Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AWS @ 3
Audit @ 7
Azure @ 3
Compliance @ 6
Kubernetes @ 3
Security @ 7
Terraform @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Governance, Risk, and Compliance (GRC) is foundational to Security delivering mission outcomes at OpenAI. The GRC team builds solutions for ambiguous security requirements and delivers technologies to mission-critical customers. The team provides security and engineering expertise to meet stringent customer requirements and is responsible for obtaining, expanding, and maintaining Authorizations to Operate (ATOs) for critical systems.
The role supports OpenAI products and agency-specific ATOs in highly regulated and secure environments, including US government compliance frameworks such as FedRAMP and Department of War requirements. You will work with engineers, internal stakeholders, and external assessors to design, document, and implement security controls.
Responsibilities
- Drive the ATO process for FedRAMP and multiple government clients in restricted environments with minimal oversight.
- Collaborate with engineering teams to interpret security requirements and implement controls that balance compliance with operational needs.
- Create clear, concise, and technically accurate documentation, including System Security Plans (SSPs), risk assessments, and architecture diagrams.
- Act as a subject matter expert during audits and assessments.
- Continuously improve the efficiency and quality of compliance processes.
- Communicate technical concepts to engineers and non-technical stakeholders.
- Manage large, complex technical programs and multitask effectively under pressure.
Requirements
- Proven experience obtaining and maintaining FedRAMP ATOs and agency-specific ATOs in highly restricted environments, within government or regulated sectors.
- Deep understanding of US government security frameworks and policies, including NIST, RMF, and FedRAMP.
- An active US security clearance.
- 5+ years of compliance experience involving information security, data security, infrastructure security, or network security.
- Familiarity with deployment models and cloud platforms, including Azure and AWS.
- Familiarity with infrastructure technologies including Kubernetes and Terraform.
- Strong knowledge of security concepts and technologies such as authentication, encryption, vulnerability management, and audit logging.
- Ability to work collaboratively and effectively in a cross-functional team environment.
- Ability to thrive in dynamic environments and navigate ambiguity.
Work Arrangement
This role is based in Washington, DC, and follows a hybrid work model requiring three days in the office per week.
Benefits
- Equity, performance-related bonuses for eligible employees, and comprehensive benefits.
- Medical, dental, and vision insurance, with employer contributions to Health Savings Accounts.
- Pre-tax accounts for health, dependent care, and commuter expenses.
- 401(k) retirement plan with employer match.
- Paid parental, medical, and caregiver leave.
- Paid time off, company holidays, and paid sick or safe time.
- Mental health and wellness support.
- Employer-paid basic life and disability coverage.
- Annual learning and development stipend.
- Daily office meals and eligible meal delivery credits.
- Relocation support for eligible employees.
- Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may be provided.