It Controls Data Engineer

OpenAI OpenAI · AI Frontier · San Francisco, CA · IT

This role focuses on building data infrastructure for IT controls, audit readiness, and continuous monitoring within OpenAI's IT and Security organization. It involves designing and maintaining data pipelines, datasets, models, and validation logic to ensure security and IT controls are measurable, repeatable, and defensible, particularly for SOX compliance. The role requires strong data engineering skills, experience with enterprise system data, and the ability to translate technical details for auditors.

What you'd actually do

  1. Building reliable data pipelines, models, and datasets for IT controls, including access, identity, configuration, change, ticketing, exception, and evidence data.
  2. Creating data quality, lineage, reconciliation, and completeness checks that make control data defensible for SOX and other audit use cases.
  3. Designing automated evidence generation workflows that produce complete, accurate, and repeatable audit populations, exports, dashboards, and control artifacts.
  4. Developing control monitoring logic to detect drift, missing evidence, stale access, direct system changes, overdue activity, and other control exceptions.
  5. Partnering with Security, IT, Infrastructure, Engineering, Risk Management, and system owners to understand source systems, validate data, and improve automation reliability.

Skills

Required

  • data engineering
  • analytics engineering
  • SQL
  • Python
  • enterprise system data
  • data modeling
  • data lineage
  • data completeness
  • data accuracy
  • data reconciliation
  • data validation
  • data observability
  • data repeatability
  • security controls
  • IT controls
  • SOX
  • audit readiness
  • risk management
  • compliance
  • regulated technology environments

Nice to have

  • Entra ID
  • Workday
  • GitHub
  • Databricks
  • Salesforce
  • Azure
  • AWS
  • GCP

What the JD emphasized

  • audit readiness
  • control assurance
  • SOX
  • audit use cases
  • audit stakeholders
  • regulated technology environments
  • audit
  • auditors