Security Engineer, Agent Security
San Francisco • FullTime
Posted 1y ago
About the job
As a Security Engineer on the Agent Security Team, you will be at the forefront of securing OpenAI’s cutting-edge agentic AI systems. Your role will involve designing and implementing robust security frameworks, policies, and controls to safeguard OpenAI’s critical assets and ensure the safe deployment of agentic systems. You will develop comprehensive threat models, partner tightly with our Agent Infrastructure group to fortify the platforms that power OpenAI’s most advanced agentic systems, and lead efforts to enhance safety monitoring pipelines at scale. We are looking for a versatile engineer who thrives in ambiguity and can make meaningful contributions from day one, prepared to ship solutions quickly while maintaining a high standard of quality and security. You will need to bring expertise in securing complex systems and designing robust isolation strategies for emerging AI technologies, all while being mindful of usability, and communicate effectively across various teams and functions.
Responsibilities
- Architect security controls for agentic AI, including identity, network, and runtime defenses.
- Build production-grade security tooling to harden safety monitoring pipelines.
- Collaborate with Agent Infrastructure, product, research, safety, and security teams.
- Influence the long-term Agent Security roadmap and help define industry standards for securing autonomous AI.
Requirements
- Strong software-engineering skills in Python or a systems language (Go, Rust, C/C++).
- Proven track record of shipping and operating secure, high-reliability services.
- Deep expertise in modern isolation techniques (e.g., container security, kernel-level hardening).
- Hands-on network security experience, including identity-based controls and policy enforcement.
- Clear, concise communication skills to bridge engineering, research, and leadership audiences.
- Ability to influence roadmaps and drive consensus.
- Bias for action and ownership, thriving in ambiguity.
- Cloud security depth on at least one major provider (Azure, AWS, GCP), including identity federation and infrastructure-as-code.
- Familiarity with AI/ML security challenges is a plus.