Data Scientist, Cybersecurity
Remote • US - Remote • FullTime
Posted 28d ago
About the job
OpenAI's Agentic Data Science team is seeking a senior data scientist to define and measure effective cybersecurity in the age of AI agents. This role involves partnering across Security, Cyber Product, Engineering, and Research teams to assess emerging risks, enhance internal security controls, and shape AI-powered security products. The core challenge lies in understanding and quantifying the effectiveness of AI agent security measures, distinguishing genuine risk reduction from user friction, and ensuring the accuracy and actionability of AI-identified vulnerabilities. This is a high-ownership position for an individual capable of establishing a new analytical discipline and driving measurable improvements in ambiguous security challenges.
Responsibilities
- Define metrics and evaluation frameworks for AI-agent security, including control coverage, behavior, access patterns, and risk.
- Quantify the effectiveness and operational costs of security controls, aiming to improve their precision and usability.
- Enhance data foundations for security decisions by improving instrumentation and establishing trusted datasets.
- Identify signals of anomalous behavior and risky access to strengthen detection and response capabilities.
- Assess the effectiveness of AI systems in identifying security issues and supporting user workflows.
- Develop quality measures for security findings, linking model behavior to outcomes like triage and remediation.
- Measure user interaction with security workflows to identify opportunities for product improvement.
- Design and implement measurement and experimentation strategies for new models, controls, and features.
- Translate technical analysis into security and product strategy recommendations.
- Help establish and grow a new security data science capability within the organization.
Requirements
- 5+ years of experience in data science, applied research, analytics, or a related quantitative field.
- Experience in cybersecurity, trust and safety, fraud prevention, privacy, or similar domains with adversarial behavior.
- Strong proficiency in SQL and Python for data investigation and workflow building.
- Experience defining metrics and evaluation frameworks with limited ground truth or delayed outcomes.
- Strong judgment in experimentation, causal inference, and observational analysis.
- Ability to partner effectively with cross-functional teams including engineers, product managers, and researchers.
- Demonstrated ability to translate technical analysis into concrete improvements.
- Comfort operating independently and structuring new domains.