Offensive Security Engineer, Agent Products

at OpenAI
USD 347,000-490,000 per year
SENIOR
✅ Remote
✅ Relocation

Tech Stack

AI @ 4 API @ 4 Azure @ 4 CI/CD @ 4 Codex Data Science @ 6 Design Patterns GitHub @ 6 Kubernetes @ 6 Linux @ 6 Python @ 6 React @ 6 SRE Security @ 7 macOS @ 6

Details

Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products, supporting all products and research at OpenAI.

The role focuses on hands-on penetration testing of OpenAI’s agent-powered products, infrastructure, and model-integrated application surfaces. You will assess complex systems end to end, identify vulnerabilities, validate exploitability and impact, and partner with engineering teams to drive durable fixes. The work will primarily involve continuously testing agent-powered products such as Codex and Operator, including the interactions between applications, infrastructure, tools, and models.

Responsibilities

  • Conduct deep penetration tests of agent-powered products, including web applications, APIs, cloud services, identity and authorization flows, CI/CD systems, and model-integrated product surfaces.
  • Hunt continuously for exploitable vulnerabilities in agentic product systems.
  • Perform code reviews, architecture reviews, and hands-on exploitation to validate risk and identify subtle or novel failure modes.
  • Produce clear, actionable findings with reproduction steps, exploitability analysis, impact assessments, and remediation guidance.
  • Partner with engineering teams to drive fixes, validate remediation, and improve secure design patterns.
  • Build tools, test harnesses, and automation to scale penetration testing across evolving product surfaces.
  • Leverage advanced automation and OpenAI technologies to optimize offensive security work.
  • Share attacker-informed insights with security and engineering teams to improve threat models, mitigations, and defensive coverage.

Requirements

  • 7+ years of hands-on experience in penetration testing, product security assessment, application security, cloud security assessment, or equivalent offensive security disciplines.
  • Deep expertise finding, exploiting, documenting, and helping remediate vulnerabilities in complex production systems.
  • Experience assessing modern technology products, including web applications, APIs, cloud infrastructure, identity systems, CI/CD pipelines, and distributed services.
  • Experience designing, developing, or assessing the security of AI-powered systems.
  • Experience finding, exploiting, and mitigating AI system vulnerabilities, including prompt injection, confused deputies, unsafe tool use, and dynamically generated UI components.
  • Exceptional code review skills for identifying novel and subtle vulnerabilities.
  • Offensive security assessment experience in at least one hyperscaler cloud environment; Azure experience is preferred.
  • Demonstrated mastery assessing complex technology stacks, including highly customized Kubernetes clusters, container environments, CI/CD pipelines, GitHub security, macOS and Linux operating systems, data science tooling and environments, Python-based web services, and React-based frontend applications.
  • Strong understanding of trust boundaries and risk assessment in dynamic contexts.
  • Excellent coding skills, including the ability to write robust tools and automation for offensive security testing.
  • Ability to communicate complex technical concepts through clear reports, practical remediation guidance, and compelling technical storytelling.
  • Proven track record of contributing to solutions in complex codebases, in addition to finding vulnerabilities.

Bonus Points

  • Background or expertise in AI or data science.
  • Experience working at technology startups or in fast-paced technology environments.
  • Experience in software engineering, product security, application security, detection engineering, site reliability engineering, security engineering, or IT infrastructure.

Benefits

  • Equity, performance-related bonuses for eligible employees, and comprehensive benefits.
  • Medical, dental, and vision insurance, with employer contributions to Health Savings Accounts.
  • Pre-tax Flexible Spending Accounts and commuter benefits.
  • 401(k) retirement plan with employer match.
  • Paid parental, medical, and caregiver leave.
  • Paid time off, paid company holidays, and paid sick or safe time as required by applicable law.
  • Mental health and wellness support.
  • Employer-paid basic life and disability coverage.
  • Annual learning and development stipend.
  • Daily meals in offices and meal delivery credits as eligible.
  • Relocation support for eligible employees.
  • Additional benefits may include charitable donation matching and wellness stipends.
  • OpenAI is an equal opportunity employer and provides reasonable accommodations to applicants with disabilities.

More jobs at OpenAI

Similar jobs