OpenAI

Offensive Security Agent Engineer

OpenAI
Apply
2 months ago
Remote, United States +4 moreStaff+
H1B sponsor

Base Salary

$347k - $490k/yr

Responsibilities

  • Own the architecture, technical direction, operating model, and evaluation strategy for OpenAI’s offensive security agents.
  • Design and build specialized agents that continuously test infrastructure and applications from authenticated and unauthenticated perspectives.
  • Translate offensive security workflows into tools, skills, harnesses, policies, and internal knowledge bases.
  • Build capabilities for testing cloud and Kubernetes environments, modern web applications, external attack surfaces, endpoints, and other high-value systems.
  • Create vulnerability-management loops covering impact validation, ownership identification, prioritization, remediation support, progress tracking, and fix verification.
  • Design human-in-the-loop controls for approving dangerous actions, providing context, redirecting investigations, and steering agents safely.
  • Develop feedback mechanisms that incorporate decisions, corrections, and expertise from offensive security practitioners.
  • Build evaluations measuring meaningful security outcomes and agent capability over time.
  • Develop production infrastructure that runs continuously, recovers from failures, remains observable and debuggable, and operates safely against production systems.
  • Investigate agent reasoning and behavior failures and improve tools, context, workflows, and guardrails.
  • Partner with offensive security, infrastructure security, product security, Codex security, and engineering teams to make findings high-signal and actionable.
  • Help define the future of offensive security and enable agents to perform repeatable security testing.

Requirements

  • Substantial hands-on offensive security experience and strong judgment about meaningful vulnerabilities and attack paths.
  • Extensive expertise in one or more areas including cloud security, Kubernetes and container security, web application security, source-code review, Linux security, macOS security, or external attack-surface testing.
  • Experience assessing complex customized environments beyond standardized scanners, checklists, or known-vulnerability detection.
  • Ability to decompose ambiguous offensive security problems into reliable systems and encode expert workflows into software.
  • Experience building production-quality software.
  • Experience building or meaningfully extending agent systems using models, tools, structured context, memory, orchestration, and feedback loops.
  • Understanding of evaluations, observability, failure recovery, safety, maintainability, and regression resistance in production agent systems.
  • Strong understanding of current model capabilities and limitations and how tools, context, scaffolding, and human feedback affect performance.
  • Bonus: background or expertise in AI or data science, startup experience, or experience in software engineering, product security, application security, detection engineering, site reliability engineering, security engineering, or IT infrastructure.
OpenAI

About OpenAI

1,001-5,000 employees

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. AI is an extremely powerful tool that must be created with safety and human needs at its core. OpenAI is dedicated to putting that alignment of interests first — ahead of profit. To achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity. Our investment in diversity, equity, and inclusion is ongoing, executed through a wide range of initiatives, and championed and supported by leadership. At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

Contact me