Offensive Security Engineer, Agent Products
📍 Washington, United States
📍 New York City, United States
📍 San Francisco, United States
📍 Seattle, United States
Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 4
API @ 4
Azure @ 4
CI/CD @ 4
Codex
Data Science @ 6
Design Patterns
GitHub @ 6
Kubernetes @ 6
Linux @ 6
Python @ 6
React @ 6
SRE
Security @ 9
macOS @ 6
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
About the Team
Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. They are technical in what they build but operational in how they do their work, and are committed to supporting all products and research at OpenAI.
Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.
About the Role
OpenAI is seeking an exceptional Principal-level Offensive Security Engineer focused on deep, hands-on penetration testing of OpenAI’s agent-powered products, infrastructure, and model-integrated application surfaces. The role assesses complex systems end to end, identifies realistic vulnerabilities, validates exploitability and impact, and partners closely with engineering teams to drive durable fixes.
The role is primarily focused on continuously testing agent-powered products like Codex and Operator. These systems are uniquely valuable targets because they’re rapidly evolving, can perform sensitive actions on behalf of users, and have large, diverse attack surfaces. The role secures agents by finding vulnerabilities that emerge from the interactions between the applications, infrastructure, tools, and models that power them.
You will not only find vulnerabilities, but actively drive their resolution, build reusable testing approaches, automate offensive security workflows with cutting-edge technologies, and use your attacker perspective to improve the security of OpenAI’s products.
Responsibilities
- Conduct deep penetration tests of OpenAI’s agent-powered products, including web applications, APIs, cloud services, identity and authorization flows, CI/CD systems, and model-integrated product surfaces.
- Continuously hunt for exploitable vulnerabilities in the interactions between the applications, infrastructure, tools, and models that power agentic products.
- Perform code review, architecture review, and hands-on exploitation to validate risk and identify subtle or novel failure modes.
- Produce clear, actionable findings with reproduction steps, exploitability analysis, impact assessment, and practical remediation guidance.
- Partner directly with engineering teams to drive fixes, validate remediation, and improve secure design patterns across agentic products.
- Build tools, test harnesses, and automation to scale penetration testing across rapidly evolving product surfaces.
- Leverage advanced automation and OpenAI technologies to optimize offensive security work.
- Share attacker-informed insights with security and engineering teams to improve threat models, mitigations, and defensive coverage.
Requirements
- 7+ years of hands-on penetration testing, product security assessment, application security, cloud security assessment, or equivalent offensive security experience.
- Deep expertise finding, exploiting, documenting, and helping remediate vulnerabilities in complex production systems.
- Experience performing offensive security assessments of modern technology products, including web applications, APIs, cloud infrastructure, identity systems, CI/CD pipelines, and distributed services.
- Experience designing, developing, or assessing the security of AI-powered systems.
- Experience finding, exploiting, and mitigating common vulnerabilities in AI systems, including:
- prompt injection
- confused deputies
- unsafe tool use
- dynamically generated UI components
- Exceptional skill in code review to identify novel and subtle vulnerabilities.
- Proven experience performing offensive security assessments in at least one hyperscaler cloud environment; Azure experience is preferred.
- Demonstrated mastery assessing complex technology stacks, including:
- Highly customized Kubernetes clusters
- Container environments
- CI/CD pipelines
- GitHub security
- macOS and Linux operating systems
- Data science tooling and environments
- Python-based web services
- React-based frontend applications
- Strong intuitive understanding of trust boundaries and risk assessment in dynamic contexts.
- Excellent coding skills, capable of writing robust tools and automation for offensive security testing.
- Ability to communicate complex technical concepts effectively through clear reports, practical remediation guidance, and compelling technical storytelling.
- Proven track record of not just finding vulnerabilities, but actively contributing to solutions in complex codebases.
Bonus points
- Background or expertise in AI or data science.
- Prior experience working in tech startups or fast-paced technology environments.
- Experience in related disciplines such as Software Engineering, Product Security, Application Security, Detection Engineering, Site Reliability Engineering, Security Engineering, or IT Infrastructure.
About OpenAI
OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. OpenAI pushes the boundaries of the capabilities of AI systems and seeks to safely deploy them to the world through its products.
OpenAI is an equal opportunity employer.
Background checks for applicants will be administered in accordance with applicable law.
OpenAI also notes availability of reasonable accommodations for applicants with disabilities via the provided link.