Latest Security Engineering jobs at OpenAI
Job results
Design and ship security-critical software and firmware at the boundary between policy systems and hardware-backed cryptographic protection. The role requires 5+ years of secure embedded development and deep C, C++, or Rust experience.
Leads cybersecurity and cyber intelligence operations for high-risk user-safety decisions, combining strategic planning, operational systems, automation, and direct people management. Requires 8+ years in cybersecurity-related work and 4+ years leading teams.
Senior individual contributor responsible for improving cyber operations, resolving complex dual-use safety decisions, and building scalable reviewer, quality, vendor, and automation systems. Requires 8+ years of hands-on cybersecurity experience and strong operational judgment.
Defines the security architecture for a next-generation operating system, spanning trust boundaries, hardware-backed protections, isolation, secure updates, and AI-agent guardrails. The role requires deep privileged-systems expertise, systems programming ability, and experience securing platforms across hardware, firmware, and software.
Investigates and assesses physical security threats involving personnel, executives, events, travel, and operations. The role requires at least five years of relevant intelligence or threat-assessment experience, strong analytical communication, and familiarity with OSINT, behavioral threat methodologies, and technology-enabled investigations.
The Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.
Leads the architecture and evolution of enterprise identity systems, including SSO, SCIM, tenant models, permissions, and shared identity primitives across products. Requires senior-staff experience guiding large-scale distributed platforms, setting multi-year technical direction, and aligning multiple teams on secure, reliable solutions.
Lead day-to-day physical security operations and vendor-managed armed/unarmed guard teams at OpenAI's Mountain View site. Develop policies, deliver FTO-style training, manage vendor performance, and coordinate with law enforcement while building cross-functional relationships. Requires 15+ years law enforcement or corporate security experience with frontline supervisory background.
Serve as the dedicated senior security partner to OpenAI's Marketing team, identifying secrecy risks in launches, events, creative production, and external partners while embedding practical controls that protect sensitive information without slowing execution. Requires 12+ years protecting major product launches and building trusted relationships with executives and creative teams.
Build and own a portfolio of specialized AI agents that autonomously discover, validate, and drive remediation of vulnerabilities across OpenAI's infrastructure, cloud, Kubernetes, web apps, and attack surface. Requires deep offensive security expertise, agent/systems building experience, and strong production engineering skills at Staff-Principal level.
Leads physical and corporate security operations for the Paris office, supports Brussels, and coordinates regional coverage across Europe. The role requires 8+ years of operational security experience, strong incident management and vendor oversight capabilities, and professional English; French is preferred.
Senior technical owner designing, building, and operating secure, reliable infrastructure-as-code platforms for identity, access, and shared services. Requires 10+ years of hands-on SRE experience in high-reliability on-prem/hybrid environments.
Security Engineer owning end-to-end hardware, firmware, and system security for OpenAI's first-party AI accelerators and servers. Requires 7+ years in hardware/embedded security and strong systems programming skills.
Build and operate backend and data systems for real-time fraud/abuse detection, investigation, and enforcement at OpenAI. Requires 5+ years backend engineering and 2+ years fraud/abuse experience.
Defines and maintains policies for AI model behavior in high-risk domains like agentic systems and user safety. Collaborates with research, engineering, and product teams to operationalize policies into measurable safeguards using empirical data and red-teaming.
Designs and builds systems to proactively detect and enforce against product abuse using data science, ML, and investigations. Collaborates cross-functionally on monitoring new/existing products and responding to critical escalations. Requires 4+ years in technical analysis with SQL/Python.
Conducts deep investigations into sophisticated threat actors misusing AI models and targeting OpenAI, leveraging OSINT, telemetry, and scripting to identify disruptions. Builds scalable tooling and automations to enhance detection and safety, partnering cross-functionally for impact.
Leads US government compliance programs, driving FedRAMP and agency ATOs for OpenAI products. Collaborates with engineers on security controls, documentation, and audits in highly regulated environments. Requires 5+ years compliance experience and deep USG framework knowledge.
Build scalable systems and data pipelines for security observability, enhancing detection, forensics, and compliance. Requires strong engineering in Python/Golang, Terraform, Azure, and data pipelines with a generalist SRE mindset.
Builds and operates Host Assurance platform to establish trust in bare-metal hosts for OpenAI's global infrastructure. Requires strong software engineering, deep expertise in PKI/HSM/cryptography/secure boot/host attestation, and ability to work across hardware-software boundaries at scale.
Leads architecture and implementation of planet-scale security services like authN/Z, proxies, and key management for OpenAI's GPU clusters, multi-cloud infra, and AI models. Requires expertise in secure distributed systems, cloud platforms, and cross-team leadership.
Principal Security Engineer leads security for OpenAI's infrastructure including GPU clusters, multi-cloud, datacenters, and Kubernetes. Drives strategy, builds controls against advanced threats, and mentors teams with deep cloud and on-prem expertise.
Builds and operates detection and response systems to protect OpenAI's sensitive assets across endpoints, cloud, Kubernetes, and datacenter infrastructure. Requires hands-on threat detection, incident response experience, and expertise in modern cloud platforms and automation.
Security Engineer focused on insider threat detection and response, building automated detection workflows, tuning rules, and partnering on investigations for AI infrastructure. Requires 5+ years experience in detection/response, OS/cloud familiarity, and scripting proficiency.
Principal-level Offensive Security Engineer conducts red/purple team operations and penetration testing on AI agent products like Codex and Operator, hunting vulnerabilities in app-infra-model interactions and collaborating with defensive teams to strengthen security.
Builds backend systems to enforce data privacy, automate compliance, and implement distributed authorization mechanisms. Requires 5+ years experience in backend/infrastructure with languages like Python or Go, plus familiarity with privacy regulations.
Designs and builds security controls for infrastructure including GPU clusters, multi-cloud setups, datacenters, Kubernetes, and networks to protect AI models and data from advanced threats. Requires deep security expertise, cloud platform knowledge, and proactive problem-solving across on-prem and cloud environments.
Designs and builds production-grade security services like auth systems, proxies, and key management for OpenAI's GPU clusters, multi-cloud infrastructure, and AI workloads. Requires strong software engineering in Python/Go/Rust, experience with critical security infra, and cloud security expertise.
Designs and implements security frameworks, policies, and controls for agentic AI systems, including threat modeling, isolation techniques, and safety monitoring. Requires strong systems programming, cloud security expertise, and cross-functional collaboration in a fast-paced environment.
Build and operate detection and response systems protecting sensitive infrastructure, products, research environments, and data. The role requires hands-on threat detection or incident response experience, Kubernetes and cloud expertise, threat modeling, automation, and strong cross-functional collaboration.
Identifies and mitigates application security vulnerabilities through code reviews, penetration testing, and security assessments. Collaborates with development teams to integrate secure coding practices and provides guidance on threats and remediation.