Global Detection and Response Lead

OpenAI OpenAI · AI Frontier · San Francisco, CA · Security

Lead and scale OpenAI’s cybersecurity detection and response operations, setting strategy and driving execution for security monitoring, incident response, recovery, and post-incident improvements across global infrastructure. This role involves building and mentoring teams, partnering with various engineering and product teams, and evaluating/responding to emergent security concerns in a frontier AI lab environment, including detection and response strategies for agents. The role also emphasizes leveraging AI models to solve security problems.

What you'd actually do

  1. Oversee global detection and response operations, including continuous monitoring, triage, investigation, containment, and remediation of security events across a diverse set of networks and infrastructure.
  2. Lead, mentor, and directly manage several small teams of senior engineers across observability, detection and response, and threat intelligence. Hire and scale these functions deliberately and proportionately as OpenAI’s compute footprint and platform ambitions grow.
  3. Ensure world-class operational rigor and readiness through management of incident playbooks, on-call and escalation paths, tabletop exercises, and continuous improvement of response quality and speed.
  4. Improve detection quality and coverage by partnering with engineering teams to ensure critical telemetry is available, reliable, and actionable across cloud, corporate, and production environments.
  5. Deeply partner across all of OpenAI to evaluate and respond to emergent security concerns in a frontier AI lab environment, such as detection and response strategies for agents operating across infrastructure at scale.
  6. Build a world-class security program capable of withstanding tier-1 adversaries by maximally embracing our own models to solve frontier security problems.

Skills

Required

  • 10+ years in cybersecurity
  • Detection engineering
  • Incident response
  • Security operations
  • Building and leading teams
  • Modern observability stacks (SIEM, data lakes, EDR, cloud telemetry, logging)
  • Detection primitives
  • Adversary tradecraft (TTPs)
  • Global footprint experience
  • Airgapped and sovereign environments experience
  • Leadership skills
  • Written and verbal communication skills
  • Calm under pressure
  • Security incident command

Nice to have

  • Active U.S. Government security clearance (Top Secret) or willingness and eligibility to obtain one
  • Leveraging AI models for security problems

What the JD emphasized

  • active U.S. Government security clearance (Top Secret) or willingness and eligibility to obtain one
  • deep expertise in detection engineering, incident response, and security operations
  • deep experience building and leading detection and response, instrumentation/observability, and threat intelligence teams across a global footprint, including airgapped and sovereign environments
  • deep expertise in modern observability stacks (e.g., SIEM, data lakes, EDR, cloud telemetry, logging) and detection primitives
  • Understand modern adversary tradecraft (TTPs) and have demonstrated experience and expertise translating it into practical detection strategies and response actions