Enterprise Security Engineer

OpenAI OpenAI · AI Frontier · United States · Remote · IT

OpenAI is seeking an Enterprise Security Engineer to implement and manage the security of internal information systems. This role involves developing security measures, monitoring for threats, enforcing policies, hardening infrastructure, advising employees on best practices, and using AI-driven models for security tasks. The position requires experience with macOS fleets, endpoint security, public cloud, identity and access management, and scripting.

What you'd actually do

  1. Develop and implement security measures to protect our company's information assets against unauthorized access, disclosure, or misuse.
  2. Monitor internal and external systems for security threats and respond to alerts.
  3. Contribute to and enforce our company's IT and Security policies and procedures.
  4. Work closely with our IT department to harden our infrastructure using best practices in AzureAD, GSuite, Github, and other SaaS tooling.
  5. Advise our employees on best practices for maintaining the security of their endpoints, and office AV and network infrastructure.

Skills

Required

  • Experience in protecting and managing macOS fleets.
  • Experience deploying and managing endpoint security solutions (e.g. management frameworks, EDR tools).
  • Experience with public cloud service providers (e.g. Amazon AWS, Microsoft Azure).
  • Experience with identity and access management frameworks and protocols, including SAML, OAUTH, and SCIM.
  • Experience with e-mail security protocols (e.g. SPF, DKIM, DMARC) and controls.
  • Intermediate or advanced proficiency with a scripting language (e.g. Python, Bash, or similar).
  • Knowledge of modern adversary tactics, techniques, and procedures.

Nice to have

  • Ability to empathize and collaborate with colleagues, independently manage and run projects, and prioritize efforts for risk reduction.

What the JD emphasized

  • implementing and managing the security of OpenAI's internal information systems’ infrastructure and processes
  • develop security capabilities
  • enforce security policies
  • monitor internal systems for security threats
  • protect company data
  • secure by default
  • zero trust
  • data security
  • improved security detection and response
  • data classification
  • maintaining a secure environment
  • endpoint and cloud security roadmaps
  • security posture