broken documentation, incomplete code examples, complex installation instructions, and basic features that do not work properly. Does nobody test these things?! Arcjet is aiming for a seamless experience from signup to deployment. If you’ve deployed code in seconds to Vercel or Netlify, launched infra around the world with Fly.io, branched your database in Planetscale or Neon, easily created your own private network with Tailscale, or optimized your workflow with Raycast, you’ll know the kind of experience we’re aiming for.
- Thinking like a developer → Developers want to use tools designed for them. Our goal is to make their lives easier and earn their trust by helping solve their security problems. To achieve this, we need to meet developers where they are: in code, in their preferred editors, through self-service options, directly integrated with their frameworks, and through channels like YouTube, Slack, Discord, and developer conferences. Our aim is for Arcjet to become the default choice for developers to secure their Django, Rust, Next.js, Go, Laravel, Ruby, (and more!) apps.
We’ve spent years playing around with devtools all day (our CEO writes the console.dev devtools newsletter), so we understand what it takes to build a world class developer experience. This is key to how Arcjet is different from all the other security companies, and means you’ll be at the leading edge of building the next generation of security tools.
How we work
Remote-first, in-person regularly
We are set up as a remote-first, distributed company (US and Western EU timezones). However, in-person makes a big difference. We organize meetups 2-3 times a year for the whole team to work from the same place, kick off new projects, complete challenges, build the product, and get to know each other in real life.
Real-time sometimes, asynchronous most of the time
Group chat is the best way to stress out your team. Although we use Slack, it’s primarily for quick discussions, hashing through a problem in real-time, socializing and sharing interesting things. Our Slack messages are automatically deleted after 7 days and anything important gets migrated to Notion or GitHub.
Ship early and iterate
Default to shipping rather than waiting, so long as we don’t sacrifice reliability. Use appropriate due diligence: gradually rolling things out, and paying attention to error rates, but the best way to learn is to ship code to prod.
Mission focused
We acknowledge that in life there are many different perspectives and that healthy debate is important for society. However, whilst we may all agree about the existence of a problem, we expect people to have different opinions about how to solve it.
As such, we refrain from advocating for causes unrelated to our mission because we believe it harms inclusion. We are building a security product for developers. Anything outside of that mission should be avoided at work or on company systems.
About the job
What you’ll do
- Reporting to our Director of Engineering, you will lead the development on core components of the product, with a particular focus on our bot protection and attack detection features. This will involve working across all areas of the product, but will focus on the following areas:
- Work with our DX Engineer to maintain detailed technical documentation about how to use the SDKs, the APIs, and the security functionality. Features aren’t “done” until they’re fully tested & documented.
- Working with customers and iterating rapidly on their feedback. Developers are particularly sensitive to working on things “NOW” so we want to be able to unblock them by solving problems quickly.
- Collaborating with the rest of the team on all of the above → offering advice on areas of expertise, participating in design discussions, and conducting code reviews.
- You’ll operate the code you write i.e. you’re responsible for it once it goes into production. This will involve participating in the on-call rotation.
- When you apply (see below), include the keyword “Porcupine Tree" somewhere in your email to prove you’ve read this whole post.
Requirements
- Several years experience with software security:
- Significant experience with 🦀 Rust and/or 🦫 Go.
- You’ll need to be comfortable with ambiguity & low-structure as we build up the company. You’ll be fully supported by the rest of the team, but this generally means you’ll also need to be self-directed → defining, building, and then owning large parts of the codebase.
- Pragmatic approach to building software → you’ll know that at the early stages of product-building, lots of the code will be replaced within 12-18 months. You must understand how to balance “good enough” with ensuring security and quality. This will usually mean experience in a startup environment.
- Strong English language abilities.
- In the US, Canada or a Western EU country. You must be able (no visa restrictions) to travel to the US for team meetups.
Bonus
These are not required, but it’ll be a nice bonus if you have experience with any of the following:
- Experience with WebAssembly.
- Experience with JavaScript and TypeScript.
- Experience hacking on compilers or code generation tools.
- Experience building products for developers, with a particular understanding of what makes for a good developer experience and why this is the age of the developer.
- Experience building security products.
- Specific experience in an early-stage startup growing from 2 to 20 people.
Benefits
- Competitive VC-backed startup salary ($174K - $249K) + equity.
- Paid annual holiday allowance based on the norms in your country (unlimited holiday doesn’t work). In the US this is 20 days PTO per year, plus public holidays, pro-rated if you join mid-year.
- For US employees: health, dental, and vision insurance, plus short and long term disability insurance.
Apply
Email hiring@arcjet.com with your resume or LinkedIn URL. Include a few sentences explaining how you hit the above requirements (it doesn’t need to be long, just the highlights).
The process
- A 30min call with our Director of Engineering, about us and the role + you and your background.
- A take-home coding exercise scoped to take no more than 4 hours. Ideally returned within 1 week.
- A 1h followup call discussing how you approached the task.
- A 1h security interview to assess your security skills.
- Team call - a two-way interview for you to ask our existing team questions and for them to get to know you.
- Decision!
Questions?
Feel free to email hiring@arcjet.com with any questions before you apply.
Source: a16z portfolio. Confirm availability with the employer.
Apply through the original posting.
View listing