Systems Software Engineer, Security, First Party Hardware

Remote San Francisco FullTime

Posted 3mo ago

Job Location

San Francisco

Tech Stack

Remote Work Policy

Fully remote

Employment Type

FullTime

Categories

Applied AI Engineer

About the job

OpenAI's Hardware organization is developing AI-native silicon and system-level solutions for advanced AI workloads. We are seeking a Security Engineer to join our First-Party Hardware team. In this role, you will own the end-to-end security foundation for OpenAI's first-party AI hardware systems, encompassing hardware security, embedded security, system security, and practical deployment at data center scale. You will partner with various teams to define and deliver system-level device trust, including aspects like boot integrity, device identity, provisioning, attestation, management-plane security, storage encryption, debug controls, firmware updates, and decommissioning. Your accountability will extend from translating threat models into requirements, to implementation, and finally to validation evidence supporting launch decisions.

Responsibilities

  • Own security requirements, threat models, validation strategy, and launch-readiness evidence for first-party hardware platforms from design through production.
  • Design and review secure boot, measured boot, roots of trust, platform firmware resilience, firmware signing, recovery, and anti-rollback strategies.
  • Own device identity, provisioning, enrollment, attestation, certificate lifecycle, and key-management requirements across manufacturing and data center bring-up.
  • Harden management interfaces and operational access paths across various system components, including TLS/mTLS, Redfish, gNMI, SSH, syslog, and break-glass workflows.
  • Drive security requirements for manufacturing, supply chain, firmware/image signing, storage encryption, RMA, repair, and decommissioning processes.
  • Build and drive validation for security-critical hardware and firmware behavior, including debug lockout, lifecycle transitions, update paths, attestation evidence, and recovery flows.
  • Partner with vendors and contract manufacturers to translate security requirements into deliverables, test evidence, and launch gates.
  • Drive end-to-end closure across design, implementation, manufacturing readiness, deployment readiness, fleet operations, and incident response.
  • Investigate hardware and firmware security issues, assess exploitability and operational risk, and drive durable fixes.

Requirements

  • 7+ years of hands-on experience or equivalent expertise in hardware security, embedded security, firmware security, platform security, or low-level systems security.
  • Experience shipping or securing real hardware platforms, embedded devices, servers, accelerators, networking systems, BMCs, bootloaders, BIOS/UEFI, RTOS, kernels, or firmware update systems.
  • Deep familiarity with secure boot, measured boot, TPMs, hardware roots of trust, device attestation, key provisioning, debug interfaces, firmware signing, recovery, or lifecycle-state design.
  • Strong applied-cryptography judgment for secure boot, attestation, TLS/mTLS, key storage, certificate lifecycle, storage encryption, and long-range transitions.
  • Ability to read and write systems code in C, C++, or Rust for reviewing, prototyping, testing, or debugging security-critical behavior.
  • Comfort with hardware-software interfaces such as SPI, I2C, SMBus, PCIe, UART, JTAG, SWD, GPIOs, TPMs, and board-level debug tools.
  • Proven track record driving security improvements with cross-functional teams (hardware, firmware, infrastructure, manufacturing, operations).
  • Experience owning broad, ambiguous security programs end-to-end, translating risk into technical requirements, validation plans, and engineering decisions.
  • Clear written and verbal communication skills to translate ambiguous security risks into actionable requirements, design reviews, tests, and decisions.

Benefits

  • Relocation assistance available

About OpenAI

Get new AI jobs in your inbox

A weekly digest of the newest AI engineering roles.

© 2026 AI Job Board. All rights reserved.