Product Policy, Cyber Policy Manager

OpenAI OpenAI · AI Frontier · San Francisco, CA · Product Policy

OpenAI is seeking a Product Policy Manager specializing in Cyber to guide the development, implementation, and enforcement of policies governing the use of their AI services for cybersecurity applications. This role involves understanding both defensive and offensive cyber operations, translating technical risks into practical policies, and collaborating with various teams to ensure responsible AI deployment.

What you'd actually do

  1. Provide cyber policy advice to technical and product teams based on a deep understanding of model capabilities, product architecture, abuse pathways, defensive security use cases, and the practical needs of cybersecurity teams.
  2. Evaluate cyber-relevant product launches and model capabilities, including how they may support legitimate security work and how they could be misused by malicious or irresponsible actors.
  3. Translate cyber threat risk into clear product requirements, launch guidance, enforcement standards, user-facing policy, and internal implementation guidance.
  4. Develop operationalizable standards, enforcement protocols, and escalation paths for cyber abuse scenarios, including vulnerability exploitation, credential abuse, social engineering, malware enablement, phishing, data exfiltration, and misuse of security automation.
  5. Partner with safety, security, product, engineering, research, legal, operations, communications, and global affairs teams to make principled, timely decisions about cyber risk in high-ambiguity situations.

Skills

Required

  • 5+ years of experience in cybersecurity, security engineering, threat intelligence, incident response, abuse investigations, detection engineering, product policy, cyber policy, trust and safety, or a closely related field.
  • Strong technical fluency in one or more cyber domains (e.g., vulnerability management, malware analysis, threat intelligence, incident response, phishing and credential abuse, detection engineering, secure software development, cloud security, identity and access management, or security automation).
  • Understanding of the modern cyber threat environment and AI's role in both defense and misuse.
  • Ability to evaluate dual-use cyber capabilities with nuance.
  • Clear communication with diverse stakeholders.
  • Experience building new policy frameworks and processes in ambiguous areas.

Nice to have

  • Experience turning technical risk into durable rules, standards, processes, or decisions.
  • Use data, threat intelligence, user feedback, and operational signals to improve policy quality, measure effectiveness, and identify emerging risks.

What the JD emphasized

  • cybersecurity
  • cyber risk
  • abuse prevention
  • policy