jobloom

JobLoom finds jobs directly from company career sites before many job boards, then routes you into detailed role pages like this one.

engineering

Posted 4 days ago

Offensive Security Agent Engineer

at openai

United StatesRemote

Responsibilities

  • - Design and build a portfolio of specialized agents that continuously test OpenAI’s infrastructure and applications from a variety of authenticated and unauthenticated perspectives.
  • - Build agents that deeply understand OpenAI’s environment by integrating internal context.
  • - Develop capabilities for testing cloud and Kubernetes environments, modern web applications, external attack surface, endpoints, and other high-value systems.
  • - Build complete vulnerability-management loops that move beyond discovery to impact validation, ownership identification, prioritization, remediation support, progress tracking, and fix verification.
  • - Design human-in-the-loop systems that allow offensive security engineers to approve or reject potentially dangerous actions, provide missing context, redirect investigations, and steer agents away from unproductive paths.
  • - Create feedback mechanisms that allow agents to learn from the decisions, corrections, and domain expertise of experienced offensive security practitioners.
  • - Develop rigorous evaluations that measure meaningful security outcomes and improvements in agent capability over time.
  • - Build production-quality infrastructure that allows the system to run continuously, recover from failures, remain observable and debuggable, and operate safely against production systems.

Requirements

  • ABOUT THE TEAM Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity.
  • As OpenAI increasingly uses automation throughout the company, we believe our security testing must become increasingly automated as well.
  • In this role, you’ll build a portfolio of specialized agents that develop a deep understanding of OpenAI’s infrastructure, applications, processes, and security boundaries.
  • These agents will combine internal context with feedback from running systems to explore our cloud environments, Kubernetes clusters, web applications, endpoints, external attack surface, and other high-value targets.
  • experience and strong judgment about which vulnerabilities and attack paths are worth pursuing. - You have extensive domain expertise in areas such as cloud security, Kubernetes and container security, web application security, source-code review, Linux security, macOS security, or external attack-surface testing.
  • Expertise in cloud, Kubernetes, and modern web applications is especially valuable. - You have
  • experience working in tech startups or fast-paced technology environments. -
  • Experience in related disciplines such as Software Engineering, Product Security, Application Security, Detection Engineering, Site Reliability Engineering, Security Engineering, or IT Infrastructure.
  • About OpenAI OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence

Benefits

  • BONUS POINTS: - Background or expertise in AI or data science. - Prior

Additional details

  • The Security team protects OpenAI’s technology, people, and products.
  • We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI.
  • Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.
  • ABOUT THE ROLE We’re seeking an exceptional Staff - Principal level offensive security domain expert to build agents that continuously identify and coordinate remediation of vulnerabilities across OpenAI’s infrastructure and applications.
  • You will be the technical owner of this effort, combining deep offensive security judgment with agent engineering to build a production system that can operate safely and reliably at scale.
  • Advances in model capabilities create an opportunity to test more of our attack surface than would be possible through human effort alone and a need to ensure that we remain ahead of those same capabilities as they become available to attackers.
  • The goal is for agents to not only discover vulnerabilities, but also to validate exploitability, document impact, drive remediation, and verify fixes.
  • Success will be measured through outcomes like vulnerabilities fixed, attack surface covered, and performance on evals you’ll build.
  • These systems will operate continuously and with increasing autonomy, while using carefully designed guardrails and human-in-the-loop controls for dangerous actions.
  • They will also learn from feedback from other domain experts throughout the company. IN THIS ROLE,

Find more real-time jobs on JobLoom.