Security Engineer, Host Assurance
Builds and operates Host Assurance platform to establish trust in bare-metal hosts for OpenAI's global infrastructure. Requires strong software engineering, deep expertise in PKI/HSM/cryptography/secure boot/host attestation, and ability to work across hardware-software boundaries at scale.
About the job
Responsibilities
- Design, build, and operate components of the Host Assurance platform that establish trust in bare-metal hosts before they are eligible for production use.
- Help ensure hosts are verifiably trustworthy from delivery and installation through secure bootstrap and readiness to join orchestration systems.
- Build and improve systems such as machine identity, certificate issuance and enrollment, HSM-backed or key-management-backed trust services, host attestation, measurement, and baseline verification tooling.
- Validate delivered hardware and firmware against vendor claims and continuously detect and manage drift over time.
- Eliminate insecure bootstrap patterns while preserving deployment throughput and operational reliability. Partner with provisioning, fleet, and orchestration teams to deliver paved paths where the secure approach is the easiest approach.
- Contribute code, reviews, operational improvements, and design guidance for foundational trust services that must be dependable at scale.
- Help define observable, testable security properties for host platforms and improve the telemetry and validation needed to enforce them in practice.
- Participate in incident response, debugging, and post-incident improvements for security-critical infrastructure.
- Work across different deployment models and provider boundaries while maintaining a consistent bar for host trust outcomes.
Requirements
- Strong software engineering experience building and operating reliable production systems at scale.
- Deep expertise in at least one relevant domain such as PKI, HSMs, machine identity, applied cryptography, secure boot, firmware or hardware security, host attestation, or low-level platform security.
- Comfortable working across systems boundaries, from services and APIs down to host, boot, firmware, or hardware-adjacent trust mechanisms.
- Can write production quality code and reason clearly about failure modes, operational safety, and long-term maintainability.
- Experience replacing fragile or manual security mechanisms with durable, paved-path infrastructure.
- Balance rigor with pragmatism, and care about making strong security controls deployable in real-world environments.
- Self-directed, low ego, and willing to work across disciplines to solve the most important problems.
- Enjoy building in ambiguous spaces where the architecture is still emerging, stakes are at all time high, and the future is being built.
Skills
Pki, Hsm, Applied Cryptography, Secure Boot, Host Attestation, Firmware Security, Hardware Security, Machine Identity, Certificate Management, Key Management
Similar jobs
Security Engineering jobsConduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.
Build and operate evaluations for cyber capabilities and safeguard robustness in AI models, analyze adversarial data, and develop cyber-abuse detection probes. The role requires hands-on cybersecurity experience, Python proficiency, evaluation expertise, and strong cross-functional communication.
This hands-on security engineer will research sophisticated threat actors, build intelligence pipelines, conduct threat hunts, analyze malware and infrastructure, and translate findings into durable detections. The role requires at least five years of cyber threat intelligence or related experience, strong Python engineering, and malware and detection-analysis expertise.
Senior hands-on security engineer responsible for endpoint hardening, device trust, identity and SaaS governance, and scalable corporate-security automation across a growing organization. Requires endpoint security expertise, Python scripting, IAM and zero-trust depth, and strong threat-modeling judgment.
Design and ship security-critical software and firmware at the boundary between policy systems and hardware-backed cryptographic protection. The role requires 5+ years of secure embedded development and deep C, C++, or Rust experience.