Skip to content
OpenAIOpenAISan Francisco, CA

Cybersecurity & Technology Audit Leader

Lead cybersecurity and technology audits at OpenAI, shaping a next-generation audit function using AI, automation, and analytics. Assess complex tech and AI risks, provide governance advice to executives, and build advanced audit capabilities in a hybrid San Francisco role requiring 12+ years of experience.

342k – 380k/yr
Hybrid12+ YOESecurity Engineering

About the role

Responsibilities

  • Build and execute a risk-based audit and advisory strategy across cybersecurity, infrastructure, systems architecture, cloud environments, data, software development, change management, operational resilience, and AI.
  • Drive strong governance and oversight of critical technology programs and emerging AI risks, including model governance, data provenance and quality, privacy, security, responsible AI, third-party dependencies, monitoring, and human oversight.
  • Assess complex technical environments and control effectiveness across areas such as architecture, access models, system logs, code repositories, cloud controls, vulnerability data, and security monitoring, with a focus on distinguishing material risks from lower-value compliance issues.
  • Translate complex technical findings into clear business implications and practical recommendations that enable innovation while supporting effective risk management.
  • Build advanced audit capabilities using data analytics, automation, and AI to improve risk assessment, audit scoping, testing, continuous monitoring, and reporting, including identifying anomalies, control weaknesses, and emerging risks.
  • Build trusted relationships across the organization and support clear, effective reporting to executive management, regulators, and the Board.
  • Monitor developments in technology, threat activity, regulation, and industry practices to keep the audit approach current and forward-looking.
  • Coach colleagues, share technical expertise, and contribute to a culture of high standards, sound judgment, curiosity, ownership, and continuous learning.

Requirements

  • 12-15+ years of relevant experience in cybersecurity, technology audit, technology risk, security engineering, data risk, cloud security, or a related field.
  • Strong technical expertise across several areas, such as cloud platforms, identity and access management, application security, infrastructure, networks, vulnerability management, incident response, security operations, data platforms, or software development.
  • Strong knowledge of data architecture, provenance, lineage, quality, governance, access, and analytics, including the risks associated with using data in AI systems.
  • Knowledge of AI and machine-learning risks, along with experience using data analytics, scripting, automation, or AI-assisted techniques—or a demonstrated ability to develop these capabilities quickly.
  • The ability to understand complex systems, ask incisive questions, evaluate incomplete information, and reach well-supported conclusions with sound judgment.
  • The confidence to challenge constructively and a business-enabling mindset that balances innovation, speed, business impact, and risk.
  • Strong communication and relationship-building skills, including the ability to explain complex technical issues to executives and work effectively with technology leaders, engineers, risk professionals, and senior management.
  • Comfort operating in a fast-paced, evolving environment, with the initiative, curiosity, and adaptability to help build a new team and capability.
  • A bachelor’s degree in cybersecurity, computer science, information systems, engineering, data science, accounting, or a related discipline—or equivalent practical experience.

Nice-to-Haves

  • Relevant certifications, such as CISSP, CISA, CISM, CRISC, CCSP, cloud-provider certifications, or data and AI credentials.

Skills

CybersecurityCloud Securityai risk managementData Governancecloud platformsidentity and access managementApplication SecurityVulnerability ManagementIncident ResponseData AnalyticsAutomationcisspcisa
OpenAI

Senior Staff Software Engineer, Identity

OpenAISan Francisco, CA +1

Leads the architecture and evolution of enterprise identity systems, including SSO, SCIM, tenant models, permissions, and shared identity primitives across products. Requires senior-staff experience guiding large-scale distributed platforms, setting multi-year technical direction, and aligning multiple teams on secure, reliable solutions.

345k – 405k/yrHybrid7+ YOESecurity Engineering
Anthropic

Staff+ Application Security Engineer

AnthropicSan Francisco, CA +2

Staff Application Security Engineer focused on M&A due diligence and secure integration of acquired codebases and systems at Anthropic. Lead security assessments, risk readouts, post-close remediation and automation using Claude, while contributing to core AppSec work. Requires 7+ years AppSec experience, rapid codebase assessment skills, and coding ability.

320k – 485k/yrHybrid7+ YOESecurity Engineering
OpenAI

Staff Security Reliability Engineer

OpenAISan Francisco, CA

Senior technical owner designing, building, and operating secure, reliable infrastructure-as-code platforms for identity, access, and shared services. Requires 10+ years of hands-on SRE experience in high-reliability on-prem/hybrid environments.

293k – 385k/yrHybrid10+ YOESecurity Engineering
Notion

Software Engineer, Security

NotionSan Francisco, CA

Security engineer owning cross-cutting auth, authorization, and AI guardrail programs across product and infrastructure. Requires 10+ years shipping security-critical infrastructure and experience with AI/LLM protections.

290k – 350k/yrHybrid10+ YOESecurity Engineering
OpenAI

Secure Manufacturing & Stealth Partner, Marketing

OpenAISan Francisco, CA

Serve as the dedicated senior security partner to OpenAI's Marketing team, identifying secrecy risks in launches, events, creative production, and external partners while embedding practical controls that protect sensitive information without slowing execution. Requires 12+ years protecting major product launches and building trusted relationships with executives and creative teams.

288k – 425k/yrHybrid12+ YOESecurity Engineering