About the Role
We are seeking a Staff to Principal level offensive security expert to develop agents that continuously identify and coordinate remediation of vulnerabilities across infrastructure and applications. You will serve as the technical owner, combining deep security judgment with agent engineering to create a production system that operates safely and reliably at scale, with increasing automation to match company-wide trends and advancements in AI capabilities.
Responsibilities
- Act as the technical lead for offensive security agents, defining architecture, technical direction, operational model, and evaluation approach
- Create a range of specialized agents to continuously test infrastructure and applications from both authenticated and unauthenticated viewpoints
- Convert expert offensive security processes and insights into tools, skills, harnesses, policies, and internal knowledge repositories
- Develop agents that integrate internal context to gain a deep understanding of the environment
- Engineer capabilities for testing cloud and Kubernetes setups, modern web applications, external attack surfaces, endpoints, and other critical systems
- Establish full vulnerability management cycles that include discovery, impact validation, ownership identification, prioritization, remediation support, progress tracking, and fix verification
- Design systems with human oversight to allow security engineers to approve or reject risky actions, provide context, redirect investigations, and guide agents away from ineffective paths
- Implement feedback systems enabling agents to learn from decisions, corrections, and expertise of experienced security practitioners
- Develop thorough evaluations to measure security outcomes and track improvements in agent capabilities over time
- Build robust production infrastructure for continuous operation, failure recovery, observability, debuggability, and safe interaction with production systems
- Analyze agent reasoning and behavior failures, identify model capabilities and limitations, and enhance tools, context, workflows, and safeguards accordingly
- Collaborate closely with offensive security, infrastructure security, product security, codex security, and engineering teams to ensure findings are high-value, clear, and actionable
- Contribute to defining the future of offensive security by enabling agents to handle repetitive testing while human experts focus on automation and high-impact agent-assisted reviews
Requirements
- Significant hands-on offensive security experience with strong judgment on which vulnerabilities and attack paths to prioritize
- Deep expertise in areas such as cloud security, Kubernetes and container security, web application security, source-code review, Linux security, macOS security, or external attack-surface testing
- Experience evaluating complex, customized environments without relying mainly on standard scanners, checklists, or known-vulnerability detection
- Ability to tackle ambiguous offensive security challenges, break them down into reliable systems, and encode expert reasoning and workflows into software
- Experience building production-quality software
- Experience developing or significantly extending agent systems that utilize models, tools, structured context, memory, orchestration, and feedback loops for complex tasks
- Understanding that impressive agent demos differ from dependable production systems, with a focus on evaluations, observability, failure recovery, safety, maintainability, and regression resistance
- Strong intuition about current model capabilities and limitations, and how tools, context, scaffolding, and human feedback can extend their operational range
- Enthusiasm for working with cutting-edge models, curiosity about emerging capabilities, and constant pursuit of ways to enhance personal workflows using them
- Motivation to serve as technical owner of an ambitious new system, make foundational architectural decisions, and help build a team around it
Nice to Have
- Background or expertise in AI or data science
- Prior experience in tech startups or fast-paced technology environments
- Experience in related fields such as Software Engineering, Product Security, Application Security, Detection Engineering, Site Reliability Engineering, Security Engineering, or IT Infrastructure
About the Team
Security is fundamental to the mission of ensuring artificial general intelligence benefits all of humanity. The team protects technology, people, and products, building technical solutions with an operational approach, and supports all products and research. Tenets include prioritizing impact, enabling researchers, preparing for future transformative technologies, and fostering a robust security culture.
About OpenAI
We are an AI research and deployment company focused on ensuring general-purpose artificial intelligence benefits everyone. We advance AI capabilities and safely deploy them through products, prioritizing safety and human needs, and valuing diverse perspectives. We are an equal opportunity employer, not discriminating based on race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other protected characteristics.
OpenAI Global Applicant
We believe AI can help solve global challenges and want its benefits widely shared. Join us in shaping technology's future.
Other
- Background checks will be conducted as per applicable law.
- Applicants with arrest or conviction records will be considered in line with legal requirements.
- We are committed to providing reasonable accommodations for applicants with disabilities.