Systems Software Engineer, Security, First-Party Hardware

at OpenAI
USD 230,000-385,000 per year
SENIOR
✅ Hybrid
✅ Relocation

Tech Stack

AI Communication @ 6 Networking @ 4 Rust @ 6 Security @ 7

Details

OpenAI’s Hardware organization develops AI-native silicon and system-level solutions for advanced AI workloads. The First-Party Hardware team is seeking a Security Engineer to own the end-to-end security foundation for first-party AI hardware systems across hardware security, embedded security, system security, and deployment at data center scale.

The role involves partnering with silicon, hardware, firmware, infrastructure, manufacturing, operations, and security teams to define and deliver system-level device trust. This includes boot integrity, device identity, provisioning, attestation, management-plane security, storage encryption, debug controls, firmware updates and recovery, RMA, and decommissioning. The engineer will turn threat models into requirements, implementations, and validation evidence supporting launch decisions.

Responsibilities

  • Own security requirements, threat models, validation strategy, and launch-readiness evidence for first-party hardware platforms from early design through production deployment.
  • Design and review secure boot, measured boot, roots of trust, platform firmware resilience, firmware signing, recovery, and anti-rollback strategies across heterogeneous devices.
  • Own device identity, provisioning, enrollment, attestation, certificate lifecycle, and key-management requirements across manufacturing and data center bring-up.
  • Harden management interfaces and operational access paths across BMCs, hosts, accelerators, switches, and service tooling, including TLS/mTLS, Redfish, gNMI, SSH, syslog, and break-glass workflows.
  • Drive security requirements for manufacturing, supply chain, firmware and image signing, storage encryption, RMA, repair, and decommissioning processes.
  • Build and drive validation for security-critical hardware and firmware behavior, including debug lockout, lifecycle transitions, update paths, attestation evidence, and recovery flows.
  • Partner with vendors and contract manufacturers to turn security requirements into concrete deliverables, test evidence, and launch gates.
  • Drive end-to-end closure across design, implementation, manufacturing readiness, deployment readiness, fleet operations, and incident response.
  • Investigate hardware and firmware security issues, assess exploitability and operational risk, and drive durable fixes with engineering owners.

Requirements

  • 7+ years of hands-on experience, or exceptional accomplishments demonstrating equivalent expertise, in hardware security, embedded security, firmware security, platform security, or low-level systems security.
  • Experience shipping or securing real hardware platforms, embedded devices, servers, accelerators, networking systems, BMCs, bootloaders, BIOS/UEFI, RTOS, kernels, or firmware update systems.
  • Deep familiarity with secure boot, measured boot, TPMs, hardware roots of trust, device attestation, key provisioning, debug interfaces, firmware signing, recovery, or lifecycle-state design.
  • Strong applied-cryptography judgment for secure boot, attestation, TLS/mTLS, key storage, certificate lifecycle, storage encryption, and long-range transitions such as post-quantum readiness.
  • Ability to read and write systems code in C, C++, or Rust and use that skill to review, prototype, test, or debug security-critical behavior.
  • Familiarity with hardware-software interfaces such as SPI, I2C, SMBus, PCIe, UART, JTAG, SWD, GPIOs, TPMs, and board-level debug tools.
  • Proven track record driving security improvements with hardware, firmware, infrastructure, manufacturing, operations, and partner teams.
  • Experience owning broad, ambiguous security programs end to end, including translating risk into technical requirements, validation plans, and accountable engineering decisions.
  • Clear written and verbal communication skills, with the ability to turn ambiguous security risks into actionable requirements, design reviews, tests, and decisions.
  • Candidates may need to meet certain legal status requirements under U.S. export control laws and regulations.

Benefits

  • Base salary range of $230,000–$385,000 per year.
  • Equity, performance-related bonuses for eligible employees, and comprehensive benefits.
  • Medical, dental, and vision insurance, with employer contributions to Health Savings Accounts.
  • Pre-tax accounts for health, dependent care, and commuter expenses.
  • 401(k) retirement plan with employer match.
  • Paid parental, medical, and caregiver leave.
  • Paid time off, company holidays, office closures, and paid sick or safe time.
  • Mental health and wellness support.
  • Employer-paid basic life and disability coverage.
  • Annual learning and development stipend.
  • Daily office meals and eligible meal delivery credits.
  • Relocation support for eligible employees.

Work Arrangement

San Francisco, California. Hybrid schedule with 3 days per week onsite.

More jobs at OpenAI

Similar jobs