LogoKode$word
Arq Inc. logo
Verified Tech Organization

Careers at Arq Inc.

Browse and filter through all verified positions currently open at Arq Inc..

Total Company Roles13
Matching Filter13

All Openings (13)

Ordered by most recently published

Security Engineer, Lead

On-sitefull timeLead / StaffSao Paulo, Brazil
Apply Now

What We're Looking For You'll be ARQ's first Security Engineer based in Brazil – it's the chance to lay the foundation for how we do security in the region and shape how that function grows from here. You'll work closely with our global security team but have real autonomy in deciding what "good" looks like locally, from day one. We're looking for someone who enjoys a multidisciplinary role. Security at ARQ spans Application Security, Security Operations, and Governance/Risk/Compliance, and we need someone comfortable moving across at least two of these three areas – because in a founding role, there's no one else to hand off the parts that don't fit your specialty. What you'll do Drive the application security roadmap: threat modelling standards, secure code review practices, API security testing strategy, and security pipeline architecture Define the company's approach to securing AI/agentic workflows – setting guardrails for prompts, destructive actions, and data exposure, and advising other teams building with LLMs/MCP servers Set the technical direction for detection engineering, alert pipelines, and automated response across the security stack (Datadog SIEM, CrowdStrike, Cloudflare), and raise the bar on how the team designs and reviews detections Own incident response readiness at a program level: design IR playbooks, lead tabletop exercises, and act as technical lead during major incidents Set the standard and approach for cloud security assessments across AWS and Kubernetes, reviewing findings from other engineers and tackling the most complex environments directly Own the vendor security assessment framework itself: continuously improving the due diligence process and handling the highest-risk vendor reviews Act as a technical mentor to mid and senior engineers, reviewing their detection logic, assessments, and playbooks without formal management responsibilities What you'll need 7+ years in information security, including demonstrated experience building or substantially maturing a security function or program from the ground up Deep, hands-on expertise in cloud infrastructure security (AWS, Kubernetes), able to architect controls Proven experience driving application security programs: threat modelling frameworks, secure code review standards, CI/CD pipeline hardening, and API security testing strategy Demonstrated ability to define practical security guardrails for AI/agentic tooling – you understand the risks of LLM integrations, MCP servers, and automated workflows at an architectural level Strong detection engineering background – you've designed detection strategy and mentored others in writing rules Deep experience with endpoint security tooling (EDR/XDR) and identity & access management architecture in a SaaS-heavy environment (Google Workspace, Okta/Cloudflare Access, SSO/SCIM) Experience designing or significantly evolving a vendor security assessment/third-party due diligence program Excellent written and verbal communication; comfortable representing security decisions to leadership and cross-functional stakeholders Business fluent in English Benefits Competitive salary and benefits Stock options, so you own part of what you build Discretionary performance bonus The latest tools and technology A world-class team that will challenge and grow your skills The opportunity to help build the best fintech app in Latin America Office Policy: 3-4 days a week in-office

View more...
Cybersecurity
Verified28 days ago

Security Engineer, Mid

On-sitefull timeMid-LevelSao Paulo, Brazil
Apply Now

What We're Looking For You'll be ARQ's first Security Engineer based in Brazil – it's the chance to lay the foundation for how we do security in the region and shape how that function grows from here. You'll work closely with our global security team but have real autonomy in deciding what "good" looks like locally, from day one. We're looking for someone who enjoys a multidisciplinary role. Security at ARQ spans Application Security, Security Operations, and Governance/Risk/Compliance, and we need someone comfortable moving across at least two of these three areas – because in a founding role, there's no one else to hand off the parts that don't fit your specialty. What you'll do Support application security work: threat modelling sessions, secure code review, API security testing, and CI/CD pipeline checks Help review and monitor AI/agentic workflows for prompt risks, unsafe automated actions, and data exposure Build and maintain SIEM detection rules, alert pipelines, and response playbooks (Datadog SIEM, CrowdStrike, Cloudflare), owning detection coverage for a defined set of systems end-to-end Support incident response: triage alerts, execute IR playbooks, and help run tabletop exercises Conduct cloud security assessments across AWS and Kubernetes environments under the guidance of senior team members Execute vendor security assessments using the established due diligence framework, owning the review process for a portion of the vendor pipeline What you'll need 2–4 years in information security or a closely related technical role (security operations, cloud/infra engineering with a security focus, or similar) Working experience with at least one cloud environment (AWS preferred) and familiarity with Kubernetes fundamentals Basic familiarity with application security concepts: threat modelling, secure code review, or API security testing Curiosity about AI/agentic tooling risks (LLM integrations, MCP servers, automated workflows) – prior hands-on experience is a plus, not required Exposure to SIEM platforms and an interest in detection engineering – you've written or tuned at least a few detection rules Strong written and verbal communication in English Benefits Competitive salary and benefits Stock options, so you own part of what you build Discretionary performance bonus The latest tools and technology A world-class team that will challenge and grow your skills The opportunity to help build the best fintech app in Latin America Office Policy: 3-4 days a week in-office

View more...
Cybersecurity
Verified28 days ago

Security Engineer, Senior

On-sitefull timeSeniorSao Paulo, Brazil
Apply Now

What We're Looking For You'll be ARQ's first Security Engineer based in Brazil – it's the chance to lay the foundation for how we do security in the region and shape how that function grows from here. You'll work closely with our global security team but have real autonomy in deciding what "good" looks like locally, from day one. We're looking for someone who enjoys a multidisciplinary role. Security at ARQ spans Application Security, Security Operations, and Governance/Risk/Compliance, and we need someone comfortable moving across at least two of these three areas – because in a founding role, there's no one else to hand off the parts that don't fit your specialty. What you'll do Drive application security initiatives: threat modelling, secure code review support, API testing, and security pipeline improvements Assess and secure AI/agentic workflows across the company — reviewing prompts, preventing destructive actions, and controlling data exposure Build and improve SIEM detection rules, alert pipelines, and automated response playbooks (Datadog SIEM, CrowdStrike, Cloudflare) Contribute to incident response readiness, including IR playbooks, tabletop exercises, and forensic procedures Conduct cloud security assessments across AWS and Kubernetes environments Establish and run the vendor security assessment process — building a scalable due diligence framework for third-party onboarding What you'll need 4–7 years in information security, ideally having built or significantly shaped the security function at a startup or high-growth company - you've been the person who sets things up, not just maintains them Hands-on experience with cloud infrastructure security (AWS, Kubernetes) Familiarity with application security practices: threat modelling, secure code review, CI/CD pipeline hardening, and API security testing Ability to assess and secure emerging AI/agentic tooling - you understand the risks of LLM integrations, MCP servers, and automated workflows, and can define practical guardrails Working knowledge of SIEM platforms and detection engineering - you've written detection rules Experience with endpoint security tooling (EDR/XDR) and identity & access management in a SaaS-heavy environment (Google Workspace, Okta/Cloudflare Access, SSO/SCIM) Experience running or contributing to vendor security assessments and third-party due diligence Strong written and verbal communication in English Benefits Competitive salary and benefits Stock options, so you own part of what you build Discretionary performance bonus The latest tools and technology A world-class team that will challenge and grow your skills The opportunity to help build the best fintech app in Latin America Office Policy: 3-4 days a week in-office

View more...
Cybersecurity
Verified28 days ago

Page 2 of 2