Member of Technical Staff, Security Engineer
IT
New York, NY, USA
About Arca
Arca is a wealth management firm built from the ground up with AI. Most people get financial advice that's reactive: an annual check-in, a plan that's a document instead of a living thing, a relationship where you're one of three hundred clients your advisor is trying to remember. We think that's backwards. The kind of service that used to require a team of specialists behind you, the kind that makes you feel like the only person in the room, should be available to far more than the ultra-wealthy.
So we're building it. We're not SaaS — we are the wealth management business, rebuilding it from the inside with AI. Our platform is an Iron Man suit for advisors: it takes over the low-leverage work so they can focus on what actually requires a human, showing up with empathy, context, and judgment. Underneath, it keeps a living understanding of each client. It remembers the thing you mentioned once, six months ago. It notices when your life changes — a new job, a new kid, a market shift — and adjusts before you think to ask. You won't see the technology. You'll just notice your advisor seems to know you better than any financial professional ever has.
That's the product we're growing: client by client, on the strength of the experience itself. We started by acquiring firms managing over $1B in client assets, which gave us real advisors, real clients, and real financial outcomes to build against from day one. But acquisition was the starting line. The bet is that an advisor backed by this platform delivers something good enough that clients come to us on their own.
It's a $20T market, and we think it's ready to be rebuilt.
— Rron, CEO
The receipts
Stage: Series A, $64M raised
Backed by: General Catalyst, Index Ventures, Venrock
Board & Advisors: Former CEO of Vanguard, Former CFO of Schwab, Founder of Altruist, Morgan Housel (author of The Psychology of Money)
The team
We’re small on purpose. We’re a team of 12 based out of NYC and we’re engineering heavy with 8 engineers. We hail from high growth startups like Stripe, Ramp, Rippling, Plaid, Doordash, & Glean.
We’re fully in-office in Flatiron, five days a week—lunch together, coffee breaks, basketball games, happy hours.
The role
As a Member of Technical Staff focused on Security, you'll own security across the entire company—our AWS infrastructure, our applications, and the IT environment the team works in every day. We're a wealth management firm: we hold real client assets and some of the most sensitive data a person has, and our agents act on that data at scale, all the time. That makes security foundational to the product, not a checkbox at the end. You'll be our first dedicated security hire, which means you set the posture, the standards, and the culture. If you build it, you own it.
What you'll build (and own)
Infrastructure security. Our AWS environment end to end—VPC and VPN peering, network segmentation, IAM, secrets, and the guardrails that keep a fast-moving team from shipping something unsafe. You'll make the secure path the easy path.
Application security. The security of everything we ship, across our web and desktop clients and the backend behind them—threat modeling features, dependency and supply-chain controls, and building appsec into how the team designs and reviews code rather than bolting it on after.
Identity and access. SSO, RBAC, and least-privilege access across our systems—for humans and for agents—so the right people and processes can reach exactly what they need and nothing more, with a clear record of who touched what.
IT security. The security of how the team actually works—devices, endpoints, and access—in partnership with our IT MSP, whose relationship you'll own and level up.
Compliance, auditability, and trust. The programs that prove we're secure to clients, partners, and auditors: making the system compliant and auditable, running our bug bounty and VDP program, and owning our relationships with pentesters.
Example problems you'd work on
These aren't hypothetical; we're actively working on versions of all of these.
Making agents' work auditable. Our agents are the primary users of our system of record—they read and act on client data continuously, at a scale no human team could. Every action needs to be reconstructable later: what the agent did, on whose behalf, with what data, and why. You'll build the access controls and audit trails that make agent activity fully accountable, so we can prove exactly what happened without slowing agents down.
Locking down AWS without slowing the team. Eight engineers ship fast into a regulated domain. You'll harden the AWS environment—VPC/VPN peering, segmentation, IAM, secrets management—and design it so the secure default is also the fastest one. Security that fights the team gets routed around; security that's built in compounds.
Identity and least privilege across humans and agents. You'll own SSO and RBAC end to end, extending least-privilege thinking to non-human actors: an agent should reach exactly the client data its task requires and nothing more, with permissions that are legible and auditable. Getting this right is what lets us hand agents more responsibility safely.
Application security across web and desktop clients. You'll threat-model new features, set up dependency and supply-chain controls, and weave appsec into design and code review across our web and desktop apps—so we catch the class of issue that touches client assets before it ships, not after a report comes in.
Standing up bug bounty, VDP, and pentest programs. You'll run our external security surface: a bug bounty and vulnerability disclosure program, and the relationships with pentesters that stress-test us. You'll turn what comes back into prioritized fixes and a security posture that visibly improves over time.
Compliance and auditability as leverage, not tax. In financial services, auditability isn't optional—and it's also how we win trust with clients, partners, and every firm we acquire. You'll make the system compliant and auditable by design, so proving we're secure is a byproduct of how we build rather than a scramble before a deadline.
The kind of person who thrives here
You’re excited by ownership, ambiguity, and building things that matter.
You treat security as an enabler, not a gate. You've seen security done as the team of "no," and you build the opposite—the secure path made easy, threat models that sharpen decisions instead of blocking them. You have range: comfortable in AWS internals, in application code, and in the IT and compliance work that most engineers avoid, because you know posture is only as strong as its weakest surface.
You're ambitious in a way specific to this work. You're securing real retirement savings, estate plans, and the most sensitive data a person has. A gap here isn't a bug ticket; it's someone's financial life. That consequence makes you more rigorous, not slower.
You move fast, and you know speed and security aren't in tension here. A control that only works in theory is a liability the day it's tested. You treat securing what we ship as part of shipping, not a step that comes after.
You're someone people actually want to be in the room with. This is a 12-person team, one office, five days a week, working on problems that don't have clean answers. The people who thrive here want to argue about threat models at lunch and then close out a finding together in the afternoon. Kind, direct, and low-ego, you can give candid feedback without being an asshole, and you're genuinely energized by this environment (not just tolerant of it).
Why now is the moment to join
This is a narrow window with unusually high leverage.
We just came out of stealth, and we're growing fast. The team is intentionally small, the equity reflects that, and the ceiling is high. You'd be joining early enough that the work you do now directly shapes what the company becomes and what's possible next.
You'd be our first dedicated security hire. There's no legacy posture to inherit and no committee to negotiate with—you define the standards, the tooling, and the culture, and they become the foundation for every acquisition that follows.
The advisor-facing product is being defined right now, by a small team that talks to advisors every day. We've just brought on our second firm—the real inflection point, where we start separating what generalizes from what was bespoke. The security patterns you set now scale across every firm we bring on.
The hard part is behind us, which means the interesting part is starting. The platform is live, the concept is proven, advisors have moved real client assets onto it. The work now is scaling a working, trusted system across four or five acquisitions this year—under real load, real data, and real scrutiny.