About the role
What will you do at Arize AI?
ABOUT ARIZE
AI is rapidly transforming the world. As generative AI reshapes industries,
teams need powerful ways to monitor, troubleshoot, and optimize their AI
systems. That’s where we come in. Arize AI is the leading AI & Agent Engineering
observability and evaluation platform, empowering AI engineers to ship
high-performing, reliable agents and applications. From first prototype to
production scale, Arize AX unifies build, test, and run in a single workspace—so
teams can ship faster with confidence.
We’re a Series C company backed by top-tier investors, with over $135M in
funding and a rapidly growing customer base of 150+ leading enterprises and
Fortune 500 companies. Customers like Booking.com [http://booking.com/], Uber,
Siemens, and PepsiCo leverage Arize to deliver AI that works.
THE OPPORTUNITY
We're hiring a DevSecOps Engineer to embed security into how we ship software —
not as a gate at the end, but as a capability woven through every pipeline,
repo, and runtime. You'll work across a TypeScript-heavy stack (Node.js
services, Next.js frontends, internal platform tools) and play a central role in
how we securely design, deploy, and operate **agentic AI systems** — autonomous
and semi-autonomous AI agents that take real actions on behalf of users and
engineers.
This role is deeply collaborative. You'll spend more time pairing with other
departments. If you believe security is best delivered as developer experience,
you'll feel at home.
We're a small, senior team that prioritizes collaboration over hierarchy and
enablement over enforcement. Security at our company isn't a department people
avoid — it's a function people pull into their work because we make it useful.
Expect a lot of pairing, frequent design reviews, and a culture where asking "is
this secure?" early is celebrated, not punished.We believe the next generation
of software will be co-built with AI agents. We want a teammate who is excited
to figure out, alongside us, what it means to make that future safe.
WHAT YOU'LL DO:
* Design and implement guardrails for agentic AI workflows — including tool-use
sandboxing, prompt-injection defenses, MCP server hardening, secret scoping
for agents, and runtime policy enforcement.
* Build internal tooling in TypeScript: SDKs, CLI utilities, GitHub Actions,
custom linters, and developer-facing dashboards that make the secure path the
easy path.
* Threat-model new features alongside product engineers, especially those
involving LLM integrations, autonomous agents, or third-party tool calls.
* Integrate and tune SAST, DAST, SCA, secret scanning, and IaC scanning
(Terraform, Kubernetes manifests, Helm) into pull-request workflows with
low-friction feedback loops.
* Lead incident response for security events, coordinating cross-functionally
and producing blameless postmortems that improve our systems, not assign
blame.
* Partner with the AI/ML team on responsible deployment of agents — defining
what "trusted action" means, what telemetry we need, and how we contain blast
radius when an agent misbehaves.
* Mentor engineers across the org on secure coding patterns in TypeScript and
on the unique risks of building with LLMs and agent frameworks.
WHAT WE'RE LOOKING FOR
* 4+ years of hands-on experience in DevSecOps, application security, or
platform security roles.
* Strong working knowledge of TypeScript and the Node.js ecosystem.
* Practical experience securing cloud infrastructure (AWS, GCP, or Azure),
containers, and Kubernetes.
* Fluency with modern CI/CD tooling (GitHub Actions, or similar) and IaC
(Terraform, Pulumi).
* Genuine curiosity about — and ideally hands-on experience with agentic AI
systems: LLM tool use, function calling, MCP, agent frameworks (LangGraph,
OpenAI Agents SDK, Anthropic SDK, etc.), and the emerging security patterns
around them.
* A collaboration-first mindset. You write clearly, give feedback kindly, and
would rather pair on a problem than throw a Jira ticket over the wall.
* Comfort with ambiguity — the security playbook for agentic systems is being
written in real time, and you want to help write it.
BONUS POINTS
* Experience with prompt-injection research, LLM red-teaming, or AI
safety/evals work.
* Contributions to open-source, especially in the TypeScript or AI or Security
ecosystems.
* Familiarity with SOC 2, ISO 27001, or similar compliance frameworks — and
opinions on how to satisfy them without crushing engineering velocity.
* Background in incident response or detection engineering at a fast-moving
company.
The estimated annual salary for this role is between $150,000 - $200,000, plus a
competitive equity package. Actual compensation is determined based upon a
variety of job related factors that may include: transferable work experience,
skill sets, and qualifications. Total compensation also includes a comprehensive
benefit package, including: medical, dental, vision, 401(k) plan, unlimited paid
time off, generous parental leave plan, and others for mental and wellness
support.
While we are a remote-first company, we have opened offices in New York City and
the San Francisco Bay Area, as an option for those in those cities who wish to
work in-person. For all other employees, there is a WFH monthly stipend to pay
for co-working spaces.
MORE ABOUT ARIZE
Arize’s mission is to make the world’s AI work—and work for people.
Our founders came together through a shared frustration: while investments in AI
are growing rapidly across every industry, organizations face a critical
challenge—understanding whether AI is performing and how to improve it at scale.
Learn more about what we're doing here:
https://techcrunch.com/2025/02/20/arize-ai-hopes-it-has-first-mover-advantage-in-ai-observability/
[https://techcrunch.com/2025/02/20/arize-ai-hopes-it-has-first-mover-advantage-in-ai-observability/]
https://arize.com/blog/arize-ai-raises-70m-series-c-to-build-the-gold-standard-for-ai-evaluation-observability/
[https://arize.com/blog/arize-ai-raises-70m-series-c-to-build-the-gold-standard-for-ai-evaluation-observability/]
Diversity & Inclusion @ Arize
Our company's mission is to make AI work and make AI work for the people, we
hope to make an impact in bias industry-wide and that's a big motivator for
people who work here. We actively hope that individuals contribute to a good
culture
* Regularly have chats with industry experts, researchers, and ethicists across
the ecosystem to advance the use of responsible AI
* Culturally conscious events such as LGBTQ trivia during pride month
* We have an active Lady Arizers subgroup
Which skills does this role require?
Make your next move
Build a shortlist and prepare
Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.
- Build a focused shortlist before you applyCompare role requirements with your experience and give each application a clear reason.
- Practice explaining your experience in an interviewRehearse your answers before meeting the hiring team.
Other roles to compare
Review the responsibilities and requirements before adding an opening to your shortlist.
AI Workflow Engineer
Scout Motors Inc. · Charlotte, North Carolina, United States
AI Solutions Engineer
Superior Essex · Sandy Springs, Georgia, United States
Automation Engineer, CGIC & BD AI Automation
Quantum Sky · Reston, Virginia, United States
Lead AI Forward Engineer
Thomson Reuters · Frisco, Texas, United States
Principal Engineer (AI Engineering)
Wells Fargo · Columbus, Ohio, United States
AI Solutions Engineer
Vantage Bank · Fort Worth, Texas, United States
Role information can change. Confirm current details on the original application page.
