Security Engineer, Insider Threat Detection & Response

OpenAI OpenAI · AI Frontier · San Francisco, CA · Security

Security Engineer focused on insider threat detection and response, innovating on detection infrastructure, developing detection rules, and driving projects related to insider threats within AI infrastructure. The role also involves partnering with cross-functional teams and using AI to enhance security posture.

What you'd actually do

  1. Innovate on Detection and Response infrastructure to engineer and automate end-to-end detection and investigation workflows.
  2. Develop, measure, and tune detection rules to ensure effective and sustainable operations.
  3. Drive projects across OpenAI’s technology stack with a focus on insider threats, ranging from access abuse and intellectual property theft to novel risks emerging within AI infrastructure.
  4. Partner closely with cross-functional stakeholders, including HR, Legal, and peer investigative teams, providing technical expertise and evidence to support investigations.
  5. Collaborate on cutting-edge AI research, and use AI to improve OpenAI’s Security posture.

Skills

Required

  • Detection and Response
  • Insider Threat Detection
  • Security Infrastructure
  • Detection Rule Development
  • Access Abuse
  • Intellectual Property Theft
  • AI Infrastructure Security
  • Cross-functional Collaboration
  • Technical Expertise
  • Evidence Support
  • AI Research Collaboration
  • Security Posture Improvement
  • macOS
  • Windows
  • Linux
  • Kubernetes
  • Cloud Infrastructure
  • Adversary Tactics
  • Attack Paths
  • Data Exfiltration Techniques
  • Incident Management
  • Python
  • Bash
  • PowerShell
  • Project Management
  • Risk Reduction
  • Adaptability to New Risks

What the JD emphasized

  • 5+ years experience working in a detection/response or insider-risk role
  • broad familiarity with operating systems and platforms such as macOS, Windows, Linux, and Kubernetes, along with experience in cloud infrastructure
  • Knowledge of modern adversary tactics and attack paths, data exfiltration techniques, and have experience running and leading incidents
  • Proficiency with a scripting language (e.g. Python, Bash, PowerShell, or similar)
  • Independently manage and run projects , balance preventative controls with user friction, and prioritize efforts for risk reduction
  • You’re motivated by securing transformative technology and can adapt familiar security frameworks to new risks in AI infrastructure

Other signals

  • Detecting insider threats
  • Safeguard OpenAI's most sensitive assets
  • AI infrastructure
  • Use AI to improve OpenAI’s Security posture