Security Engineer, Insider Threat Detection & Response
Security Engineer focused on insider threat detection and response, building automated detection workflows, tuning rules, and partnering on investigations for AI infrastructure. Requires 5+ years experience in detection/response, OS/cloud familiarity, and scripting proficiency.
About the job
About the Role
As a Security Engineer, you will build, operate, and secure transformational AI technologies with a focus on detecting insider threats and influencing controls to safeguard OpenAI's most sensitive assets.
In this role, you will:
- Innovate on Detection and Response infrastructure to engineer and automate end-to-end detection and investigation workflows.
- Develop, measure, and tune detection rules to ensure effective and sustainable operations.
- Drive projects across OpenAI’s technology stack with a focus on insider threats, ranging from access abuse and intellectual property theft to novel risks emerging within AI infrastructure.
- Partner closely with cross-functional stakeholders, including HR, Legal, and peer investigative teams, providing technical expertise and evidence to support investigations.
- Collaborate on cutting-edge AI research, and use AI to improve OpenAI’s Security posture.
You might thrive in this role if you:
- 5+ years experience working in a detection/response or insider-risk role. We are seeking mid-level and senior candidates.
- You have broad familiarity with operating systems and platforms such as macOS, Windows, Linux, and Kubernetes, along with experience in cloud infrastructure.
- Knowledge of modern adversary tactics and attack paths, data exfiltration techniques, and have experience running and leading incidents.
- Proficiency with a scripting language (e.g. Python, Bash, PowerShell, or similar).
- Independently manage and run projects, balance preventative controls with user friction, and prioritize efforts for risk reduction.
- You’re motivated by securing transformative technology and can adapt familiar security frameworks to new risks in AI infrastructure.
Skills
Kubernetes, macOS, Windows, Linux, Python, Bash, PowerShell, Cloud Infrastructure, Detection Engineering, Incident Response
Similar jobs
Security Engineering jobsThe Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.
This role builds and improves infrastructure security controls across cloud, operating system, Kubernetes, network, and CI/CD environments. It requires cloud security expertise, programming and Infrastructure as Code proficiency, threat-modeling experience, and the ability to lead infrastructure containment during security incidents.
The Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.
Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.
Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.