OpenAI is seeking an exceptional Staff - Principal level offensive security domain expert to build agents that continuously identify and coordinate remediation of vulnerabilities across OpenAI’s infrastructure and applications. This role involves being the technical owner of this effort, combining deep offensive security judgment with agent engineering to build a production system that can operate safely and reliably at scale. As OpenAI increasingly uses automation, security testing must also become automated. Advances in model capabilities offer an opportunity to test more of the attack surface than human effort alone and a need to stay ahead of these capabilities as they become available to attackers. The role involves building specialized agents that understand OpenAI’s infrastructure, applications, processes, and security boundaries. These agents will explore cloud environments, Kubernetes clusters, web applications, endpoints, external attack surface, and other high-value targets by combining internal context with feedback from running systems. The goal is for agents to discover vulnerabilities, validate exploitability, document impact, drive remediation, and verify fixes. Success will be measured by outcomes like vulnerabilities fixed, attack surface covered, and performance on evals. These systems will operate continuously and with increasing autonomy, using guardrails and human-in-the-loop controls for dangerous actions, and learning from feedback from other domain experts. The position aims to define the future of offensive security at OpenAI, enabling agents to perform most repeatable security testing while human experts focus on automation and high-leverage agent-assisted manual review.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Principal
Education Level
No Education Listed