Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 3
API @ 3
Codex @ 3
Communication @ 6
Security @ 5
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
OpenAI's Vendor Security team helps internal teams work securely with external products, services, and partners. Its work spans software, infrastructure, hardware, professional and managed services, vendor-provided workforces, data, and research. The team builds programs and products that help teams understand vendor risk and implement effective safeguards.
The role is an individual-contributor position responsible for making sound security decisions, turning recurring vendor-security problems into effective tools and practices, and leading vendor-security engagements from business need through verified safeguards.
Responsibilities
- Own vendor security engagements through scoping, assessment, decision, treatment, and reassessment when material facts change.
- Independently make assessment decisions, determine when to involve peers, specialists, or leadership, and route formal exceptions and risk acceptance to the appropriate decision owners.
- Understand vendor use cases, workflows, user journeys, data flows, identities, access, integrations, and supply-chain dependencies.
- Identify plausible attack paths and their consequences for OpenAI.
- Assess architectures, configurations, controls, logs, and operational practices, and test whether evidence supports relevant security claims.
- Develop practical treatments involving operating models, data exposure, access, architecture, vendor choice, controls, or containment.
- Drive implementation with responsible owners and verify that treatments work.
- Build reusable security patterns with clear applicability, safeguards, evidence requirements, exceptions, and review triggers.
- Work with Legal, Procurement, and vendors on security addenda. Evaluate proposed terms and deviations, explain their security implications, and develop workable positions with the appropriate decision owners. Legal leads wording and negotiation.
- Define requirements, roadmaps, and success measures for bounded programs, products, and services.
- Use Codex or comparable AI-assisted tools to build, inspect, test, and maintain improvements to scoping, evidence checks, routing, decision reuse, and treatment tracking.
- Investigate failures and own results through adoption, continued operation, and explicit handoff or retirement.
- Lead delivery across Security and partner teams by translating goals into technical requirements, milestones, and delivery plans; influencing implementation choices; identifying systemic risks; resolving dependencies and disagreements; and completing commitments.
- Use casework, incidents, threat information, and customer feedback to improve decisions and the program.
Requirements
- Experience independently assessing consequential third-party, supply-chain, or comparable security risks and applying judgment to unfamiliar vendor technologies and operating models.
- Understanding of security principles and controls, including data protection, access management, application security, prevention, detection, and response.
- Ability to reason about architecture, identity, APIs, data flows, logging, integrations, and control effectiveness.
- Knowledge of relevant frameworks and standards, including ISO 27001, NIST 800-53, and SOC 2.
- Experience translating security findings and requirements into practical contractual positions with Legal, Procurement, and vendor representatives.
- Experience delivering useful products or workflow improvements, testing expected behavior and failure cases, learning from users, and owning performance after launch.
- Ability to use Codex or comparable AI-assisted development tools to build, run, inspect, and test working solutions.
- Experience independently delivering cross-functional programs, converting ambiguity into technical requirements and plans, and adapting priorities to achieve measurable outcomes.
- Ability to determine when to build, use existing systems, or engage partners to resolve blockers.
- Ability to build constructive relationships with Security, Engineering, Product, Privacy, Legal, business teams, and vendors.
- Strong written and verbal communication skills, including the ability to explain recommendations, supporting evidence, and relevant tradeoffs.
- Willingness to question assumptions, investigate unfamiliar systems, try thoughtful new approaches, and revise judgment when new evidence changes the situation.
Benefits
- Equity, performance-related bonuses for eligible employees, and benefits including medical, dental, and vision insurance.
- Employer contributions to Health Savings Accounts, pre-tax FSA and commuter accounts, and a 401(k) plan with employer match.
- Paid parental, medical, and caregiver leave.
- Paid time off, company holidays, office closures, and paid sick or safe time as required by applicable law.
- Mental health and wellness support.
- Employer-paid basic life and disability coverage.
- Annual learning and development stipend.
- Daily meals in offices and meal delivery credits as eligible.
- Relocation support for eligible employees.
- Additional taxable fringe benefits may be provided.
- OpenAI is an equal opportunity employer and provides reasonable accommodations to applicants with disabilities.
More jobs at OpenAI
Technical Program Manager, Robotics
OpenAI · San Francisco, United States
USD 207,000-285,000 per year
Software Engineer, Enterprise Controls
OpenAI · San Francisco, United States
USD 230,000-385,000 per year
Software Engineer, OpenAI Presence
OpenAI · San Francisco, United States
USD 230,000-385,000 per year
People Technology Analyst, Workday PATT & Benefits
OpenAI · United States
USD 187,000-280,000 per year
ITAV Event Technical Producer
OpenAI · San Francisco, United States
USD 240,000-266,000 per year
Similar jobs
Forward Deployed Engineer - Physical AI Cloud Platform
Nebius · United States, Austin, United States
USD 179,500-224,300 per year
Product Manager, Enterprise Identity
OpenAI · San Francisco, United States
USD 347,000-490,000 per year
AI Support Engineer, Government - San Francisco, CA
OpenAI · San Francisco, United States
USD 180,000-260,000 per year
AI Support Engineer, Government - Washington, D.C.
OpenAI · Washington, United States
USD 162,000-234,000 per year
Applied AI Architect, Government
OpenAI · Washington, United States
USD 234,000-335,000 per year
Design Program Manager, Research Operations
Stripe · United States
USD 137,100-205,700 per year
Technical Program Manager, Enterprise
OpenAI · San Francisco, United States
USD 257,000-445,000 per year
AI Support Engineer, Biosciences - San Francisco
OpenAI · San Francisco, United States
USD 180,000-260,000 per year