Security Engineer, Host Assurance

at OpenAI
USD 293,000-385,000 per year
MIDDLE
✅ Hybrid
✅ Relocation

Tech Stack

API @ 3 Debugging PKI @ 3 Security @ 3

Details

Security is foundational to OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Host Assurance team builds a dependable, scalable foundation for bare-metal infrastructure that is secure by default, verifiable in practice, and resilient across providers and operating models.

This is a hands-on engineering role focused on building and operating the security infrastructure that establishes trust in hardware platforms before they are eligible to run workloads. The role works across trust services, operating systems, hardware and firmware validation, and infrastructure security.

Responsibilities

  • Design, build, and operate components of the Host Assurance platform that establish trust in bare-metal hosts before production use.
  • Ensure hosts are verifiably trustworthy from delivery and installation through secure bootstrap and readiness to join orchestration systems.
  • Build and improve machine identity, certificate issuance and enrollment, HSM-backed or key-management-backed trust services, host attestation, measurement, and baseline verification tooling.
  • Validate delivered hardware and firmware against vendor claims and continuously detect and manage drift.
  • Eliminate insecure bootstrap patterns while preserving deployment throughput and operational reliability.
  • Partner with provisioning, fleet, and orchestration teams to create paved paths where secure approaches are the easiest approaches.
  • Contribute production code, reviews, operational improvements, and design guidance for foundational trust services operating at scale.
  • Define observable and testable security properties for host platforms and improve the telemetry and validation needed to enforce them.
  • Participate in incident response, debugging, and post-incident improvements for security-critical infrastructure.
  • Work across deployment models and provider boundaries while maintaining consistent host trust outcomes.

Requirements

  • Strong software engineering experience building and operating reliable production systems at scale.
  • Deep expertise in at least one relevant domain, such as PKI, HSMs, machine identity, applied cryptography, secure boot, firmware or hardware security, host attestation, or low-level platform security.
  • Comfort working across systems boundaries, from services and APIs to hosts, boot processes, firmware, and hardware-adjacent trust mechanisms.
  • Ability to write production-quality code and reason clearly about failure modes, operational safety, and long-term maintainability.
  • Experience replacing fragile or manual security mechanisms with durable, paved-path infrastructure.
  • A balance of technical rigor and pragmatism, with a focus on deployable security controls.
  • Self-directed, collaborative, and comfortable working across disciplines in ambiguous environments.

Workplace And Location

  • Preferably based in San Francisco, California, or Seattle, Washington.
  • Hybrid work model requiring three days in the office per week.
  • Relocation assistance is available to new employees.

Benefits

  • Equity, performance-related bonuses for eligible employees, and benefits including medical, dental, and vision insurance.
  • Employer contributions to Health Savings Accounts, pre-tax flexible spending and commuter accounts, and a 401(k) retirement plan with employer match.
  • Paid parental, medical, caregiver, and sick or safe leave.
  • Paid time off, company holidays, and coordinated office closures.
  • Mental health and wellness support, employer-paid basic life and disability coverage, and a learning and development stipend.
  • Daily office meals and eligible meal delivery credits.
  • Relocation support for eligible employees.
  • Additional taxable fringe benefits may include charitable donation matching and wellness stipends.

More jobs at OpenAI

Similar jobs