Offensive Security Agent Engineer

at OpenAI
USD 347,000-490,000 per year
SENIOR
✅ Remote
✅ Relocation

Tech Stack

AI @ 6 Codex @ 4 Data Science @ 6 Kubernetes @ 6 Linux @ 6 Observability @ 7 SRE Security @ 4 macOS @ 6

Details

Security is at the foundation of OpenAI’s mission. The Security team protects OpenAI’s technology, people, and products while supporting its products and research.

The role is for a Staff–Principal-level offensive security domain expert who will build agents that continuously identify vulnerabilities and coordinate remediation across OpenAI’s infrastructure and applications. The technical owner will combine deep offensive security expertise with agent engineering to build a production system that operates safely and reliably at scale.

The agents will use internal context and feedback from running systems to explore cloud environments, Kubernetes clusters, web applications, endpoints, external attack surfaces, and other high-value targets. They will discover vulnerabilities, validate exploitability, document impact, drive remediation, and verify fixes. The systems will operate continuously with increasing autonomy, using guardrails and human-in-the-loop controls for dangerous actions.

Responsibilities

  • Serve as the technical owner for OpenAI’s offensive security agents, defining architecture, technical direction, operating model, and evaluation strategy.
  • Design and build specialized agents that continuously test infrastructure and applications from authenticated and unauthenticated perspectives.
  • Translate offensive security workflows and expert intuition into tools, skills, harnesses, policies, and internal knowledge bases.
  • Integrate internal context so agents deeply understand OpenAI’s environment.
  • Develop capabilities for testing cloud and Kubernetes environments, modern web applications, external attack surfaces, endpoints, and other high-value systems.
  • Build vulnerability-management loops covering discovery, exploitability validation, impact assessment, ownership identification, prioritization, remediation support, progress tracking, and fix verification.
  • Design human-in-the-loop systems that allow offensive security engineers to approve or reject potentially dangerous actions, provide context, redirect investigations, and guide agents away from unproductive paths.
  • Create feedback mechanisms that allow agents to learn from decisions, corrections, and domain expertise from experienced offensive security practitioners.
  • Develop rigorous evaluations measuring meaningful security outcomes and improvements in agent capability.
  • Build production-quality infrastructure that runs continuously, recovers from failures, remains observable and debuggable, and operates safely against production systems.
  • Investigate agent reasoning and behavior failures and improve tools, context, workflows, and guardrails.
  • Partner with offensive security, infrastructure security, product security, Codex security, and engineering teams to ensure findings are high-signal, understandable, and actionable.
  • Help define the future of offensive security at OpenAI by enabling agents to perform repeatable security testing while human experts focus on automation and high-leverage agent-assisted manual review.

Requirements

  • Substantial hands-on offensive security experience and strong judgment about which vulnerabilities and attack paths are worth pursuing.
  • Extensive expertise in areas such as cloud security, Kubernetes and container security, web application security, source-code review, Linux security, macOS security, or external attack-surface testing. Cloud, Kubernetes, and modern web application expertise are especially valuable.
  • Experience assessing complex, highly customized environments rather than relying primarily on standardized scanners, checklists, or known-vulnerability detection.
  • Ability to decompose ambiguous offensive security problems into reliable systems and encode experienced-operator reasoning and workflows into software.
  • Experience building production-quality software.
  • Experience building or meaningfully extending agent systems using models, tools, structured context, memory, orchestration, and feedback loops.
  • Strong understanding of production agent requirements, including evaluations, observability, failure recovery, safety, maintainability, and regression resistance.
  • Strong intuition about model capabilities and limitations and how tools, context, scaffolding, and human feedback can extend their useful operating range.
  • Interest in working with frontier models and using them to improve security workflows.
  • Ability to serve as the technical owner of an ambitious new system, make foundational architectural decisions, and help grow a team.

Bonus Qualifications

  • Background or expertise in AI or data science.
  • Experience working in technology startups or fast-paced technology environments.
  • Experience in software engineering, product security, application security, detection engineering, site reliability engineering, security engineering, or IT infrastructure.

Benefits

  • Base salary of $347,000–$490,000 per year, plus equity.
  • Medical, dental, and vision insurance, with employer contributions to Health Savings Accounts.
  • Pre-tax FSA, dependent-care FSA, and commuter accounts.
  • 401(k) retirement plan with employer match.
  • Paid parental, medical, and caregiver leave.
  • Paid time off, company holidays, office closures, and sick or safe time.
  • Mental health and wellness support.
  • Employer-paid basic life and disability coverage.
  • Annual learning and development stipend.
  • Daily office meals and eligible meal delivery credits.
  • Relocation support for eligible employees.
  • Additional benefits may include charitable donation matching and wellness stipends.

More jobs at OpenAI

Similar jobs