Skip to content
OpenAIOpenAI

Principal Security Engineer, Infrastructure Security

Leads architecture and implementation of planet-scale security services like authN/Z, proxies, and key management for OpenAI's GPU clusters, multi-cloud infra, and AI models. Requires expertise in secure distributed systems, cloud platforms, and cross-team leadership.

About the job

Responsibilities

  • Own the architecture and roadmap for one or more core security services (e.g., authN/Z, policy enforcement, secure proxies, key management), taking them from design to rollout to long-term operation.
  • Design and implement planet-scale security systems that provide strong guarantees across hardware, operating systems, Kubernetes, networks, and CI/CD: balancing security, reliability, latency, and developer ergonomics.
  • Lead cross-functional launches with infrastructure and research engineering teams, shaping interfaces, migration plans, and safe rollout strategies across large fleets and critical workflows.
  • Build or evolve security primitives (identity, attestation, authorization, encryption key lifecycle, access mediation) that become platform building blocks for OpenAI.
  • Leverage frontier models and agents to develop automation and detection tooling to continuously identify and mitigate risks in large-scale cloud and on-prem environments.
  • Lead design reviews and threat models for major initiatives, and drive closure on systemic issues.
  • Mentor engineers across InfraSec and partner teams, raising the bar on engineering quality, operational readiness, and secure-by-default practices.

Requirements

  • Strong software engineering skills with a track record of shipping and operating reliable distributed systems in production.
  • Experience building or operating critical infrastructure, especially security infrastructure, at planet scale (e.g., auth services, service-to-service proxies, certificate or key-management systems).
  • Deep understanding of security principles, best practices, and common vulnerabilities.
  • Demonstrated ability to lead cross-team technical initiatives: setting direction, aligning stakeholders, driving execution, and delivering measurable outcomes.
  • Expertise and curiosity about using frontier models and agents to effectively solve security challenges.
  • Expertise in securing large-scale cloud platforms (e.g., Azure, AWS, GCP), including multi-cloud networks and cloud-agnostic system design.
  • A proactive mindset, with the ability to identify and address security gaps or inefficiencies through automation and tooling.
  • Strong analytical and problem-solving skills, with an ability to think critically and objectively assess risks.
  • Excellent communication skills, with the ability to convey complex security concepts to executive, technical, and non-technical stakeholders.

Skills

Kubernetes, AWS, Azure, GCP, Distributed Systems, Authentication, Authorization, Key Management, Service Mesh, Encryption

GitLab

GitLab

United States
Principal Security Researcher
$203k+/yrRemote10+ YOESecurity Engineering

Leads offensive security research across GitLab’s codebase and AI-powered agentic surfaces, identifying systemic vulnerabilities, developing exploit proofs of concept, and driving remediation. Requires 10+ years of security research or penetration-testing experience and proficiency in multiple programming languages.

GitLab

GitLab

United States
Principal Security Awareness & Human Risk Engineer
$203k+/yrRemote10+ YOESecurity Engineering

Own GitLab’s global security awareness and human-risk program, leading phishing simulations, behavior-change initiatives, training platforms, vendor strategy, and audit support. Requires 10+ years scaling enterprise awareness programs and strong stakeholder influence in a distributed organization.

Wrapbook

Wrapbook

United States
GRC Principal - Data Privacy and Security
$143k+/yrRemote10+ YOESecurity Engineering

Leads security, privacy, audit, vendor-risk, and AI governance programs while setting long-term GRC strategy and executing cross-functional controls. Requires 10+ years of GRC, information security, and privacy compliance experience, with deep SOC 2, privacy, and emerging AI governance expertise.

Exa

Exa

San Francisco, CA

Head of Security
$250k+/yrOn-site8+ YOESecurity Engineering

Leads Exa’s company-wide security strategy, architecture, engineering, governance, incident response, and team development across AI infrastructure, cloud, products, and corporate systems. Requires executive-level security accountability and deep technical credibility in a rapidly scaling technology company.

Gusto

Gusto

San Francisco, CA

Senior Staff IT Controls, Enterprise Applications
$245k+/yrHybrid10+ YOESecurity Engineering

Own and scale IT general controls, access governance, segregation of duties, and audit readiness across enterprise applications. The role combines SOX expertise with AI-enabled continuous controls monitoring and requires 10+ years of controls, audit, or enterprise governance experience.