Offensive Security Agent Engineer

OpenAI
$347,000 - $490,000

About The Position

OpenAI is seeking an exceptional Staff - Principal level offensive security domain expert to build agents that continuously identify and coordinate remediation of vulnerabilities across OpenAI’s infrastructure and applications. This role involves being the technical owner of this effort, combining deep offensive security judgment with agent engineering to build a production system that can operate safely and reliably at scale. As OpenAI increasingly uses automation, security testing must also become automated. Advances in model capabilities offer an opportunity to test more of the attack surface than human effort alone and a need to stay ahead of these capabilities as they become available to attackers. The role involves building specialized agents that understand OpenAI’s infrastructure, applications, processes, and security boundaries. These agents will explore cloud environments, Kubernetes clusters, web applications, endpoints, external attack surface, and other high-value targets by combining internal context with feedback from running systems. The goal is for agents to discover vulnerabilities, validate exploitability, document impact, drive remediation, and verify fixes. Success will be measured by outcomes like vulnerabilities fixed, attack surface covered, and performance on evals. These systems will operate continuously and with increasing autonomy, using guardrails and human-in-the-loop controls for dangerous actions, and learning from feedback from other domain experts. The position aims to define the future of offensive security at OpenAI, enabling agents to perform most repeatable security testing while human experts focus on automation and high-leverage agent-assisted manual review.

Requirements

  • Substantial hands-on offensive security experience and strong judgment about which vulnerabilities and attack paths are worth pursuing.
  • Extensive domain expertise in areas such as cloud security, Kubernetes and container security, web application security, source-code review, Linux security, macOS security, or external attack-surface testing. Expertise in cloud, Kubernetes, and modern web applications is especially valuable.
  • Experience assessing complex, highly customized environments rather than relying primarily on standardized scanners, checklists, or known-vulnerability detection.
  • Ability to take an ambiguous offensive security problem, decompose it into a reliable system, and encode the reasoning and workflows of an experienced operator into software.
  • Experience building production quality software.
  • Experience building or meaningfully extending agent systems that use models, tools, structured context, memory, orchestration, and feedback loops to perform complex work.
  • Understanding that an impressive agent demonstration is very different from a dependable production system, and caring deeply about evaluations, observability, failure recovery, safety, maintainability, and regression resistance.
  • Strong intuitions about where current models are capable, where they are unreliable, and how tools, context, scaffolding, and human feedback can expand their useful operating range.
  • Excitement about working closely with frontier models, curiosity about their emerging capabilities, and constantly looking for ways to use them to improve your own workflows.
  • Energized by the opportunity to serve as a technical owner of an ambitious new system, make foundational architectural decisions, and help grow a team around it.

Nice To Haves

  • Background or expertise in AI or data science.
  • Prior experience working in tech startups or fast-paced technology environments.
  • Experience in related disciplines such as Software Engineering, Product Security, Application Security, Detection Engineering, Site Reliability Engineering, Security Engineering, or IT Infrastructure.

Responsibilities

  • Serve as the technical owner of OpenAI’s offensive security agents, establishing its architecture, technical direction, operating model, and evaluation strategy.
  • Design and build a portfolio of specialized agents that continuously test OpenAI’s infrastructure and applications from a variety of authenticated and unauthenticated perspectives.
  • Translate expert offensive security workflows and intuition into tools, skills, harnesses, policies, and internal knowledge bases.
  • Build agents that deeply understand OpenAI’s environment by integrating internal context.
  • Develop capabilities for testing cloud and Kubernetes environments, modern web applications, external attack surface, endpoints, and other high-value systems.
  • Build complete vulnerability-management loops that move beyond discovery to impact validation, ownership identification, prioritization, remediation support, progress tracking, and fix verification.
  • Design human-in-the-loop systems that allow offensive security engineers to approve or reject potentially dangerous actions, provide missing context, redirect investigations, and steer agents away from unproductive paths.
  • Create feedback mechanisms that allow agents to learn from the decisions, corrections, and domain expertise of experienced offensive security practitioners.
  • Develop rigorous evaluations that measure meaningful security outcomes and improvements in agent capability over time.
  • Build production-quality infrastructure that allows the system to run continuously, recover from failures, remain observable and debuggable, and operate safely against production systems.
  • Investigate failures in agent reasoning and behavior, identify where models are capable or unreliable, and improve the surrounding tools, context, workflows, and guardrails accordingly.
  • Partner closely with offensive security, infrastructure security, product security, codex security, and engineering teams to ensure findings are high signal, understandable, and actionable.
  • Help define the future of offensive security at OpenAI, with the goal of enabling agents to perform most repeatable security testing while human experts focus on automation and high leverage agent-assisted manual review.

Benefits

  • OpenAI is an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.
  • Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates.
  • We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service