Principal Software Engineer, Infrastructure Security
📍 New York City, United States
📍 San Francisco, United States
📍 Seattle, United States
Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AWS @ 6
Azure @ 6
CI/CD
Communication @ 6
Distributed Systems @ 7
GCP @ 6
GPU
Kubernetes
Networking
Security @ 4
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products, supporting every product and research effort.
The Infrastructure Security team safeguards OpenAI’s research and production environments, including GPU supercomputing clusters, multi-cloud infrastructure, datacenters, networking, storage, Kubernetes clusters, service meshes, and data pathways carrying sensitive model weights and user data.
As a Principal Software Engineer, you will set technical direction and drive execution for foundational security services, such as authentication systems, egress and ingress proxies, access brokers, and key management platforms. These systems require high standards of reliability, scalability, and software craftsmanship under intense scale and adversarial pressure.
Responsibilities
- Own the architecture and roadmap for core security services, including authentication and authorization, policy enforcement, secure proxies, and key management, from design through rollout and long-term operation.
- Design and implement planet-scale security systems across hardware, operating systems, Kubernetes, networks, and CI/CD while balancing security, reliability, latency, and developer ergonomics.
- Lead cross-functional launches with infrastructure and research engineering teams, shaping interfaces, migration plans, and safe rollout strategies across large fleets and critical workflows.
- Build or evolve security primitives, including identity, attestation, authorization, encryption key lifecycle management, and access mediation.
- Use frontier models and agents to develop automation and detection tooling that continuously identifies and mitigates risks in large-scale cloud and on-premises environments.
- Lead design reviews and threat models for major initiatives and drive closure on systemic issues.
- Mentor engineers across Infrastructure Security and partner teams, raising standards for engineering quality, operational readiness, and secure-by-default practices.
Requirements
- Strong software engineering skills and a track record of shipping and operating reliable distributed systems in production.
- Experience building or operating critical infrastructure, especially security infrastructure, at planet scale, such as authentication services, service-to-service proxies, certificate systems, or key-management systems.
- Deep understanding of security principles, best practices, and common vulnerabilities.
- Demonstrated ability to lead cross-team technical initiatives by setting direction, aligning stakeholders, driving execution, and delivering measurable outcomes.
- Expertise and curiosity in using frontier models and agents to solve security challenges.
- Expertise securing large-scale cloud platforms such as Azure, AWS, and GCP, including multi-cloud networks and cloud-agnostic system design.
- Proactive approach to identifying and addressing security gaps or inefficiencies through automation and tooling.
- Strong analytical and problem-solving skills, with the ability to think critically and objectively assess risks.
- Excellent communication skills and the ability to convey complex security concepts to executive, technical, and non-technical stakeholders.
Benefits
- Base salary of $347,000–$490,000 per year, plus equity and performance-related bonus opportunities for eligible employees.
- Medical, dental, and vision insurance with employer contributions to Health Savings Accounts.
- Pre-tax Flexible Spending Accounts and commuter expense accounts.
- 401(k) retirement plan with employer match.
- Paid parental, medical, and caregiver leave.
- Paid time off, company holidays, office closures, and paid sick or safe time as required by applicable law.
- Mental health and wellness support.
- Employer-paid basic life and disability coverage.
- Annual learning and development stipend.
- Daily office meals and eligible meal delivery credits.
- Relocation support for eligible employees.
- Additional benefits may include charitable donation matching and wellness stipends.