Arena

Member of Security Staff, Privacy & Trust Ops Lead

SF Bay Area · Posted 3h ago

salary not listedstaffpermanentonsite

Job Description

About Arena Intelligence

Arena is the platform for evaluating how AI models perform in the real world. Founded by researchers from UC Berkeley's SkyLab, we're on a mission to measure and advance the frontier of AI for real-world use, and to build the foundation for everyone to understand, shape, and benefit from it.


Tens of millions of people use Arena each month to evaluate how frontier systems handle the work they actually do. The preferences they share power the most transparent, rigorous, and human-centered evaluations in AI. Leading AI labs, enterprises, and independent researchers rely on our work and open datasets to understand how models behave in real workflows: agentic coding, creative generation, professional productivity, and beyond. We go beyond leaderboards and decompose what human experience reveals about AI, so models advance toward the work people actually do.


We're a team of researchers, academics, builders, and creatives from UC Berkeley, Google, Stanford, and DeepMind. We seek truth, move fast, and value craftsmanship, curiosity, and impact over hierarchy. We're building a company where thoughtful, curious people from all backgrounds can do their best work together, in an office culture that radiates excellence, energy, and focus.

We're hiring the first dedicated owner of privacy, compliance, and trust operations at Arena. This is a build-from-here role. You'll be hands-on from day one, maturing core parts of the program as you go, and you'll decide what to prioritize first.

You'll partner closely with Engineering, driving privacy and trust engineering initiatives, like de-identification, pseudonymous identifiers, and data lifecycle controls, from requirements through to what actually ships in the product.

You'll also work closely with our Legal Team, who own the legal determinations. You own the operations underneath them: the programs that make those decisions real, evidenced, and repeatable.

This role is onsite in our San Francisco office. It works directly with our leadership team, and being in the room is part of the job.

What You'll Own

Privacy operations and the commercial data path. The privacy program end-to-end: records of processing, data subject rights, retention, breach notification, and the privacy notices that face millions of users. This also covers the compliance work behind how Arena's data products are packaged and shared externally.

Compliance, risk, and third-party management. The control framework portfolio (SOC 2, ISO 27001, NIST CSF, NIST AI RMF), our continuous compliance monitoring program, and a risk register with accountable business owners. You'll also own third-party risk management end-to-end, and privacy for the API and gateway, including the sub-processor register behind our enterprise customer terms.

Model-provider compliance. Arena's relationships with frontier labs are each their own compliance surface: data processing terms, acceptable-use obligations, provider provenance and screening, and trust operations when something escalates in either direction. This barely exists as a named job anywhere else.

Trust and safety governance. Mandated reporting and the clocks attached to it, evidence preservation, oversight of whether moderation actually works, and the enforcement policy underneath it.

The Authority That Comes With It

  • A gate on vendor and provider onboarding: your review has to close before onboarding proceeds

  • A named escalation path to the Executive Team when a proposed risk treatment is refused

  • A voice in major product and commercial decisions that touch trust, privacy, or data

  • Sign-off on compliance representations: nothing goes to a customer, provider, auditor, or regulator claiming a control we don't have

You'll Have

  • A track record of building a privacy or compliance program somewhere it didn't exist

  • Enough technical fluency to work directly with engineers on privacy and trust systems, reading a schema, reasoning about a data flow, and driving initiatives like de-identification and data lifecycle controls from requirements through to what ships

  • Real depth in GDPR and US state privacy regimes: you can run a DPIA yourself and reason about controller/processor boundaries in a genuinely ambiguous relationship

  • Audit experience from the inside: SOC 2 and ideally ISO 27001, owning evidence and control narratives rather than coordinating someone else who did

  • Experience owning an external party relationship where the obligations were contractual and the follow-through was on you

  • Experience on the commercial side of privacy, where the program gates revenue, not just protects data

  • An obligation you've owned with a real clock on it: mandated reporting, breach notification, regulatory disclosure

  • Judgment about what's actually risky, and the willingness to say plainly when something is theater

  • Comfort reasoning from principles on questions that don't have settled regulatory answers yet

Bonus Points

  • Experience working with or inside AI labs, model providers, or platforms with similar provider relationships

  • NIST AI RMF, ISO 42001, or comparable AI governance work

  • Trust and safety experience, especially mandated reporting regimes or platform integrity at consumer scale

  • Privacy engineering background

What this role is not

  • It is not a policy-writing seat. Policy is an output, not the job.

  • It is not a checkbox compliance seat. If your instinct is to close a finding by writing a
    document that says it is closed, this will not be a good fit.

  • It is not a product engineering role. If Arena builds new products in this space, they'd sit
    with their own dedicated team. This seat sets the governance and boundaries, not the roadmap.

What we offer

  • We offer competitive compensation and equity aligned to the markets where our team members are based. The base salary range will depend on the candidate’s permanent work location.

  • Comprehensive health and wellness benefits, including medical, dental, vision, and additional support programs.

  • The opportunity to work on cutting-edge AI with a small, mission-driven team

  • A culture that values transparency, trust, and community impact

Come help build the space where anyone can explore and help shape the future of AI.

Arena Intelligence provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, genetics, sexual orientation, gender identity, or gender expression. We are committed to a diverse and inclusive workforce and welcome people from all backgrounds, experiences, perspectives, and abilities.