Security Engineer, Host Assurance

OpenAI OpenAI · AI Frontier · San Francisco, CA · Security

Security Engineer focused on building and operating the Host Assurance platform for bare-metal infrastructure. This role establishes trust in hardware platforms before they run workloads, involving machine identity, attestation, and hardware/firmware validation, ensuring secure and scalable compute foundations.

What you'd actually do

  1. Design, build, and operate components of the Host Assurance platform that establish trust in bare-metal hosts before they are eligible for production use.
  2. Help ensure hosts are verifiably trustworthy from delivery and installation through secure bootstrap and readiness to join orchestration systems.
  3. Build and improve systems such as machine identity, certificate issuance and enrollment, HSM-backed or key-management-backed trust services, host attestation, measurement, and baseline verification tooling.
  4. Validate delivered hardware and firmware against vendor claims and continuously detect and manage drift over time.
  5. Eliminate insecure bootstrap patterns while preserving deployment throughput and operational reliability. Partner with provisioning, fleet, and orchestration teams to deliver paved paths where the secure approach is the easiest approach.

Skills

Required

  • Software engineering experience building and operating reliable production systems at scale
  • Deep expertise in PKI, HSMs, machine identity, applied cryptography, secure boot, firmware or hardware security, host attestation, or low-level platform security
  • Experience working across systems boundaries (services, APIs, host, boot, firmware, hardware)
  • Ability to write production quality code
  • Experience replacing fragile or manual security mechanisms with durable infrastructure
  • Experience building in ambiguous spaces

Nice to have

  • Experience with cloud-scale orchestration
  • Experience with confidential computing initiatives
  • Experience with novel hardware platforms and emerging deployment models
  • Experience with telemetry and validation for security enforcement

What the JD emphasized

  • deeply hands-on engineering role
  • strong technical judgment
  • work comfortably at low levels of the stack
  • practical mindset for building systems that are secure, reliable, and usable in fast-moving production environments
  • critical path of OpenAI’s frontier infrastructure investments
  • directly shape how large amounts of compute are brought online
  • partner closely with infrastructure, research, and confidential computing initiatives
  • novel hardware platforms and emerging deployment models
  • engineers who enjoy working across trust services, operating systems, hardware and firmware validation, and infrastructure security
  • ambiguous, high-impact problems at the boundary of hardware and large-scale systems
  • building and operating reliable production systems at scale
  • deep expertise in at least one relevant domain such as PKI, HSMs, machine identity, applied cryptography, secure boot, firmware or hardware security, host attestation, or low-level platform security
  • comfortable working across systems boundaries, from services and APIs down to host, boot, firmware, or hardware-adjacent trust mechanisms
  • write production quality code and reason clearly about failure modes, operational safety, and long-term maintainability
  • experience replacing fragile or manual security mechanisms with durable, paved-path infrastructure
  • Balance rigor with pragmatism
  • making strong security controls deployable in real-world environments
  • self-directed, low ego
  • work across disciplines to solve the most important problems
  • building in ambiguous spaces where the architecture is still emerging, stakes are at all time high, and the future is being built