Product Manager, Codex Security Controls & Partner Interfaces

at OpenAI
USD 293,000-385,000 per year
MIDDLE
✅ Remote
✅ Relocation

Tech Stack

AI @ 3 API @ 3 Audit @ 3 CI/CD @ 3 Codex @ 3 OAuth @ 2 Security @ 3

Details

OpenAI’s Cyber team is building the security foundation for Codex, including native controls that govern what Codex can access and do, as well as interfaces that enable customers and security partners to inspect, constrain, approve, and respond to Codex activity. The goal is to make Codex secure by default, governable by enterprises, and interoperable with established security products.

This deeply technical Product Manager role focuses on securing Codex across identity, permissions, tools, MCP servers, repositories, secrets, networks, and high-impact actions. The role also defines standard interfaces that enable authorized customer and partner systems to provide security context, inspect activity, return policy decisions, receive telemetry, and initiate bounded responses. The role works closely with Codex product and engineering, OpenAI Security and Safety, enterprise customers, and partners across application security, identity, cloud security, data security, infrastructure, and security operations.

Responsibilities

Build Native Security Controls for Codex

  • Partner with engineering, design, security, and safety teams to develop controls for identity, roles, permissions, and tenant isolation.
  • Govern access to repositories, files, tools, MCP servers, secrets, networks, and infrastructure.
  • Define read, write, execute, and deployment authority.
  • Develop human and policy-based approval systems.
  • Address prompt injection and untrusted-content threats.
  • Establish audit trails, provenance, stop conditions, revocation, and rollback.
  • Help create a graduated authority model in which local, read-only, and reversible actions require less friction than actions involving production systems, credentials, sensitive data, or irreversible changes.

Define Partner Interfaces

  • Develop common, versioned interfaces that allow customer-selected security products to participate in Codex workflows.
  • Enable sharing of trusted identity, task, resource, and environment context.
  • Support inspection of code, commands, artifacts, tool calls, and planned actions.
  • Enable allow, deny, constrain, and require-approval decisions.
  • Export normalized execution and security telemetry.
  • Support pausing activity, revoking access, and requiring reauthorization.
  • Define requirements for authentication, authorization, customer consent, data minimization, latency, retries, failure behavior, auditability, and backward compatibility.
  • Ensure integrations use shared platform contracts instead of creating a separate Codex architecture for each partner.

Build the Partner Ecosystem

  • Work directly with security vendors and enterprise design partners to turn interfaces into production integrations.
  • Create partner SDKs, reference implementations, technical documentation, test environments, conformance suites, and certification requirements.
  • Prioritize partners based on customer value, technical relevance, deployment readiness, and their ability to improve the shared platform.
  • Convert lessons from individual partner engagements into reusable product capabilities.

Shape the Customer Experience

Define how enterprise administrators configure and understand Codex security controls, including:

  • Policies by user, workspace, repository, environment, tool, or action.
  • Approved security providers and permitted data sharing.
  • Approval requirements and time-limited exceptions.
  • Policy inheritance and conflict resolution.
  • Audit, investigation, and incident-response workflows.

Ensure developers receive clear and actionable explanations when an action is blocked or requires approval.

Establish Evaluation and Launch Gates

  • Work with security, safety, research, and engineering teams to test controls under realistic and adversarial conditions.
  • Evaluate permission bypass, prompt injection, malicious tools, secret exposure, cross-tenant access, stale authorization, partner outages, conflicting decisions, and incomplete audit evidence.
  • Help determine when new Codex capabilities have sufficient controls, reliability, and usability for broader deployment.

Requirements

You might thrive in this role if you:

  • Have built enterprise security, developer-platform, infrastructure, or control-plane products.
  • Understand identity, authorization, sandboxing, secrets, tool use, APIs, and audit systems.
  • Think in terms of trust boundaries, failure modes, and abuse paths.
  • Can balance security, developer productivity, latency, reliability, and customer control.
  • Have experience building integrations across complex enterprise systems or partner ecosystems.
  • Can turn conflicting partner requirements into a coherent platform.
  • Communicate credibly with developers, security architects, CISOs, researchers, and partner product teams.
  • Prefer measurable security outcomes and real adoption over demonstrations or integration announcements.

Nice to Have

  • Experience in application security, identity, cloud security, data security, source control, CI/CD, SIEM, or enterprise governance.
  • Familiarity with RBAC, ABAC, policy-as-code, OAuth, OIDC, workload identity, or secrets management.
  • Experience with AI agents, MCP, sandboxed execution, prompt-injection defenses, or agent-security evaluations.
  • Experience building SDKs, developer platforms, integration marketplaces, or certification programs.

Success Measures

During the first six months, success includes establishing:

  • A roadmap for native Codex controls and partner-extensible controls.
  • A common architecture for security context, policy decisions, inspection, telemetry, and response.
  • Initial reference integrations with a focused group of partners.
  • Evaluation and launch criteria for high-risk Codex capabilities.
  • Baseline measures for control coverage, bypass resistance, latency, reliability, and developer experience.

During the first year, success includes shipping meaningful controls across sensitive Codex workflows, bringing standardized partner interfaces into production, and demonstrating that enterprises can grant Codex greater authority without sacrificing visibility, control, or accountability.

Benefits

  • Medical, dental, and vision insurance with employer contributions to Health Savings Accounts.
  • Pre-tax accounts for health, dependent care, and commuter expenses.
  • 401(k) retirement plan with employer match.
  • Paid parental, medical, and caregiver leave.
  • Paid time off and 13+ paid company holidays.
  • Paid company office closures and paid sick or safe time as required by law.
  • Mental health and wellness support.
  • Employer-paid basic life and disability coverage.
  • Annual learning and development stipend.
  • Daily meals in offices and eligible meal delivery credits.
  • Relocation support for eligible employees.
  • Additional benefits may include charitable donation matching and wellness stipends.

OpenAI is an equal opportunity employer. Background checks and reasonable accommodations are handled in accordance with applicable laws.

More jobs at OpenAI

Similar jobs