Base Salary
$266k - $445k/yr
Responsibilities
- Own security requirements, threat models, validation strategy, and launch-readiness evidence for first-party hardware platforms from design through production deployment.
- Design and review secure boot, measured boot, roots of trust, platform firmware resilience, firmware signing, recovery, and anti-rollback strategies.
- Own device identity, provisioning, enrollment, attestation, certificate lifecycle, and key-management requirements across manufacturing and data-center bring-up.
- Harden management interfaces and operational access paths across BMCs, hosts, accelerators, switches, and service tooling.
- Drive security requirements for manufacturing, supply chain, image signing, storage encryption, RMA, repair, and decommissioning.
- Build and drive validation for security-critical hardware and firmware behavior, including debug lockout, lifecycle transitions, update paths, attestation evidence, and recovery flows.
- Partner with vendors and contract manufacturers to deliver security requirements, test evidence, and launch gates.
- Drive closure across design, implementation, manufacturing readiness, deployment readiness, fleet operations, and incident response.
- Investigate hardware and firmware security issues, assess exploitability and operational risk, and drive durable fixes.
Requirements
- 7+ years of hands-on experience, or exceptional accomplishments demonstrating equivalent expertise, in hardware, embedded, firmware, platform, or low-level systems security.
- Experience shipping or securing hardware platforms, embedded devices, servers, accelerators, networking systems, BMCs, bootloaders, BIOS/UEFI, RTOS, kernels, or firmware update systems.
- Deep familiarity with secure boot, measured boot, TPMs, hardware roots of trust, device attestation, key provisioning, debug interfaces, firmware signing, recovery, or lifecycle-state design.
- Applied cryptography expertise for secure boot, attestation, TLS/mTLS, key storage, certificate lifecycle, storage encryption, and post-quantum readiness.
- Ability to read and write systems code in C, C++, or Rust for reviewing, prototyping, testing, or debugging security-critical behavior.
- Comfort with SPI, I2C, SMBus, PCIe, UART, JTAG, SWD, GPIOs, TPMs, and board-level debug tools.
- Track record of driving security improvements with hardware, firmware, infrastructure, manufacturing, operations, and partner teams.
- Experience owning broad, ambiguous security programs end to end and translating risk into technical requirements, validation plans, and engineering decisions.
- Strong written and verbal communication skills.
- Candidates may need to meet U.S. export-control legal-status requirements.
Benefits
- Hybrid work in San Francisco with 3 days per week onsite
- Relocation assistance available
About OpenAI
OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. AI is an extremely powerful tool that must be created with safety and human needs at its core. OpenAI is dedicated to putting that alignment of interests first — ahead of profit. To achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity. Our investment in diversity, equity, and inclusion is ongoing, executed through a wide range of initiatives, and championed and supported by leadership. At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.
