Skip to main content
OpenAI
OpenAI

Product Manager, Codex Security Controls & Partner Interfaces

RemoteUnited States only
Published
Role
Product
Employment
Full-time
Company size
Enterprise
$293k–$385k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Deeply technical Product Manager for Codex security controls and partner interfaces. Needs enterprise security/developer-platform/infrastructure/control-plane product experience, strong understanding of identity, authorization, sandboxing, secrets, APIs, audit systems, and partner integrations. US-based remote role.

Required skills

APIs

Optional skills

RBACABACpolicy-as-codeOAuthOIDCworkload identitysecrets managementMCP

What you'll do

  • Build native security controls for Codex.
  • Partner with engineering, design, security, and safety teams to develop controls for identity, roles, permissions, and tenant isolation.
  • Partner with engineering, design, security, and safety teams to develop controls for access to repositories, files, tools, MCP servers, secrets, networks, and infrastructure.
  • Partner with engineering, design, security, and safety teams to develop controls for read, write, execute, and deployment authority.
  • Partner with engineering, design, security, and safety teams to develop controls for human and policy-based approvals.
  • Partner with engineering, design, security, and safety teams to develop controls for prompt-injection and untrusted-content defenses.
  • Partner with engineering, design, security, and safety teams to develop controls for audit trails, provenance, stop conditions, revocation, and rollback.
  • Help establish a graduated authority model in which local, read-only, and reversible actions require less friction than actions involving production systems, credentials, sensitive data, or irreversible changes.
  • Define common, versioned partner interfaces that allow customer-selected security products to participate in Codex workflows.
  • Define interfaces supporting sharing trusted identity, task, resource, and environment context.
  • Define interfaces supporting inspection of code, commands, artifacts, tool calls, or planned actions.
  • Define interfaces supporting allow, deny, constrain, or require-approval decisions.
  • Define interfaces supporting normalized execution and security telemetry export.
  • Define interfaces supporting pausing activity, revoking access, or requiring reauthorization.
  • Define clear requirements for authentication, authorization, customer consent, data minimization, latency, retries, failure behavior, auditability, and backwards compatibility.
  • Ensure integrations use shared platform contracts rather than creating a different Codex architecture for every partner.
  • Work directly with security vendors and enterprise design partners to turn interfaces into production integrations.
  • Create partner SDKs, reference implementations, technical documentation, test environments, conformance suites, and certification requirements.
  • Prioritize partners based on customer value, technical relevance, deployment readiness, and ability to improve the shared platform.
  • Turn lessons from individual partner engagements into reusable product capabilities.
  • Define how enterprise administrators configure and understand Codex security controls.
  • Define policies by user, workspace, repository, environment, tool, or action.
  • Define approved security providers and permitted data sharing.
  • Define approval requirements and time-limited exceptions.
  • Define policy inheritance and conflict resolution.
  • Define audit, investigation, and incident-response workflows.
  • Ensure developers receive clear, actionable explanations when an action is blocked or requires approval.
  • Work with security, safety, research, and engineering teams to test whether controls work under realistic and adversarial conditions.
  • Evaluate risks such as permission bypass, prompt injection, malicious tools, secret exposure, cross-tenant access, stale authorization, partner outages, conflicting decisions, and incomplete audit evidence.
  • Help determine when new Codex capabilities have sufficient controls, reliability, and usability for broader deployment.

What they require

  • Deeply technical Product Manager able to build Codex security controls and the partner ecosystem around them.
  • Experience building enterprise security, developer-platform, infrastructure, or control-plane products.
  • Understanding of identity, authorization, sandboxing, secrets, tool use, APIs, and audit systems.
  • Ability to think in terms of trust boundaries, failure modes, and abuse paths.
  • Ability to balance security, developer productivity, latency, reliability, and customer control.
  • Experience building integrations across complex enterprise systems or partner ecosystems.
  • Ability to turn conflicting partner requirements into a coherent platform.
  • Ability to communicate credibly with developers, security architects, CISOs, researchers, and partner product teams.
  • Preference for measurable security outcomes and real adoption over demonstrations or integration announcements.
  • Preferred: Experience in application security, identity, cloud security, data security, source control, CI/CD, SIEM, or enterprise governance.
  • Preferred: Familiarity with RBAC, ABAC, policy-as-code, OAuth, OIDC, workload identity, or secrets management.
  • Preferred: Experience with AI agents, MCP, sandboxed execution, prompt-injection defenses, or agent-security evaluations.
  • Preferred: Experience building SDKs, developer platforms, integration marketplaces, or certification programs.

Benefits

  • Reasonable accommodations for applicants with disabilities.
  • Opportunity to shape the future of technology.

American artificial intelligence research organization

🇺🇸 United StatesAIEnterpriseopenai.com

What people say about this company

4.6/ 5

Details

Apply routeDom
$293k–$385k/yr