# Cybersecurity & Technology Audit Leader

**Company:** [OpenAI](https://hotfix.jobs/companies/openai)
**Location:** San Francisco, CA
**Role:** Security Engineering
**Salary:** $342k – $380k/yr
**Experience:** 12+ years
**Skills:** Cybersecurity, Cloud Security, ai risk management, Data Governance, cloud platforms, identity and access management, Application Security, Vulnerability Management, Incident Response, Data Analytics, Automation, cissp, cisa
**Posted:** 2026-07-29

> Lead cybersecurity and technology audits at OpenAI, shaping a next-generation audit function using AI, automation, and analytics. Assess complex tech and AI risks, provide governance advice to executives, and build advanced audit capabilities in a hybrid San Francisco role requiring 12+ years of experience.

## Job Description

## Responsibilities
- Build and execute a risk-based audit and advisory strategy across cybersecurity, infrastructure, systems architecture, cloud environments, data, software development, change management, operational resilience, and AI.
- Drive strong governance and oversight of critical technology programs and emerging AI risks, including model governance, data provenance and quality, privacy, security, responsible AI, third-party dependencies, monitoring, and human oversight.
- Assess complex technical environments and control effectiveness across areas such as architecture, access models, system logs, code repositories, cloud controls, vulnerability data, and security monitoring, with a focus on distinguishing material risks from lower-value compliance issues.
- Translate complex technical findings into clear business implications and practical recommendations that enable innovation while supporting effective risk management.
- Build advanced audit capabilities using data analytics, automation, and AI to improve risk assessment, audit scoping, testing, continuous monitoring, and reporting, including identifying anomalies, control weaknesses, and emerging risks.
- Build trusted relationships across the organization and support clear, effective reporting to executive management, regulators, and the Board.
- Monitor developments in technology, threat activity, regulation, and industry practices to keep the audit approach current and forward-looking.
- Coach colleagues, share technical expertise, and contribute to a culture of high standards, sound judgment, curiosity, ownership, and continuous learning.

## Requirements
- 12-15+ years of relevant experience in cybersecurity, technology audit, technology risk, security engineering, data risk, cloud security, or a related field.
- Strong technical expertise across several areas, such as cloud platforms, identity and access management, application security, infrastructure, networks, vulnerability management, incident response, security operations, data platforms, or software development.
- Strong knowledge of data architecture, provenance, lineage, quality, governance, access, and analytics, including the risks associated with using data in AI systems.
- Knowledge of AI and machine-learning risks, along with experience using data analytics, scripting, automation, or AI-assisted techniques—or a demonstrated ability to develop these capabilities quickly.
- The ability to understand complex systems, ask incisive questions, evaluate incomplete information, and reach well-supported conclusions with sound judgment.
- The confidence to challenge constructively and a business-enabling mindset that balances innovation, speed, business impact, and risk.
- Strong communication and relationship-building skills, including the ability to explain complex technical issues to executives and work effectively with technology leaders, engineers, risk professionals, and senior management.
- Comfort operating in a fast-paced, evolving environment, with the initiative, curiosity, and adaptability to help build a new team and capability.
- A bachelor’s degree in cybersecurity, computer science, information systems, engineering, data science, accounting, or a related discipline—or equivalent practical experience.

## Nice-to-Haves
- Relevant certifications, such as CISSP, CISA, CISM, CRISC, CCSP, cloud-provider certifications, or data and AI credentials.

## Similar roles

- [Senior Staff Software Engineer, Identity](https://hotfix.jobs/jobs/d1e98174-a157-4283-9c5e-8591d3d56b7f) - OpenAI - San Francisco, CA - $345k – $405k/yr
- [Staff+ Application Security Engineer](https://hotfix.jobs/jobs/176eddbe-ab46-4c6b-b459-b97404661b42) - Anthropic - San Francisco, CA - $320k – $485k/yr
- [Staff Security Reliability Engineer](https://hotfix.jobs/jobs/626c14c3-6d35-433f-a4a1-7e4e17fa2b28) - OpenAI - San Francisco, CA - $293k – $385k/yr
- [Software Engineer, Security](https://hotfix.jobs/jobs/e6283f18-9abb-4d55-acf7-cc3220bb1636) - Notion - San Francisco, CA - $290k – $350k/yr
- [Secure Manufacturing & Stealth Partner, Marketing](https://hotfix.jobs/jobs/01484828-a22c-4b90-bb28-b5355f7afcd6) - OpenAI - San Francisco, CA - $288k – $425k/yr

**Apply:** https://hotfix.jobs/jobs/0e341af3-5fe6-48cf-9b15-cfbbe2442953
**Canonical:** https://hotfix.jobs/jobs/0e341af3-5fe6-48cf-9b15-cfbbe2442953