Security Engineer, Detection and Response
📍 New York City, United States
📍 San Francisco, United States
📍 Seattle, United States
Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 3
AWS @ 3
Azure @ 3
Communication @ 6
GCP @ 3
Kubernetes @ 3
Networking @ 3
Security @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products through technical systems and operational processes.
As a Security Engineer on Detection & Response, you will help protect OpenAI’s intellectual property, customer data, and supporting infrastructure by building and operating systems that detect suspicious activity and enable effective responses. You will work across endpoints, identity, cloud, hyperscale compute infrastructure, and datacenter-adjacent layers, partnering with security teams and infrastructure owners to define telemetry and response requirements and build tooling and automation.
Responsibilities
- Build and evolve Detection & Response capabilities across OpenAI’s infrastructure, products, and research environments, emphasizing high-signal detection and reliable operational response.
- Engineer detection pipelines and tooling, including rule lifecycle management, measurement and quality loops for coverage, precision, and latency, tuning processes, and safe rollout patterns.
- Automate response and investigations by building workflows for triage, enrichment, containment, and evidence capture to reduce toil and improve time-to-understand and time-to-contain.
- Partner with Security teams and system and infrastructure owners to ensure new systems launch with appropriate telemetry, threat models, and response playbooks.
- Define Detection & Response requirements and drive visibility across endpoints, identity, SaaS, cloud, and Kubernetes. Identify and prioritize telemetry and control gaps, advocate for fixes, and implement them directly when appropriate.
- Evaluate and respond to emerging security concerns in a frontier AI lab environment, including detection and response strategies for agents operating across infrastructure at scale.
Requirements
- Hands-on threat detection and/or incident response experience, including building detections, conducting investigations, and improving operational playbooks.
- Understanding of modern adversary tradecraft and the ability to translate tactics, techniques, and procedures into practical detection strategies and response actions.
- A threat-modeling mindset, including the ability to evaluate infrastructure and features, identify Detection & Response implications, and define concrete requirements.
- Experience working in Kubernetes and containerized environments, including building detections from cluster telemetry and understanding failure and attack modes involving workloads, nodes, control planes, and networking.
- Ability to reason about lower-level infrastructure and datacenter risks, including firmware and BMC surfaces, network segmentation and telemetry, and difficult-to-observe control paths.
- Experience across major cloud platforms, including Azure, AWS, GCP, and OCI, with the ability to design cloud-agnostic detection approaches where possible.
- Experience building automation to replace repetitive Detection & Response work, including the thoughtful use of agent-style workflows while keeping outcomes measurable, auditable, and safe.
- Interest in emerging security problems at a forward-looking technology company, including detecting and responding to agents operating across systems at scale.
- Clear communication and strong cross-functional collaboration skills, with the ability to translate Detection & Response needs into requirements and drive follow-through with technical and non-technical stakeholders.
- Scripting experience and an interest in using AI and agent tooling to accelerate investigations and automation.
About OpenAI
OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. OpenAI is an equal opportunity employer and does not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.
Background checks will be administered in accordance with applicable law. OpenAI is committed to providing reasonable accommodations to applicants with disabilities.