Security Engineer, Agent Security

OpenAI OpenAI · AI Frontier · San Francisco, CA · Security

Security Engineer focused on securing agentic AI systems by designing and implementing security controls, policies, and tooling. The role involves threat modeling, collaborating with infrastructure and safety teams, and influencing security strategy for AI agents.

What you'd actually do

  1. Architecting security controls for agentic AI – design, implement, and iterate on identity, network, and runtime-level defenses (e.g., sandboxing, policy enforcement) that integrate directly with the Agent Infrastructure stack.
  2. Building production-grade security tooling – ship code that hardens safety monitoring pipelines across agent executions at scale.
  3. Collaborating cross-functionally – work daily with Agent Infrastructure, product, research, safety, and security teams to balance security, performance, and usability.
  4. Influencing strategy & standards – shape the long-term Agent Security roadmap, publish best practices internally and externally, and help define industry standards for securing autonomous AI.

Skills

Required

  • Strong software-engineering skills in Python or at least one systems language (Go, Rust, C/C++)
  • Deep expertise in modern isolation techniques
  • Hands-on network security experience
  • Clear, concise communication
  • Bias for action & ownership
  • Cloud security depth on at least one major provider (Azure, AWS, GCP)

Nice to have

  • Familiarity with AI/ML security challenges

What the JD emphasized

  • ship solutions quickly
  • high standard of quality and security
  • track record of shipping and operating secure, high-reliability services
  • Deep expertise in modern isolation techniques
  • Bias for action & ownership
  • move quickly without sacrificing rigor

Other signals

  • securing agentic AI systems
  • designing and implementing security frameworks, policies, and controls
  • safeguard OpenAI’s critical assets
  • safe deployment of agentic systems
  • develop comprehensive threat models
  • fortify the platforms that power OpenAI’s most advanced agentic systems
  • enhance safety monitoring pipelines at scale
  • ship solutions quickly
  • high standard of quality and security
  • drive innovative solutions
  • set the industry standard for agent security
  • securing complex systems
  • designing robust isolation strategies for emerging AI technologies
  • mindful of usability
  • communicate effectively across various teams and functions
  • scalable and robust solutions
  • collaboratively in an innovative environment
  • solve complex security challenges
  • influence OpenAI’s security strategy
  • advancing the safe and responsible deployment of agentic AI systems
  • Architecting security controls for agentic AI
  • identity, network, and runtime-level defenses
  • sandboxing, policy enforcement
  • integrate directly with the Agent Infrastructure stack
  • Building production-grade security tooling
  • ship code that hardens safety monitoring pipelines across agent executions at scale
  • Collaborating cross-functionally
  • Agent Infrastructure, product, research, safety, and security teams
  • balance security, performance, and usability
  • Influencing strategy & standards
  • shape the long-term Agent Security roadmap
  • publish best practices internally and externally
  • define industry standards for securing autonomous AI
  • Strong software-engineering skills in Python or at least one systems language (Go, Rust, C/C++)
  • track record of shipping and operating secure, high-reliability services
  • Deep expertise in modern isolation techniques
  • container security, kernel-level hardening, and other isolation methods
  • Hands-on network security experience
  • implementing identity-based controls, policy enforcement, and secure large-scale telemetry pipelines
  • Clear, concise communication that bridges engineering, research, and leadership audiences
  • comfort influencing roadmaps and driving consensus
  • Bias for action & ownership
  • thrive in ambiguity
  • move quickly without sacrificing rigor
  • elevate the security bar company-wide from day one
  • Cloud security depth on at least one major provider (Azure, AWS, GCP)
  • identity federation, workload IAM, and infrastructure-as-code best practices
  • Familiarity with AI/ML security challenges
  • experience addressing risks associated with advanced AI systems