yoinka

Offensive Security Agent Engineer

OpenAI

RemoteRemote - USFull TimeMid
Sign in to applyVerified 1h ago
Location
Remote - US
Employment
Full Time
Work model
Remote
Level
Mid
Posted
2h ago

Skills

KubernetesLinux

About this role

About the Team

Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.

About the Role

We’re seeking an exceptional Staff - Principal level offensive security domain expert to build agents that continuously identify and coordinate remediation of vulnerabilities across OpenAI’s infrastructure and applications. You will be the technical owner of this effort, combining deep offensive security judgment with agent engineering to build a production system that can operate safely and reliably at scale. As OpenAI increasingly uses automation throughout the company, we believe our security testing must become increasingly automated as well. Advances in model capabilities create an opportunity to test more of our attack surface than would be possible through human effort alone and a need to ensure that we remain ahead of those same capabilities as they become available to attackers. In this role, you’ll build a portfolio of specialized agents that develop a deep understanding of OpenAI’s infrastructure, applications, processes, and security boundaries. These agents will combine internal context with feedback from running systems to explore our cloud environments, Kubernetes clusters, web applications, endpoints, external attack surface, and other high-value targets. The goal is for agents to not only discover vulnerabilities, but also to validate exploitability, document impact, drive remediation, and verify fixes. Success will be measured through outcomes like vulnerabilities fixed, attack surface covered, and performance on evals you’ll build. These systems will operate continuously and with increasing autonomy, while using carefully designed guardrails and human-in-the-loop controls for dangerous actions. They will also learn from feedback from other domain experts throughout the company. In this role, you will: Serve as the technical owner of OpenAI’s offensive security agents, establishing its architecture, technical direction, operating model, and evaluation strategy. Design and build a portfolio of specialized agents that continuously test OpenAI’s infrastructure and applications from a variety of authenticated and unauthenticated perspectives. Translate expert offensive security workflows and intuition into tools, skills, harnesses, policies, and internal knowledge bases. Build agents that deeply understand OpenAI’s environment by integrating internal context. Develop capabilities for testing cloud and Kubernetes environments, modern web applications, external attack surface, endpoints, and other high-value systems. Build complete vulnerability-management loops that move beyond discovery to impact validation, ownership identification, prioritization, remediation support, progress tracking, and fix verification. Design human-in-the-loop systems that allow offensive security engineers to approve or reject potentially dangerous actions, provide missing context, redirect investigations, and steer agents away from unproductive paths. Create feedback mechanisms that allow agents to learn from the decisions, corrections, and domain expertise of experienced offensive security practitioners. Develop rigorous evaluations that measure meaningful security outcomes and improvements in agent capability over time. Build production-quality infrastructure that allows the system to run continuously, recover from failures, remain observable and debuggable, and operate safely against production systems. Investigate failures in agent reasoning and behavior, identify where models are

Offensive Security Agent Engineer at OpenAI — Remote - US | Yoinka