Skip to content

Open nowPosted 275 days ago

Member of Security Staff, IT Engineer — Arena

a16z portfolio7,517 open roles

Pay
$80,000 – $165,000 a year
Where
Bay Area, California, United States; SF Bay Area
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowMember of Security Staff, IT Engineer — Arenaa16z portfolio · Bay Area, California, United States; SF Bay Area
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on a16z portfolio's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.3% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.9%1 day
  2. 3.9%3 days
  3. 8.3%7 days
  4. 15.3%14 days
  5. 34.2%30 days
This job: posted 275 days ago

The posting

About Arena Intelligence

Arena is the platform for evaluating how AI models perform in the real world. Founded by researchers from UC Berkeley's SkyLab, we're on a mission to measure and advance the frontier of AI for real-world use, and to build the foundation for everyone to understand, shape, and benefit from it.

Tens of millions of people use Arena each month to evaluate how frontier systems handle the work they actually do. The preferences they share power the most transparent, rigorous, and human-centered evaluations in AI. Leading AI labs, enterprises, and independent researchers rely on our work and open datasets to understand how models behave in real workflows: agentic coding, creative generation, professional productivity, and beyond. We go beyond leaderboards and decompose what human experience reveals about AI, so models advance toward the work people actually do.

We're a team of researchers, academics, builders, and creatives from UC Berkeley, Google, Stanford, and DeepMind. We seek truth, move fast, and value craftsmanship, curiosity, and impact over hierarchy. We're building a company where thoughtful, curious people from all backgrounds can do their best work together, in an office culture that radiates excellence, energy, and focus.

About the Role

We are looking for a senior IT and security engineer to own that function's technical direction. You will set how identity, endpoints, and access actually work here, decide what gets automated rather than done by hand, and be the person the team defers to on the hard calls.

This is a hands-on seat. You will do the work, not direct it from a distance.

You are not starting from zero. Identity is centralized with automated provisioning, the fleet is managed and enrolled with endpoint protection deployed, and remote access runs through a zero-trust layer. The foundations work. We need someone to deepen them, extend the model to areas it doesn't reach yet, and document what currently lives in people's heads.

The scope goes past enterprise systems. Our engineers build on source control, cloud data and analytics platforms, hosting, and managed infrastructure, and access to those carries consequences that a wiki or a calendar does not. You will own how entitlement works there too.

This role is onsite in our San Francisco office.

You'll

  • Design the identity and access model, not just administer it. Okta is the center of gravity: SSO and SCIM, group and role design, lifecycle automation for joiners, movers, and leavers, and access reviews that produce evidence an auditor accepts. You decide what determines group membership and what the source of truth is.
  • Own endpoint strategy across a heavily Apple fleet. Intune, Apple Business Manager, and CrowdStrike Falcon: enrollment, compliance baselines, patching, and the full lifecycle from procurement to retirement.
  • Set the posture across enterprise and production systems. Enterprise platforms plus the developer and production systems our engineers depend on: source control, cloud data and analytics, hosting, and managed infrastructure. One standard applied across all of it, third-party application access, and a real answer for what an application can reach once authorized.
  • Extend the access model to production. Entitlement to developer and data platforms is a harder problem than enterprise SaaS: the blast radius is larger, the roles are less uniform, and the review evidence is what auditors scrutinize most. You own how that works.
  • Decide what stops being manual. Much of the current request queue is automatable, and nobody has had time. Okta Workflows, Google APIs, Python, PowerShell, or Bash- whatever fits.
  • Deepen operational readiness. An on-call rotation exists. Runbooks, escalation paths, and documentation are thinner than they should be, and much of the environment is still undocumented. You write it so a colleague can do the work without you.
  • Own onboarding and offboarding end to end, including the evidence trail compliance depends on.
  • Partner with the security function on device trust, conditional access, and privileged access. This seat sits inside security rather than next to it.

You'll have

  • Deep, current, hands-on experience. You can describe what you built or configured in the last three months at keyboard level.
  • You have owned a function, not just a queue. You have made architectural calls about how identity and endpoint management should work somewhere, defended them, and lived with what they cost. You can name one you got wrong and changed.
  • Real identity depth. Okta or comparable. You can explain what determines group membership, what happens to a mover rather than only a joiner and leaver, and how your model holds up as a company grows quickly.
  • Automation instinct. You can name a category of work that no longer exists because you eliminated it, and say what you deliberately left manual.
  • Endpoint management at scale across mixed platforms. Intune, Jamf, or equivalent, plus an endpoint security agent fleet.
  • Security depth for this domain. Least privilege, conditional access, device trust, privileged access, and what an auditor will ask for.
  • Judgment about production and developer access, where over-granting is quietly expensive and under-granting stops engineers working. You have held that line somewhere.
  • Hands-on with AI tooling in your own work. You use AI to build, script, and troubleshoot, and you know where it belongs in an enterprise environment and where it doesn't.
  • Comfort inheriting something partly built and partly undocumented, and improving it rather than rebuilding it.
  • Calm under competing demands. You will support engineers, researchers, and executives, and need to tell a real emergency from a loud one.

Bonus points

  • Compliance evidence work: SOC 2 or ISO 27001 access reviews, asset inventory, offboarding records
  • Experience supporting a company through a period of rapid headcount growth
  • Zero-trust or conditional-access architecture
  • Governing AI tool adoption across a workforce: access, data handling, and sanctioned versus shadow usage
  • Cloudflare One administration and policy configuration
  • Hardware-key MFA rollouts (YubiKey, FIDO2)
  • AV, networking, or office buildout experience
  • Linux and cloud platforms (GCP, AWS, Azure)

What we offer

  • We offer competitive compensation and equity aligned to the markets where our team members are based. The base salary range will depend on the candidate’s permanent work location.
  • Comprehensive health and wellness benefits, including medical, dental, vision, and additional support programs.
  • The opportunity to work on cutting-edge AI with a small, mission-driven team
  • A culture that values transparency, trust, and community impact

Come help build the space where anyone can explore and help shape the future of AI.

Arena Intelligence provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, genetics, sexual orientation, gender identity, or gender expression. We are committed to a diverse and inclusive workforce and welcome people from all backgrounds, experiences, perspectives, and abilities.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against a16z portfolio's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on a16z portfolio's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    a16z portfolio's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.