Offensive Security Engineer, Agent Products
at OpenAI
📍 United States
📍 Washington, United States
📍 New York City, United States
📍 San Francisco, United States
📍 Seattle, United States
📍 Washington, United States
📍 New York City, United States
📍 San Francisco, United States
📍 Seattle, United States
USD 347,000-490,000 per year
Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 4
API @ 4
Azure @ 4
CI/CD @ 4
Codex
Data Science @ 6
Design Patterns
GitHub @ 6
Kubernetes @ 6
Linux @ 6
Python @ 6
React @ 6
SRE
Security @ 7
macOS @ 6
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products, supporting all products and research at OpenAI.
The role focuses on hands-on penetration testing of OpenAI’s agent-powered products, infrastructure, and model-integrated application surfaces. You will assess complex systems end to end, identify vulnerabilities, validate exploitability and impact, and partner with engineering teams to drive durable fixes. The work will primarily involve continuously testing agent-powered products such as Codex and Operator, including the interactions between applications, infrastructure, tools, and models.
Responsibilities
- Conduct deep penetration tests of agent-powered products, including web applications, APIs, cloud services, identity and authorization flows, CI/CD systems, and model-integrated product surfaces.
- Hunt continuously for exploitable vulnerabilities in agentic product systems.
- Perform code reviews, architecture reviews, and hands-on exploitation to validate risk and identify subtle or novel failure modes.
- Produce clear, actionable findings with reproduction steps, exploitability analysis, impact assessments, and remediation guidance.
- Partner with engineering teams to drive fixes, validate remediation, and improve secure design patterns.
- Build tools, test harnesses, and automation to scale penetration testing across evolving product surfaces.
- Leverage advanced automation and OpenAI technologies to optimize offensive security work.
- Share attacker-informed insights with security and engineering teams to improve threat models, mitigations, and defensive coverage.
Requirements
- 7+ years of hands-on experience in penetration testing, product security assessment, application security, cloud security assessment, or equivalent offensive security disciplines.
- Deep expertise finding, exploiting, documenting, and helping remediate vulnerabilities in complex production systems.
- Experience assessing modern technology products, including web applications, APIs, cloud infrastructure, identity systems, CI/CD pipelines, and distributed services.
- Experience designing, developing, or assessing the security of AI-powered systems.
- Experience finding, exploiting, and mitigating AI system vulnerabilities, including prompt injection, confused deputies, unsafe tool use, and dynamically generated UI components.
- Exceptional code review skills for identifying novel and subtle vulnerabilities.
- Offensive security assessment experience in at least one hyperscaler cloud environment; Azure experience is preferred.
- Demonstrated mastery assessing complex technology stacks, including highly customized Kubernetes clusters, container environments, CI/CD pipelines, GitHub security, macOS and Linux operating systems, data science tooling and environments, Python-based web services, and React-based frontend applications.
- Strong understanding of trust boundaries and risk assessment in dynamic contexts.
- Excellent coding skills, including the ability to write robust tools and automation for offensive security testing.
- Ability to communicate complex technical concepts through clear reports, practical remediation guidance, and compelling technical storytelling.
- Proven track record of contributing to solutions in complex codebases, in addition to finding vulnerabilities.
Bonus Points
- Background or expertise in AI or data science.
- Experience working at technology startups or in fast-paced technology environments.
- Experience in software engineering, product security, application security, detection engineering, site reliability engineering, security engineering, or IT infrastructure.
Benefits
- Equity, performance-related bonuses for eligible employees, and comprehensive benefits.
- Medical, dental, and vision insurance, with employer contributions to Health Savings Accounts.
- Pre-tax Flexible Spending Accounts and commuter benefits.
- 401(k) retirement plan with employer match.
- Paid parental, medical, and caregiver leave.
- Paid time off, paid company holidays, and paid sick or safe time as required by applicable law.
- Mental health and wellness support.
- Employer-paid basic life and disability coverage.
- Annual learning and development stipend.
- Daily meals in offices and meal delivery credits as eligible.
- Relocation support for eligible employees.
- Additional benefits may include charitable donation matching and wellness stipends.
- OpenAI is an equal opportunity employer and provides reasonable accommodations to applicants with disabilities.
More jobs at OpenAI
Researcher, Frontier Risk Mitigations
OpenAI · San Francisco, United States
USD 295,000-445,000 per year
Tech Lead Manager, Education
OpenAI · San Francisco, United States
USD 325,000-405,000 per year
Support Program Manager, Partnerships
OpenAI · San Francisco, United States
USD 216,000-240,000 per year
Researcher, Recursive Self-Improvement Safety
OpenAI · San Francisco, United States
USD 295,000-445,000 per year
Manager, Cyber - AI Deployment Engineering
OpenAI · San Francisco, United States
USD 302,000-335,000 per year
Similar jobs
Member of Technical Staff (Offensive Security Engineer)
Perplexity AI · Serbia, New York City, United States, United States, San Francisco, United States, London, United Kingdom
USD 220,000-405,000 per year
Forward Deployed Engineer - Physical AI Cloud Platform
Nebius · United States, Austin, United States
USD 179,500-224,300 per year
Offensive Security Agent Engineer
OpenAI · Washington, United States, New York City, United States, Seattle, United States, United States, San Francisco, United States
USD 347,000-490,000 per year
Senior Infrastructure Software Engineer, TensorRT Edge-LLM
Nvidia · Santa Clara, United States
USD 184,000-287,500 per year
Staff Backend Software Engineer, Agent Platform
SentinelOne · United States
USD 156,000-215,000 per year
Senior Systems Software Engineer, Developer Productivity and Cloud Automation - GeForce NOW
Nvidia · Santa Clara, United States
USD 184,000-356,500 per year
Senior AI Engineer
Grafana Labs · United States
USD 154,400-185,300 per year
Senior Systems Software Engineer, Kubernetes Node Lifecycle - DGX Cloud
Nvidia · Santa Clara, United States
USD 184,000-356,500 per year