Staff/Principal Offensive Security Engineer - AI Agents
OpenAI
About the Role
We’re seeking an exceptional Staff - Principal level offensive security domain expert to build agents that continuously identify and coordinate remediation of vulnerabilities across OpenAI’s infrastructure and applications. You will be the technical owner of this effort, combining deep offensive security judgment with agent engineering to build a production system that can operate safely and reliably at scale.
As OpenAI increasingly uses automation throughout the company, we believe our security testing must become increasingly automated as well. Advances in model capabilities create an opportunity to test more of our attack surface than would be possible through human effort alone and a need to ensure that we remain ahead of those same capabilities as they become available to attackers.
In this role, you’ll build a portfolio of specialized agents that develop a deep understanding of OpenAI’s infrastructure, applications, processes, and security boundaries. These agents will combine internal context with feedback from running systems to explore our cloud environments , Kubernetes clusters , web applications , endpoints, external attack surface, and other high-value targets.
The goal is for agents to not only discover vulnerabilities, but also to validate exploitability, document impact, drive remediation, and verify fixes. Success will be measured through outcomes like vulnerabilities fixed, attack surface covered, and performance on evals you’ll build.
These systems will operate continuously and with increasing autonomy, while using carefully designed guardrails and human-in-the-loop controls for dangerous actions. They will also learn from feedback from other domain experts throughout the company.
In this role, you will:
- Serve as the technical owner of OpenAI’s offensive security agents, establishing its architecture, technical direction, operating model, and evaluation strategy.
- Design and build a portfolio of specialized agents that continuously test OpenAI’s infrastructure and applications from a variety of authenticated and unauthenticated perspectives.
- Translate expert offensive security workflows and intuition into tools, skills, harnesses, policies, and internal knowledge bases.
- Build agents that deeply understand OpenAI’s environment by integrating internal context.
- Develop capabilities for testing cloud and Kubernetes environments , modern web applications , external attack surface, endpoints, and other high-value systems.
- Build complete vulnerability-management loops that move beyond discovery to impact validation, ownership identification, prioritization, remediation support, progress tracking, and fix verification.
- Design human-in-the-loop systems that allow offensive security engineers to approve or reject potentially dangerous actions, provide missing context, redirect investigations, and steer agents away from unproductive paths.
- Create feedback mechanisms that allow agents to learn from the decisions, corrections, and domain expertise of experienced offensive security practitioners.
- Develop rigorous evaluations that measure meaningful security outcomes and improvements in agent capability over time.
- Build production-quality infrastructure that allows the system to run continuously, recover from failures, remain observable and debuggable, and operate safely against production systems.
- Investigate failures in agent reasoning and behavior, identify where models are capable or unreliable, and improve the surrounding tools, context, workflows, and guardrails accordingly.
- Partner closely with offensive security, infrastructure security, product security, codex security, and engineering teams to ensure findings are high signal, understandable, and actionable.
- Help define the future of offensive security at OpenAI, with the goal of enabling agents to perform most repeatable security testing while human experts focus on automation and high leverage agent-assisted manual review.
You might thrive in this role if:
- You have substantial hands-on offensive security experience and strong judgment about which vulnerabilities and attack paths are worth pursuing.
- You have extensive domain expertise in areas such as cloud security , Kubernetes and container security , web application security , source-code review, Linux security, macOS security, or external attack-surface testing. Expertise in cloud , Kubernetes , and modern web applications is especially valuable.
- You have experience assessing complex, highly customized environments rather than relying primarily on standardized scanners, checklists, or known-vulnerability detection.
- You can take an ambiguous offensive security problem, decompose it into a reliable system, and encode the reasoning and workflows of an experienced operator into software.
- You have built production quality software .
- You have built or meaningfully extended agent systems that use models, tools, structured context, memory, orchestration, and feedback loops to perform complex work.
- You understand that an impressive agent demonstration is very different from a dependable production system, and you care deeply about evaluations, observability, failure recovery, safety, maintainability, and regression resistance.
- You have strong intuitions about where current models are capable, where they are unreliable, and how tools, context, scaffolding, and human feedback can expand their useful operating range.
- You are excited about working closely with frontier models , curious about their emerging capabilities, and constantly look for ways to use them to improve your own workflows.
- You are energized by the opportunity to serve as a technical owner of an ambitious new system, make foundational architectural decisions, and help grow a team around it.
Bonus points:
- Background or expertise in AI or data science .
- Prior experience working in tech startups or fast-paced technology environments.
- Experience in related disciplines such as Software Engineering , Product Security , Application Security , Detection Engineering , Site Reliability Engineering , Security Engineering , or IT Infrastructure .
- ...We’re seeking an exceptional Staff - Principal level offensive security domain expert to build agents that continuously identify and... ...security judgment with agent engineering to build a production system that... ...Background or expertise in AI or data science . Prior experience...SuggestedFull time
- ...About the Team Security is at the foundation of OpenAI’s mission... ...re seeking an exceptional Principal-level Offensive Security Engineer focused on deep, hands-on... ...testing of OpenAI’s agent-powered products, infrastructure... ...assessing the security of AI-powered systems. ~...SuggestedFull time
$148.5k - $223.9k
...CategoryProductJob DetailsAbout SalesforceSalesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition... ...future of Salesforce.We are looking for a Senior Offensive Security Engineer (Red Team) with a strong, hands-on attacker mindset...SuggestedFull timeRemote work- ...Wraithwatch Offensive Security Engineer Wraithwatch was founded by security engineers from SpaceX, Palantir... ...to build the next generation of AI-powered cyber defense systems for the... ...utilizing generative artificial intelligence agents to autonomously model a digital twin...SuggestedRemote workWeekend work
- ...with custom domains, social engineering, lateral movement, privilege... ...checkbox compliance. Build offensive tooling. Engineer security platforms, scanning pipelines... ...the team's impact. Weaponize AI for defense. Design and build LLM-powered agents that detect, classify,...SuggestedRemote work
- ...Senior Offensive Security Engineer (Red Team) Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword — it's a way of life. The world of work as we know it...Remote work
$170k
...products for our clients and users. We're looking for an Offensive Security Engineer to think like an attacker and validate the security of... ...create meaningful business risk—not theoretical findings. AI should be one of your primary tools, enabling you to analyze...Full timeSummer workWork at officeImmediate startRemote work$500 per month
...Offensive Security Engineer Netherlands (remote) About ClickHouse Recognized on the 2025 Forbes Cloud 100 list, ClickHouse is one of the... ...real-time analytics, data warehousing, observability, and AI workloads. The company's sustained, accelerating momentum...Local areaRemote workHome officeFlexible hours- ...To validate the security of products through real-world exploitation, the full-time remote Senior Offensive Security Engineer will identify and demonstrate attack paths against applications and infrastructure, utilizing AI to enhance vulnerability discovery and analysis...Full timeRemote work
$170k
...applications and next steps. Our partner is looking for a Senior Offensive Security Engineer based in the United States. This role offers the... ...position combines offensive security expertise with modern AI-powered workflows to accelerate research, testing, and exploit...Summer workWork at officeImmediate startRemote work$117.6k - $161.7k
...Atlanta, Nashville))We're building a new AI & Offensive Tooling capability inside our Offensive Security organization, and we're looking for a senior engineer who can both build it and use it. As... ...production-quality software and AI agents, LLM-driven planning loops, multi-...Full timeTemporary workApprenticeshipWork at officeRemote workWork from homeHome office$161k - $242k
...Category Engineering Hire Type Employee Job ID 17996 Base Salary Range $161000-$242000... ..., enabling customers to rapidly innovate AI-powered products. We deliver industry-leading... ...before someone else does. You approach security testing with curiosity and rigor, not just...Permanent employmentLive inRemote workWorldwide- ...Job Title: Senior Penetration Tester / Offensive Security Specialist Location: Remote... ...clear remediation guidance 3. Social Engineering & Human Layer Testing Design and... ...Python scripting and Linux toolchains AI/GenAI-assisted tooling for attack...Contract workRemote work
- .... Position Title: Web Developer Security Engineer Location: US Congressional Budget... ...APIs, and SQL. Ability to leverage AI-assisted development tools (e.g.,... ...Certified Application Security Engineer). Offensive Security: OSWE (OffSec Web Expert);...Remote jobFull timeWork at officeLocal area
- ...intelligence to power the AI economy. We're a... ...expertise directly back into agents. Mercor is creating... ...You'll own application security at a company where the... ...the easy path for 50+ engineers Threat models for new... ...HackerOne, Bugcrowd) Offensive security skills - you'...Work at officeRemote workRelocation packageShift work
$155.52k - $194.4k
...Twilio is in your hands. We use Artificial Intelligence (AI) to help make our hiring process efficient. That said,... ...See yourself at Twilio Join the team as Twilio’s next Staff Offensive Security Engineer. About the job The Staff Engineer acts as a Technical...Full timeLocal areaRemote workWorldwide$85 per hour
...Security Engineer (Coding Agent Experience) is a remote engineering review track for evaluating production code, debugging traces, and developer-facing AI outputs against real-world correctness standards. Reviewers reproduce failures, write the unit test the model should...Remote jobFor contractors10 hours per week$85 per hour
...connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors... ..., Larry Summers , and Jack Dorsey . Position: Security Engineer (Coding Agent Experience) Type: Contract Compensation: $85/hour...Contract workSummer workRemote work$160k - $205k
...work with some of the best information security professionals in the world in challenging... ...Pentester to join a team of world-class offensive security professionals. In this role, you... ...and experience by mentoring junior engineers, and assist with monitoring and response...Full timeWork at officeRemote workShift workDay shift$153k - $376k
...translating designs into code, or iterating with AI. From idea to product, Figma empowers... ...design and collaboration, join us!As a Security Engineer you will identify and drive impactful... ....Help run penetration testing and offensive security exercises against Figma’s AI...Minimum wageFull timeLocal areaRemote workFlexible hours- ...HackerOne Platform unites agentic AI solutions with the ingenuity... ...world’s largest community of security researchers to continuously... ...in the security industry. Offensive security is no longer optional... ...accountability.Senior Security Engineer, Detection and ResponseRemote...ApprenticeshipLocal areaRemote workFlexible hoursShift work
- Crane Company is seeking an Information Security professional to join its Global Information Security Team. This role involves supporting... ...of system and network administration. Prior experience in offensive security is required.In this role, the successful candidate will...Full timeWork experience placementLocal areaRemote work
$115k - $190k
...Web Developer Security Engineer Clearance Requirement: Public Trust (Tier 2) Location: Remote... .../Scripting: Python, Node.js, Java AI-Assisted Development Tools (e.g.,... ...Penetration Tester (GWEB), OR CASE Offensive Security (One Required): OSWE, OR...Remote work- About BreachLock BreachLock is a global leader in AI‑powered penetration testing and attack surface management. We help... ...The Role We're looking for a technically strong Sales Engineer with an offensive security background to join our US sales team. You will be the trusted...Remote job
- ...Security Operations Center (SOC) Engineer We are not just another fintech unicorn. We are a pack of... ...and applications, and help turn offensive security knowledge into real detection... ...and controls. Use AI as leverage. Build agents and automations for investigation...Remote work
- ...Are you an experienced Senior Offensive Security Engineer that wants to work with cutting-edge cybersecurity technologies and contribute to enhancing our overall security posture? At Ivanti, we work passionately and authentically, striving to win together and make a real...Work at officeRemote workFlexible hours
- ...The role of a Senior Security Engineer in 2026 has evolved from a traditional... ...expert. With the rise of AI-driven threats and the death... ...architecture projects, mentoring junior staff, and automating security... ...standard). - OSCP / OSCE: Offensive Security certifications for...Full time
$200k - $240k
...Liftoff is a leading AI-powered performance marketing platform... ...presence. The Liftoff Security team protects Liftoff's customers... ...defend it, and partner with engineering teams as they ship new products... ...loop between the team's offensive and proactive findings and detection...Full timeRemote work- ...Seeking a full-time Offensive Security Engineer, this remote position will manage the development of specialized agents to continuously identify and remediate vulnerabilities across OpenAI's infrastructure and applications, ensuring safe and reliable operations at scale...Full timeRemote work
- ...About the role Mission Strengthen Sporty’s offensive security posture by proactively testing and identifying vulnerabilities across our external... ..., and endpoint defenses. The Offensive Security Engineer owns the security testing, continuous perimeter monitoring,...Full timeWork at officeLocal areaRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff/Principal Offensive Security Engineer - AI Agents. Be the first to apply!



