Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Communication @ 6
Java @ 5
Leadership @ 3
OWASP @ 3
Python @ 5
Security @ 3
Software Development @ 6
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. The team is technical in what it builds and operational in how it works, supporting all products and research at OpenAI.
As a Security Engineer, Application Security, you will identify and mitigate security vulnerabilities within software applications by building security tools, conducting code reviews, performing penetration testing, and carrying out security assessments. You will work closely with development teams to integrate secure coding practices throughout the software development lifecycle and provide security guidance to technical and non-technical stakeholders.
The role is preferred to be based in San Francisco, Seattle, or New York City, but remote work may be considered. OpenAI uses a hybrid work model with three days in the office per week.
Responsibilities
- Conduct security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software.
- Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats.
- Collaborate with development teams to integrate security best practices and secure coding guidelines throughout the software development lifecycle.
- Conduct threat modeling and risk assessments to identify potential risks and develop mitigation strategies.
- Track, analyze, and manage application vulnerabilities, providing guidance and support for remediation efforts.
- Assist with investigating, analyzing, and responding to application-related security incidents, ensuring timely resolution and documentation.
- Stay current on security threats, vulnerabilities, technologies, and application security practices.
Requirements
- Extensive experience in information security, cybersecurity, or a related field, including significant experience in leadership or management roles.
- Deep understanding of security technologies, tools, and best practices, including secure coding, threat modeling, risk assessments, and incident response.
- Experience in application security, software development, or related areas, with a strong understanding of secure coding practices and application security frameworks.
- Proficiency in programming languages such as Python, Java, or C++.
- Knowledge of security tools such as Burp Suite and OWASP ZAP.
- Familiarity with security protocols and encryption methods.
- Strong written and verbal communication skills, with the ability to explain complex security issues to technical and non-technical audiences.
Benefits
- Equity, performance-related bonus for eligible employees, and benefits in addition to base salary.
- Medical, dental, and vision insurance, with employer contributions to Health Savings Accounts.
- Pre-tax accounts for health, dependent care, and commuter expenses.
- 401(k) retirement plan with employer match.
- Paid parental, medical, and caregiver leave.
- Paid time off, company holidays, and paid sick and safe time.
- Mental health and wellness support.
- Employer-paid basic life and disability coverage.
- Annual learning and development stipend.
- Daily meals in offices and eligible meal delivery credits.
- Relocation support for eligible employees.
- Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may be provided.