2 Arrow Labs

All open roles

Security Engineer

Remote US or New York | Full-time or contract

About 2 Arrow Labs

2 Arrow Labs is a New York engineering studio for deep tech teams. We take on the technical work other teams gave up on.

We build hard systems and hand them over with tests and docs. We read codebases nobody fully understands and write down what they should do. We set up AI coding agents and measure how they do on real code.

The role

We are hiring a Security Engineer to review client systems and the AI agent setups they run. You will find real vulnerabilities, explain them clearly, and help clients fix them.

This role sits between vulnerability research and applied engineering. The work is hands-on. You read complex code, model threats, build tools and own your findings through delivery.

This is a code-level role, separate from security operations, compliance and audit work. You take an unclear system, decide how to assess it, and deliver clear findings with little direction.

What you'll do

  • Own security reviews. Lead reviews of client systems or components, from the scope through the final report.
  • Find and prove vulnerabilities. Trace root causes and exploit paths, judge impact, and write proof of concept code when it helps.
  • Review AI agent setups. Check how coding agents and model tools reach code, data and credentials, and where they can be misused.
  • Model threats. Map attack surfaces, data flows and trust boundaries, and recommend fixes engineers can ship.
  • Build security tools. Write targeted tests and automation that widen coverage and make reviews repeatable.
  • Explain your findings. Write clear reports and walk client engineers through the evidence and the fix.

How this role fits the team

You work on client projects next to the engineers who build and review the system. Security reviews often run alongside a build or a codebase review. You own the security side and pull in help when you need it.

What success looks like

  • Your findings are precise, reproducible and ranked by real impact.
  • Client engineers fix what you found because your reports make the fix clear.
  • The tools and checks you build make the next review faster.
  • Clients trust your judgment and come back for the next review.

What you'll bring

The following are requirements for this role.

  • Hands-on security work. Three or more years in application security, vulnerability research or security-focused engineering.
  • Vulnerabilities you found. You can walk us through vulnerabilities you found yourself, how you proved them, and their impact.
  • Code reading. You read unfamiliar code fast and trace how data moves through it.
  • Programming. Strong in at least two of Rust, Go, C, C++, Python or TypeScript.
  • Systems knowledge. Memory safety, operating system internals, and privilege boundaries.
  • Clear writing. You write findings that engineers can act on the same day.

Nice to have

These are not day-one requirements. They help you contribute sooner or grow the role over time.

  • Experience testing LLM applications, agents or model tool use.
  • CVEs, bug bounty findings, CTF results or published writeups.
  • Fuzzing, reverse engineering or kernel work.
  • Experience with cloud infrastructure, Kubernetes or Terraform.

Compensation

The base salary range for this role is $220,000 to $300,000. Contract work is paid at roughly $175 to $250 an hour. Pay depends on experience, scope and location. These figures are starting pay for candidates based in the United States. If your number is outside the range, write to us anyway.

Benefits

Full-time roles include four weeks of paid time off each year.