engineering
Posted 4 days agoOffensive Security Agent Engineer
at openai
United StatesRemote
Responsibilities
- - Design and build a portfolio of specialized agents that continuously test OpenAI’s infrastructure and applications from a variety of authenticated and unauthenticated perspectives.
- - Build agents that deeply understand OpenAI’s environment by integrating internal context.
- - Develop capabilities for testing cloud and Kubernetes environments, modern web applications, external attack surface, endpoints, and other high-value systems.
- - Build complete vulnerability-management loops that move beyond discovery to impact validation, ownership identification, prioritization, remediation support, progress tracking, and fix verification.
- - Design human-in-the-loop systems that allow offensive security engineers to approve or reject potentially dangerous actions, provide missing context, redirect investigations, and steer agents away from unproductive paths.
- - Create feedback mechanisms that allow agents to learn from the decisions, corrections, and domain expertise of experienced offensive security practitioners.
- - Develop rigorous evaluations that measure meaningful security outcomes and improvements in agent capability over time.
- - Build production-quality infrastructure that allows the system to run continuously, recover from failures, remain observable and debuggable, and operate safely against production systems.
Requirements
- ABOUT THE TEAM Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity.
- As OpenAI increasingly uses automation throughout the company, we believe our security testing must become increasingly automated as well.
- In this role, you’ll build a portfolio of specialized agents that develop a deep understanding of OpenAI’s infrastructure, applications, processes, and security boundaries.
- These agents will combine internal context with feedback from running systems to explore our cloud environments, Kubernetes clusters, web applications, endpoints, external attack surface, and other high-value targets.
- experience and strong judgment about which vulnerabilities and attack paths are worth pursuing. - You have extensive domain expertise in areas such as cloud security, Kubernetes and container security, web application security, source-code review, Linux security, macOS security, or external attack-surface testing.
- Expertise in cloud, Kubernetes, and modern web applications is especially valuable. - You have
- experience working in tech startups or fast-paced technology environments. -
- Experience in related disciplines such as Software Engineering, Product Security, Application Security, Detection Engineering, Site Reliability Engineering, Security Engineering, or IT Infrastructure.
- About OpenAI OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence
Benefits
- BONUS POINTS: - Background or expertise in AI or data science. - Prior
Additional details
- The Security team protects OpenAI’s technology, people, and products.
- We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI.
- Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.
- ABOUT THE ROLE We’re seeking an exceptional Staff - Principal level offensive security domain expert to build agents that continuously identify and coordinate remediation of vulnerabilities across OpenAI’s infrastructure and applications.
- You will be the technical owner of this effort, combining deep offensive security judgment with agent engineering to build a production system that can operate safely and reliably at scale.
- Advances in model capabilities create an opportunity to test more of our attack surface than would be possible through human effort alone and a need to ensure that we remain ahead of those same capabilities as they become available to attackers.
- The goal is for agents to not only discover vulnerabilities, but also to validate exploitability, document impact, drive remediation, and verify fixes.
- Success will be measured through outcomes like vulnerabilities fixed, attack surface covered, and performance on evals you’ll build.
- These systems will operate continuously and with increasing autonomy, while using carefully designed guardrails and human-in-the-loop controls for dangerous actions.
- They will also learn from feedback from other domain experts throughout the company. IN THIS ROLE,