Offensive Security Agent Engineer

OpenAI OpenAI · AI Frontier · United States · Remote · Security

Seeking an Offensive Security Agent Engineer to build and own production-grade agents for continuous vulnerability identification and remediation across OpenAI's infrastructure and applications. This role combines deep offensive security expertise with agent engineering to create a scalable, automated security testing system.

What you'd actually do

  1. Serve as the technical owner of OpenAI’s offensive security agents, establishing its architecture, technical direction, operating model, and evaluation strategy.
  2. Design and build a portfolio of specialized agents that continuously test OpenAI’s infrastructure and applications from a variety of authenticated and unauthenticated perspectives.
  3. Translate expert offensive security workflows and intuition into tools, skills, harnesses, policies, and internal knowledge bases.
  4. Build agents that deeply understand OpenAI’s environment by integrating internal context.
  5. Develop rigorous evaluations that measure meaningful security outcomes and improvements in agent capability over time.

Skills

Required

  • substantial hands-on offensive security experience
  • strong judgment about which vulnerabilities and attack paths are worth pursuing
  • extensive domain expertise in areas such as cloud security, Kubernetes and container security, web application security, source-code review, Linux security, macOS security, or external attack-surface testing
  • built production quality software
  • built or meaningfully extended agent systems that use models, tools, structured context, memory, orchestration, and feedback loops to perform complex work
  • understand that an impressive agent demonstration is very different from a dependable production system, and you care deeply about evaluations, observability, failure recovery, safety, maintainability, and regression resistance

Nice to have

  • Expertise in cloud, Kubernetes, and modern web applications is especially valuable.
  • experience assessing complex, highly customized environments rather than relying primarily on standardized scanners, checklists, or known-vulnerability detection.
  • take an ambiguous offensive security problem, decompose it into a reliable system, and encode the reasoning and workflows of an experienced operator into software.
  • strong intuitions about where current models are capable, where they are unreliable, and how tools, context, scaffolding, and human feedback can ex

What the JD emphasized

  • build production quality software
  • built or meaningfully extended agent systems
  • dependable production system
  • evaluations, observability, failure recovery, safety, maintainability, and regression resistance

Other signals

  • building production systems
  • agent engineering
  • offensive security