Security Engineer, Application Security
📍 New York City, United States
📍 San Francisco, United States
📍 Seattle, United States
Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI
Communication @ 6
Java @ 5
Leadership @ 3
OWASP @ 3
Python @ 5
Security @ 3
Software Development @ 6
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Security is at the foundation of OpenAI's mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI's technology, people, and products. The team is technical in what it builds, operational in how it works, and supports all products and research at OpenAI.
As a Security Engineer, Application Security, you will identify and mitigate security vulnerabilities within software applications by building security tools, conducting code reviews, performing penetration testing, and carrying out security assessments. You will work closely with development teams to integrate secure coding practices throughout the software development lifecycle and provide security guidance to technical and non-technical stakeholders.
The role is preferred to be based in San Francisco, Seattle, or New York City, but remote work may be considered. OpenAI uses a hybrid work model of three days in the office per week and offers relocation assistance to new employees.
Responsibilities
- Conduct security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software.
- Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats.
- Collaborate with development teams to integrate security best practices and secure coding guidelines throughout the software development lifecycle.
- Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies.
- Track, analyze, and manage application vulnerabilities, providing guidance and support for remediation efforts.
- Assist in investigating, analyzing, and responding to application-related security incidents, ensuring timely resolution and documentation.
- Stay current on security threats, vulnerabilities, technologies, and application security practices.
Requirements
- Extensive experience in information security, cybersecurity, or a related field, including significant experience in leadership or management roles.
- Deep understanding of security technologies, tools, and best practices, including secure coding, threat modeling, risk assessments, and incident response.
- Experience in application security, software development, or a related area, with a strong understanding of secure coding practices and application security frameworks.
- Proficiency in programming languages such as Python, Java, or C++.
- Knowledge of security tools such as Burp Suite and OWASP ZAP.
- Familiarity with security protocols and encryption methods.
- Strong written and verbal communication skills, with the ability to explain complex security issues to technical and non-technical audiences.
About OpenAI
OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. The company is committed to equal employment opportunity and providing reasonable accommodations to applicants with disabilities. Background checks are administered in accordance with applicable law.
Benefits
- Medical, dental, and vision insurance for employees and their families, with employer contributions to Health Savings Accounts.
- Pre-tax accounts for health, dependent care, and commuter expenses.
- 401(k) retirement plan with employer match.
- Paid parental, medical, and caregiver leave.
- Paid time off, paid company holidays, office closures, and paid sick and safe time.
- Mental health and wellness support.
- Employer-paid basic life and disability coverage.
- Annual learning and development stipend.
- Daily office meals and eligible meal delivery credits.
- Relocation support for eligible employees.
- Potential additional taxable fringe benefits, including charitable donation matching and wellness stipends.
- Compensation also includes equity and, for eligible employees, a performance-related bonus.