Security Engineer, Host Assurance

OpenAISan Francisco, CA
1dHybrid

About The Position

OpenAI is seeking a Security Engineer, Host Assurance to help build the trust foundations for bare-metal platforms across OpenAI’s global infrastructure. This is a deeply hands-on engineering role for a builder who can design, implement, and operate the core security infrastructure that establishes trust in hardware platforms before they are eligible to run workloads. Success in this role requires strong technical judgment, the ability to work comfortably at low levels of the stack, and a practical mindset for building systems that are secure, reliable, and usable in fast-moving production environments. The systems you build will sit on the critical path of OpenAI’s frontier infrastructure investments and will directly shape how large amounts of compute are brought online - securely, responsibly, and at global scale - underpinning long-lived commitments around privacy, security, and reliability. You will partner closely with infrastructure, research, and confidential computing initiatives—including novel hardware platforms and emerging deployment models– to make the secure path the easiest path. This role is well suited for engineers who enjoy working across trust services, operating systems, hardware and firmware validation, and infrastructure security, and who are excited by ambiguous, high-impact problems at the boundary of hardware and large-scale systems.

Requirements

  • Have strong software engineering experience building and operating reliable production systems at scale.
  • Have deep expertise in at least one relevant domain such as PKI, HSMs, machine identity, applied cryptography, secure boot, firmware or hardware security, host attestation, or low-level platform security.
  • Are comfortable working across systems boundaries, from services and APIs down to host, boot, firmware, or hardware-adjacent trust mechanisms.
  • Can write production quality code and reason clearly about failure modes, operational safety, and long-term maintainability.
  • Have experience replacing fragile or manual security mechanisms with durable, paved-path infrastructure.
  • Balance rigor with pragmatism, and care about making strong security controls deployable in real-world environments.
  • Are self-directed, low ego, and willing to work across disciplines to solve the most important problems.
  • Enjoy building in ambiguous spaces where the architecture is still emerging, stakes are at all time high, and the future is being built.

Responsibilities

  • Design, build, and operate components of the Host Assurance platform that establish trust in bare-metal hosts before they are eligible for production use.
  • Help ensure hosts are verifiably trustworthy from delivery and installation through secure bootstrap and readiness to join orchestration systems.
  • Build and improve systems such as machine identity, certificate issuance and enrollment, HSM-backed or key-management-backed trust services, host attestation, measurement, and baseline verification tooling.
  • Validate delivered hardware and firmware against vendor claims and continuously detect and manage drift over time.
  • Eliminate insecure bootstrap patterns while preserving deployment throughput and operational reliability. Partner with provisioning, fleet, and orchestration teams to deliver paved paths where the secure approach is the easiest approach.
  • Contribute code, reviews, operational improvements, and design guidance for foundational trust services that must be dependable at scale.
  • Help define observable, testable security properties for host platforms and improve the telemetry and validation needed to enforce them in practice.
  • Participate in incident response, debugging, and post-incident improvements for security-critical infrastructure.
  • Work across different deployment models and provider boundaries while maintaining a consistent bar for host trust outcomes.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service