Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 6
Communication @ 6
Security @ 6
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
The Safety Systems team works to build and deploy safe AGI. Within Safety Systems, the Model Policy team aligns model behavior with desired human values and norms by developing policy taxonomies and evaluation criteria for foundational models' ability to reason about safety.
Frontier AI systems are expanding capabilities in cybersecurity and software engineering, creating defensive opportunities as well as dual-use and misuse risks involving malware development, exploit discovery, vulnerability chaining, credential abuse, cyber intrusion, and autonomous offensive operations. This role will help define how OpenAI's models should behave in high-risk cybersecurity contexts through policy frameworks, threat models, taxonomies, evaluations, and behavioral specifications across training, deployment, and monitoring systems.
The role sits at the intersection of cybersecurity, AI safety, threat modeling, evaluation science, and policy implementation. It involves close collaboration with research, engineering, safety training, preparedness, and product teams to build technically grounded, measurable, enforceable policies responsive to real-world cyber risk.
Responsibilities
- Design and maintain model policies for cybersecurity and frontier-risk domains, especially dual-use and high-risk cyber capabilities.
- Translate cybersecurity threat models into behavioral specifications, evaluation criteria, grading guidance, and system-level mitigations.
- Define practical boundaries between legitimate security research, defensive workflows, and assistance that could materially enable harmful activity.
- Build policy artifacts supporting implementation across training, evaluation, deployment, monitoring, and escalation systems.
- Partner with safety researchers, engineers, and evaluation teams to operationalize policies into scalable model behavior and measurable safeguards.
- Analyze red-teaming results, deployment data, model failures, over-refusals, and ambiguous edge cases to improve policy and evaluation quality.
- Identify emerging cyber capability areas where advanced AI systems could lower barriers to misuse or increase operational capability for malicious actors.
- Contribute to system cards, safety reports, policy documentation, and external communications on cyber risk mitigation.
Requirements
- Strong technical expertise in cybersecurity, such as offensive security, defensive security, vulnerability research, malware analysis, incident response, threat intelligence, application security, exploit development, infrastructure security, or cloud security.
- Strong judgment about how AI systems may affect the cyber threat landscape, including dual-use, autonomous, or agentic system risks.
- Ability to distinguish legitimate security use cases from assistance that could materially enable harmful cyber activity.
- Experience building or applying threat models to complex technical systems, especially in adversarial or high-risk environments.
- Ability to translate technical security expertise into structured policy frameworks, evaluation criteria, operational guidance, and enforcement mechanisms.
- Comfort using empirical evidence, including evaluations, red-teaming results, deployment observations, and model failure modes, to inform policy decisions.
- Strong systems thinking across policy, evaluations, classifiers, training, deployment safeguards, measurement, and monitoring.
- Ability to work cross-functionally with researchers, engineers, product teams, policy experts, and operational stakeholders.
- Strong written communication skills, especially the ability to explain complex technical and security concepts clearly.
- A pragmatic approach to safety focused on reducing real-world risk while preserving legitimate, beneficial, and defensive uses of AI.
Workplace And Location
This role is based in the San Francisco office. The position uses a hybrid model, with three days in the office per week and optional work from home on Thursdays and Fridays. OpenAI offers relocation support to new employees.
Benefits
- Medical, dental, and vision insurance, with employer contributions to Health Savings Accounts.
- Pre-tax accounts for health, dependent care, and commuter expenses.
- 401(k) retirement plan with employer match.
- Paid parental, medical, and caregiver leave.
- Paid time off, paid company holidays, office closures, and paid sick or safe time as required by law.
- Mental health and wellness support.
- Employer-paid basic life and disability coverage.
- Annual learning and development stipend.
- Daily office meals and eligible meal delivery credits.
- Relocation support for eligible employees.
- Equity, performance-related bonuses for eligible employees, charitable donation matching, and wellness stipends may also be provided.
OpenAI is an equal opportunity employer and provides reasonable accommodations to applicants with disabilities.