security
Posted Oct 28, 2025Offensive Security Engineer, Agent Products
at openai
United StatesRemote
Responsibilities
- You’ll have the chance to not only find vulnerabilities, but actively drive their resolution, build reusable testing approaches, automate offensive security workflows with cutting-edge technologies, and use your attacker perspective to improve the security of OpenAI’s products. IN THIS ROLE
- - Perform code review, architecture review, and hands-on exploitation to validate risk and identify subtle or novel failure modes.
- - Build tools, test harnesses, and automation to scale penetration testing across rapidly evolving product surfaces.
Requirements
- ABOUT THE TEAM Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity.
- Experience performing offensive security assessments of modern technology products, including web applications, APIs, cloud infrastructure, identity systems, CI/CD pipelines, and distributed services. -
- Experience designing, developing, or assessing the security of AI-powered systems. -
- Experience finding, exploiting, and mitigating common vulnerabilities in AI systems, including prompt injection, confused deputies, unsafe tool use, and dynamically generated UI components. - Exceptional skill in code review to identify novel and subtle vulnerabilities. - Proven
- experience performing offensive security assessments in at least one hyperscaler cloud environment. Azure experience is preferred.
- - Demonstrated mastery assessing complex technology stacks, including: - Highly customized Kubernetes clusters - Container environments - CI/CD pipelines - GitHub security - macOS and Linux operating systems - Data science tooling and environments - Python-based web services - React-based frontend applications - Strong intuitive understanding of trust boundaries and risk assessment in dynamic contexts.
- - Ability to communicate complex technical concepts effectively through clear reports, practical remediation guidance, and compelling technical storytelling.
- experience working in tech startups or fast-paced technology environments. -
- Experience in related disciplines such as Software Engineering, Product Security, Application Security, Detection Engineering, Site Reliability Engineering, Security Engineering, or IT Infrastructure.
- About OpenAI OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence
Experience
- YOU MIGHT THRIVE IN THIS ROLE IF YOU HAVE: - 7+ years of hands-on penetration testing, product security assessment, application security, cloud security assessment, or equivalent offensive security experience. - Deep expertise finding, exploiting, documenting, and helping remediate vulnerabilities in complex production systems. -
Benefits
- BONUS POINTS: - Background or expertise in AI or data science. - Prior
Additional details
- The Security team protects OpenAI’s technology, people, and products.
- We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI.
- Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.
- ABOUT THE ROLE We’re seeking an exceptional Principal-level Offensive Security Engineer focused on deep, hands-on penetration testing of OpenAI’s agent-powered products, infrastructure, and model-integrated application surfaces.
- You’ll assess complex systems end to end, identify realistic vulnerabilities, validate exploitability and impact, and partner closely with engineering teams to drive durable fixes.
- This role will be primarily focused on continuously testing our agent-powered products like Codex and Operator.
- These systems are uniquely valuable targets because they’re rapidly evolving, can perform sensitive actions on behalf of users, and have large, diverse attack surfaces.
- You will play a crucial role in securing our agents by finding vulnerabilities that emerge from the interactions between the applications, infrastructure, tools, and models that power them.
- YOU WILL: - Conduct deep penetration tests of OpenAI’s agent-powered products, including web applications, APIs, cloud services, identity and authorization flows, CI/CD systems, and model-integrated product surfaces.
- - Continuously hunt for exploitable vulnerabilities in the interactions between the applications, infrastructure, tools, and models that power our agentic products.