Skip to main content
OpenAI
OpenAI

Offensive Security Agent Engineer

RemoteUnited States only
Published
Role
Security
Experience
Principal
Employment
Full-time
$347k–$490k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Staff-to-principal offensive security expert who can build production-grade AI agent systems for continuous vulnerability discovery and remediation. Must be US-based remote and strong in offensive security judgment across cloud, Kubernetes, web apps, endpoints, and complex environments.

What you'll do

  • Serve as technical owner of OpenAI’s offensive security agents, establishing architecture, technical direction, operating model, and evaluation strategy.
  • Design and build specialized agents that continuously test OpenAI’s infrastructure and applications from authenticated and unauthenticated perspectives.
  • Translate expert offensive security workflows and intuition into tools, skills, harnesses, policies, and internal knowledge bases.
  • Build agents that deeply understand OpenAI’s environment by integrating internal context.
  • Develop capabilities for testing cloud and Kubernetes environments, modern web applications, external attack surface, endpoints, and other high-value systems.
  • Build vulnerability-management loops covering impact validation, ownership identification, prioritization, remediation support, progress tracking, and fix verification.
  • Design human-in-the-loop systems for offensive security engineers to approve or reject dangerous actions, provide context, redirect investigations, and steer agents.
  • Create feedback mechanisms that let agents learn from decisions, corrections, and domain expertise of offensive security practitioners.
  • Develop rigorous evaluations that measure security outcomes and improvements in agent capability over time.
  • Build production-quality infrastructure so the system runs continuously, recovers from failures, remains observable and debuggable, and operates safely against production systems.
  • Investigate failures in agent reasoning and behavior, identify model strengths and weaknesses, and improve tools, context, workflows, and guardrails.
  • Partner with offensive security, infrastructure security, product security, Codex security, and engineering teams to make findings high-signal, understandable, and actionable.
  • Help define the future of offensive security at OpenAI by enabling agents to perform repeatable security testing while human experts focus on automation and agent-assisted manual review.

What they require

  • Staff - Principal level offensive security domain expert.
  • Substantial hands-on offensive security experience and strong judgment about which vulnerabilities and attack paths are worth pursuing.
  • Extensive domain expertise in areas such as cloud security, Kubernetes and container security, web application security, source-code review, Linux security, macOS security, or external attack-surface testing.
  • Expertise in cloud, Kubernetes, and modern web applications is especially valuable.
  • Experience assessing complex, highly customized environments rather than relying primarily on standardized scanners, checklists, or known-vulnerability detection.
  • Ability to take an ambiguous offensive security problem, decompose it into a reliable system, and encode experienced-operator reasoning and workflows into software.
  • Experience building production-quality software.
  • Experience building or meaningfully extending agent systems that use models, tools, structured context, memory, orchestration, and feedback loops for complex work.
  • Strong concern for evaluations, observability, failure recovery, safety, maintainability, and regression resistance in production systems.
  • Strong intuitions about where current models are capable or unreliable and how tools, context, scaffolding, and human feedback can expand their useful operating range.
  • Excitement about working closely with frontier models and using them to improve workflows.
  • Energized by technical ownership of an ambitious new system, foundational architectural decisions, and helping grow a team around it.
  • Preferred: Background or expertise in AI or data science.
  • Preferred: Prior experience working in tech startups or fast-paced technology environments.
  • Preferred: Experience in related disciplines such as Software Engineering, Product Security, Application Security, Detection Engineering, Site Reliability Engineering, Security Engineering, or IT Infrastructure.

Benefits

  • Offers equity
  • Reasonable accommodations for applicants with disabilities

American artificial intelligence research organization

🇺🇸 United StatesAIEnterpriseopenai.com

What people say about this company

4.6/ 5

Details

Apply routeDom
$347k–$490k/yr