Principal Security Engineer, Infrastructure Security

OpenAI OpenAI · AI Frontier · United States · Remote · Security

This role focuses on securing the infrastructure that supports AI models and research, including GPU clusters, cloud environments, and data storage. It involves designing and building security controls, leading cross-functional programs, and performing threat modeling.

What you'd actually do

  1. Own end-to-end security outcomes for one or more critical infrastructure areas, including multi-quarter strategy, roadmap, and delivery.
  2. Design and build security controls across diverse layers (e.g., physical hardware, firmware/BMC, OS, Kubernetes, networks, and CI/CD) to defend against sophisticated adversaries and insider threats.
  3. Lead cross-functional programs to deploy security enhancements and control changes across broad-scale infrastructure, balancing security guarantees with reliability and velocity.
  4. Take a generalist approach to building security controls, balancing a mix of security expertise and broad technical skillsets to adapt to evolving challenges.
  5. Lead and/or drive threat modeling and design reviews for major infrastructure changes, ensuring strong security foundations and operational excellence.

Skills

Required

  • security principles
  • best practices
  • common vulnerabilities
  • security judgment
  • automation and tooling
  • frontier models and agents
  • leading large, cross-org initiatives
  • cloud platforms (AWS, Azure)
  • multi-cloud networks and infrastructure
  • cloud-agnostic systems
  • on-prem deployments and datacenters
  • container security
  • orchestration security
  • authentication/authorization
  • analytical and problem-solving skills
  • critical thinking
  • objective security risk assessment
  • communication skills

Nice to have

  • mentoring engineers
  • technical leadership

What the JD emphasized

  • Deep understanding of security principles, best practices, and common vulnerabilities, including strong security judgment under ambiguity
  • Expertise and curiosity about using frontier models and agents to effectively solve security challenges.
  • A track record of leading large, cross-org initiatives from concept to rollout, including navigating tradeoffs, driving alignment, and delivering measurable risk reduction.
  • Deep expertise in the security of cloud platforms (e.g., Amazon AWS, Microsoft Azure), especially securing multi-cloud networks and infrastructure, and designing cloud-agnostic systems.
  • Experience securing on-prem deployments and datacenters from construction to multi-tenant use.