Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 7
Audit @ 8
Change Management
Communication @ 7
Compliance
Data Science @ 4
Security @ 8
Software Development @ 7
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
The OpenAI Audit Team is building a next-generation internal audit function using AI, automation, and data analytics to identify and assess significant and emerging risks across technology, cybersecurity, finance, compliance, operations, and data.
As the Cybersecurity & Technology Audit Leader, you will help shape the strategy, methodology, technology, and culture of the audit function. You will lead complex audits and advisory reviews covering cybersecurity, technology, data, and AI-related risks, while advising leaders on governance, resilience, and risk management. This role is based in San Francisco, California, and follows a hybrid model with three days per week in the office.
Responsibilities
- Build and execute a risk-based audit and advisory strategy across cybersecurity, infrastructure, systems architecture, cloud environments, data, software development, change management, operational resilience, and AI.
- Drive governance and oversight of critical technology programs and emerging AI risks, including model governance, data provenance and quality, privacy, security, responsible AI, third-party dependencies, monitoring, and human oversight.
- Assess technical environments and control effectiveness across architecture, access models, system logs, code repositories, cloud controls, vulnerability data, and security monitoring.
- Translate complex technical findings into clear business implications and practical recommendations.
- Build advanced audit capabilities using data analytics, automation, and AI for risk assessment, audit scoping, testing, continuous monitoring, and reporting.
- Identify anomalies, control weaknesses, and emerging risks.
- Build relationships across the organization and support reporting to executive management, regulators, and the Board.
- Monitor developments in technology, threat activity, regulation, and industry practices.
- Coach colleagues and contribute to a culture of high standards, sound judgment, curiosity, ownership, and continuous learning.
Requirements
- 12–15+ years of relevant experience in cybersecurity, technology audit, technology risk, security engineering, data risk, cloud security, or a related field.
- Strong technical expertise across areas such as cloud platforms, identity and access management, application security, infrastructure, networks, vulnerability management, incident response, security operations, data platforms, or software development.
- Strong knowledge of data architecture, provenance, lineage, quality, governance, access, and analytics, including risks associated with using data in AI systems.
- Knowledge of AI and machine-learning risks, with experience using data analytics, scripting, automation, or AI-assisted techniques, or the ability to develop these capabilities quickly.
- Ability to understand complex systems, evaluate incomplete information, and reach well-supported conclusions.
- Strong communication and relationship-building skills, including the ability to explain technical issues to executives and collaborate with technology leaders, engineers, risk professionals, and senior management.
- Ability to operate in a fast-paced, evolving environment and help build a new team and capability.
- Bachelor’s degree in cybersecurity, computer science, information systems, engineering, data science, accounting, or a related discipline, or equivalent practical experience.
- Relevant certifications such as CISSP, CISA, CISM, CRISC, CCSP, cloud-provider certifications, or data and AI credentials are valued but not required.
Benefits
- Base salary of $342,000–$380,000 per year.
- Equity and performance-related bonuses for eligible employees.
- Medical, dental, and vision insurance, with employer contributions to Health Savings Accounts.
- Pre-tax accounts for healthcare, dependent care, commuter expenses, parking, and transit.
- 401(k) retirement plan with employer match.
- Paid parental, medical, and caregiver leave.
- Paid time off, paid company holidays, office closures, and sick or safe time.
- Mental health and wellness support.
- Employer-paid basic life and disability coverage.
- Annual learning and development stipend.
- Daily office meals and eligible meal delivery credits.
- Relocation support for eligible employees.
- Additional benefits may include charitable donation matching and wellness stipends.
More jobs at OpenAI
Software Engineer, AI Accelerator Runtime
OpenAI · San Francisco, United States
USD 266,000-445,000 per year
People Research Scientist
OpenAI · Mountain View, United States, San Francisco, United States
USD 198,000-220,000 per year
Systems Software Engineer, Silicon Bringup
OpenAI · San Francisco, United States
USD 266,000-445,000 per year
Software Engineer, Model Runtime
OpenAI · San Francisco, United States
USD 266,000-445,000 per year
Strategic Delivery Lead, Intelligence Community
OpenAI · Washington, United States
USD 266,000-370,000 per year
Similar jobs
Sr. Security Engineer - GRC Fintech & Financial Services
SpaceXAI · Washington, United States, New York City, United States, Palo Alto, United States
USD 152,000-258,000 per year
Security Controls Assurance Lead
Anthropic · Washington, United States, New York City, United States, San Francisco, United States
USD 270,000-345,000 per year
Senior Security Engineer - GRC Frameworks & AI Governance
SpaceXAI · Washington, United States, New York City, United States, Palo Alto, United States
USD 152,000-258,000 per year
IT Support Engineer, Application Administrator
Anthropic · New York City, United States, San Francisco, United States
USD 230,000-265,000 per year
Regional Asset Manager
Nebius · United States, Kansas City, United States
USD 147,200-183,900 per year
Physical Security Systems Technician - IT & Infrastructure
Nebius · United States, New York City, United States
USD 112,000-140,000 per year
Data Center Operations Lead - Partner Site Operations
Anthropic · San Francisco, United States
USD 320,000-405,000 per year
Technical Program Manager, Enterprise
OpenAI · San Francisco, United States
USD 257,000-445,000 per year