Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff/Principal Offensive Security Engineer - AI Agents

Full-time

OpenAI

About the Role

We’re seeking an exceptional Staff - Principal level offensive security domain expert to build agents that continuously identify and coordinate remediation of vulnerabilities across OpenAI’s infrastructure and applications. You will be the technical owner of this effort, combining deep offensive security judgment with agent engineering to build a production system that can operate safely and reliably at scale.

As OpenAI increasingly uses automation throughout the company, we believe our security testing must become increasingly automated as well. Advances in model capabilities create an opportunity to test more of our attack surface than would be possible through human effort alone and a need to ensure that we remain ahead of those same capabilities as they become available to attackers.

In this role, you’ll build a portfolio of specialized agents that develop a deep understanding of OpenAI’s infrastructure, applications, processes, and security boundaries. These agents will combine internal context with feedback from running systems to explore our cloud environments , Kubernetes clusters , web applications , endpoints, external attack surface, and other high-value targets.

The goal is for agents to not only discover vulnerabilities, but also to validate exploitability, document impact, drive remediation, and verify fixes. Success will be measured through outcomes like vulnerabilities fixed, attack surface covered, and performance on evals you’ll build.

These systems will operate continuously and with increasing autonomy, while using carefully designed guardrails and human-in-the-loop controls for dangerous actions. They will also learn from feedback from other domain experts throughout the company.

In this role, you will:

  • Serve as the technical owner of OpenAI’s offensive security agents, establishing its architecture, technical direction, operating model, and evaluation strategy.
  • Design and build a portfolio of specialized agents that continuously test OpenAI’s infrastructure and applications from a variety of authenticated and unauthenticated perspectives.
  • Translate expert offensive security workflows and intuition into tools, skills, harnesses, policies, and internal knowledge bases.
  • Build agents that deeply understand OpenAI’s environment by integrating internal context.
  • Develop capabilities for testing cloud and Kubernetes environments , modern web applications , external attack surface, endpoints, and other high-value systems.
  • Build complete vulnerability-management loops that move beyond discovery to impact validation, ownership identification, prioritization, remediation support, progress tracking, and fix verification.
  • Design human-in-the-loop systems that allow offensive security engineers to approve or reject potentially dangerous actions, provide missing context, redirect investigations, and steer agents away from unproductive paths.
  • Create feedback mechanisms that allow agents to learn from the decisions, corrections, and domain expertise of experienced offensive security practitioners.
  • Develop rigorous evaluations that measure meaningful security outcomes and improvements in agent capability over time.
  • Build production-quality infrastructure that allows the system to run continuously, recover from failures, remain observable and debuggable, and operate safely against production systems.
  • Investigate failures in agent reasoning and behavior, identify where models are capable or unreliable, and improve the surrounding tools, context, workflows, and guardrails accordingly.
  • Partner closely with offensive security, infrastructure security, product security, codex security, and engineering teams to ensure findings are high signal, understandable, and actionable.
  • Help define the future of offensive security at OpenAI, with the goal of enabling agents to perform most repeatable security testing while human experts focus on automation and high leverage agent-assisted manual review.

You might thrive in this role if:

  • You have substantial hands-on offensive security experience and strong judgment about which vulnerabilities and attack paths are worth pursuing.
  • You have extensive domain expertise in areas such as cloud security , Kubernetes and container security , web application security , source-code review, Linux security, macOS security, or external attack-surface testing. Expertise in cloud , Kubernetes , and modern web applications is especially valuable.
  • You have experience assessing complex, highly customized environments rather than relying primarily on standardized scanners, checklists, or known-vulnerability detection.
  • You can take an ambiguous offensive security problem, decompose it into a reliable system, and encode the reasoning and workflows of an experienced operator into software.
  • You have built production quality software .
  • You have built or meaningfully extended agent systems that use models, tools, structured context, memory, orchestration, and feedback loops to perform complex work.
  • You understand that an impressive agent demonstration is very different from a dependable production system, and you care deeply about evaluations, observability, failure recovery, safety, maintainability, and regression resistance.
  • You have strong intuitions about where current models are capable, where they are unreliable, and how tools, context, scaffolding, and human feedback can expand their useful operating range.
  • You are excited about working closely with frontier models , curious about their emerging capabilities, and constantly look for ways to use them to improve your own workflows.
  • You are energized by the opportunity to serve as a technical owner of an ambitious new system, make foundational architectural decisions, and help grow a team around it.

Bonus points:

  • Background or expertise in AI or data science .
  • Prior experience working in tech startups or fast-paced technology environments.
  • Experience in related disciplines such as Software Engineering , Product Security , Application Security , Detection Engineering , Site Reliability Engineering , Security Engineering , or IT Infrastructure .
Vacancy posted 10 days ago
Similar jobs that could be interesting for youBased on the Staff/Principal Offensive Security Engineer - AI Agents in Remote vacancy
  •  ...We’re seeking an exceptional Staff - Principal level offensive security domain expert to build agents that continuously identify and...  ...security judgment with agent engineering to build a production system that...  ...Background or expertise in AI or data science . Prior experience... 
    Suggested
    Full time

    OpenAI

    Remote
    10 days ago
  •  ...About the Team Security is at the foundation of OpenAI’s mission...  ...re seeking an exceptional Principal-level Offensive Security Engineer focused on deep, hands-on...  ...testing of OpenAI’s agent-powered products, infrastructure...  ...assessing the security of AI-powered systems. ~... 
    Suggested
    Full time

    OpenAI

    Remote
    26 days ago
  • $148.5k - $223.9k

     ...CategoryProductJob DetailsAbout SalesforceSalesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition...  ...future of Salesforce.We are looking for a Senior Offensive Security Engineer (Red Team) with a strong, hands-on attacker mindset... 
    Suggested
    Full time
    Remote work

    Salesforce

    Herndon, VA
    1 day ago
  •  ...Wraithwatch Offensive Security Engineer Wraithwatch was founded by security engineers from SpaceX, Palantir...  ...to build the next generation of AI-powered cyber defense systems for the...  ...utilizing generative artificial intelligence agents to autonomously model a digital twin... 
    Suggested
    Remote work
    Weekend work

    Wraithwatch

    United States
    2 days ago
  •  ...with custom domains, social engineering, lateral movement, privilege...  ...checkbox compliance. Build offensive tooling. Engineer security platforms, scanning pipelines...  ...the team's impact. Weaponize AI for defense. Design and build LLM-powered agents that detect, classify,... 
    Suggested
    Remote work

    CloudWalk

    United States
    5 days ago
  •  ...Senior Offensive Security Engineer (Red Team) Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword — it's a way of life. The world of work as we know it... 
    Remote work

    Salesforce

    United States
    17 hours ago
  • $170k

     ...products for our clients and users. We're looking for an Offensive Security Engineer to think like an attacker and validate the security of...  ...create meaningful business risk—not theoretical findings. AI should be one of your primary tools, enabling you to analyze... 
    Full time
    Summer work
    Work at office
    Immediate start
    Remote work

    Array

    United States
    3 days ago
  • $500 per month

     ...Offensive Security Engineer Netherlands (remote) About ClickHouse Recognized on the 2025 Forbes Cloud 100 list, ClickHouse is one of the...  ...real-time analytics, data warehousing, observability, and AI workloads. The company's sustained, accelerating momentum... 
    Local area
    Remote work
    Home office
    Flexible hours

    ClickHouse

    United States
    17 hours ago
  •  ...To validate the security of products through real-world exploitation, the full-time remote Senior Offensive Security Engineer will identify and demonstrate attack paths against applications and infrastructure, utilizing AI to enhance vulnerability discovery and analysis... 
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    17 hours ago
  • $170k

     ...applications and next steps. Our partner is looking for a Senior Offensive Security Engineer based in the United States. This role offers the...  ...position combines offensive security expertise with modern AI-powered workflows to accelerate research, testing, and exploit... 
    Summer work
    Work at office
    Immediate start
    Remote work

    Jobgether

    United States
    4 days ago
  • $117.6k - $161.7k

     ...Atlanta, Nashville))We're building a new AI & Offensive Tooling capability inside our Offensive Security organization, and we're looking for a senior engineer who can both build it and use it. As...  ...production-quality software and AI agents, LLM-driven planning loops, multi-... 
    Full time
    Temporary work
    Apprenticeship
    Work at office
    Remote work
    Work from home
    Home office

    Humana

    Chicago, IL
    2 days ago
  • $161k - $242k

     ...Category Engineering Hire Type Employee Job ID 17996 Base Salary Range $161000-$242000...  ..., enabling customers to rapidly innovate AI-powered products. We deliver industry-leading...  ...before someone else does. You approach security testing with curiosity and rigor, not just... 
    Permanent employment
    Live in
    Remote work
    Worldwide

    Synopsys Inc

    Austin, TX
    a month ago
  •  ...Job Title: Senior Penetration Tester / Offensive Security Specialist Location: Remote...  ...clear remediation guidance 3. Social Engineering & Human Layer Testing Design and...  ...Python scripting and Linux toolchains AI/GenAI-assisted tooling for attack... 
    Contract work
    Remote work

    VDart

    United States
    16 hours ago
  •  ....   Position Title: Web Developer Security Engineer   Location: US Congressional Budget...  ...APIs, and SQL. Ability to leverage AI-assisted development tools (e.g.,...  ...Certified Application Security Engineer). Offensive Security: OSWE (OffSec Web Expert);... 
    Remote job
    Full time
    Work at office
    Local area

    CMT SERVICES, Inc.

    Remote
    12 hours ago
  •  ...intelligence to power the AI economy. We're a...  ...expertise directly back into agents. Mercor is creating...  ...You'll own application security at a company where the...  ...the easy path for 50+ engineers Threat models for new...  ...HackerOne, Bugcrowd) Offensive security skills - you'... 
    Work at office
    Remote work
    Relocation package
    Shift work

    Mercor Alabaster

    New York, NY
    5 days ago
  • $155.52k - $194.4k

     ...Twilio is in your hands. We use Artificial Intelligence (AI) to help make our hiring process efficient. That said,...  ...See yourself at Twilio Join the team as Twilio’s next Staff Offensive Security Engineer. About the job The Staff Engineer acts as a Technical... 
    Full time
    Local area
    Remote work
    Worldwide

    Twilio

    Remote
    a month ago
  • $85 per hour

     ...Security Engineer (Coding Agent Experience) is a remote engineering review track for evaluating production code, debugging traces, and developer-facing AI outputs against real-world correctness standards. Reviewers reproduce failures, write the unit test the model should... 
    Remote job
    For contractors
    10 hours per week

    AuraOne Human Data

    Remote
    11 days ago
  • $85 per hour

     ...connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors...  ..., Larry Summers , and Jack Dorsey . Position: Security Engineer (Coding Agent Experience) Type: Contract Compensation: $85/hour... 
    Contract work
    Summer work
    Remote work

    Mercor

    San Francisco, CA
    27 days ago
  • $160k - $205k

     ...work with some of the best information security professionals in the world in challenging...  ...Pentester to join a team of world-class offensive security professionals. In this role, you...  ...and experience by mentoring junior engineers, and assist with monitoring and response... 
    Full time
    Work at office
    Remote work
    Shift work
    Day shift

    Bank of America

    Washington DC
    1 day ago
  • $153k - $376k

     ...translating designs into code, or iterating with AI. From idea to product, Figma empowers...  ...design and collaboration, join us!As a Security Engineer you will identify and drive impactful...  ....Help run penetration testing and offensive security exercises against Figma’s AI... 
    Minimum wage
    Full time
    Local area
    Remote work
    Flexible hours

    Figma

    San Francisco, CA
    1 day ago
  •  ...HackerOne Platform unites agentic AI solutions with the ingenuity...  ...world’s largest community of security researchers to continuously...  ...in the security industry. Offensive security is no longer optional...  ...accountability.Senior Security Engineer, Detection and ResponseRemote... 
    Apprenticeship
    Local area
    Remote work
    Flexible hours
    Shift work

    HackerOne

    San Francisco, CA
    12 hours ago
  • Crane Company is seeking an Information Security professional to join its Global Information Security Team. This role involves supporting...  ...of system and network administration. Prior experience in offensive security is required.In this role, the successful candidate will... 
    Full time
    Work experience placement
    Local area
    Remote work

    Crane

    Stamford, CT
    1 day ago
  • $115k - $190k

     ...Web Developer Security Engineer Clearance Requirement: Public Trust (Tier 2) Location: Remote...  .../Scripting: Python, Node.js, Java AI-Assisted Development Tools (e.g.,...  ...Penetration Tester (GWEB), OR CASE Offensive Security (One Required): OSWE, OR... 
    Remote work

    Nationwide IT Services

    Washington DC
    1 day ago
  • About BreachLock BreachLock is a global leader in AI‑powered penetration testing and attack surface management. We help...  ...The Role We're looking for a technically strong Sales Engineer with an offensive security background to join our US sales team. You will be the trusted... 
    Remote job

    BreachLock, Inc.

    Washington DC
    2 hours ago
  •  ...Security Operations Center (SOC) Engineer We are not just another fintech unicorn. We are a pack of...  ...and applications, and help turn offensive security knowledge into real detection...  ...and controls. Use AI as leverage. Build agents and automations for investigation... 
    Remote work

    CloudWalk

    United States
    2 days ago
  •  ...Are you an experienced Senior Offensive Security Engineer that wants to work with cutting-edge cybersecurity technologies and contribute to enhancing our overall security posture? At Ivanti, we work passionately and authentically, striving to win together and make a real... 
    Work at office
    Remote work
    Flexible hours

    Ivanti

    United States
    16 hours ago
  •  ...The role of a Senior Security Engineer in 2026 has evolved from a traditional...  ...expert. With the rise of AI-driven threats and the death...  ...architecture projects, mentoring junior staff, and automating security...  ...standard). - OSCP / OSCE: Offensive Security certifications for... 
    Full time

    Red Cup IT, Inc.

    Remote
    more than 2 months ago
  • $200k - $240k

     ...Liftoff is a leading AI-powered performance marketing platform...  ...presence. The Liftoff Security team protects Liftoff's customers...  ...defend it, and partner with engineering teams as they ship new products...  ...loop between the team's offensive and proactive findings and detection... 
    Full time
    Remote work

    Liftoff Inc

    United States
    3 days ago
  •  ...Seeking a full-time Offensive Security Engineer, this remote position will manage the development of specialized agents to continuously identify and remediate vulnerabilities across OpenAI's infrastructure and applications, ensuring safe and reliable operations at scale... 
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    3 days ago
  •  ...About the role Mission Strengthen Sporty’s offensive security posture by proactively testing and identifying vulnerabilities across our external...  ..., and endpoint defenses. The Offensive Security Engineer owns the security testing, continuous perimeter monitoring,... 
    Full time
    Work at office
    Local area
    Remote work

    Sporty Group

    Remote
    a month ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff/Principal Offensive Security Engineer - AI Agents. Be the first to apply!