Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff/Principal Offensive Security Engineer - AI Agents

Full-time

OpenAI

About the Role

We’re seeking an exceptional Staff - Principal level offensive security domain expert to build agents that continuously identify and coordinate remediation of vulnerabilities across OpenAI’s infrastructure and applications. You will be the technical owner of this effort, combining deep offensive security judgment with agent engineering to build a production system that can operate safely and reliably at scale.

As OpenAI increasingly uses automation throughout the company, we believe our security testing must become increasingly automated as well. Advances in model capabilities create an opportunity to test more of our attack surface than would be possible through human effort alone and a need to ensure that we remain ahead of those same capabilities as they become available to attackers.

In this role, you’ll build a portfolio of specialized agents that develop a deep understanding of OpenAI’s infrastructure, applications, processes, and security boundaries. These agents will combine internal context with feedback from running systems to explore our cloud environments , Kubernetes clusters , web applications , endpoints, external attack surface, and other high-value targets.

The goal is for agents to not only discover vulnerabilities, but also to validate exploitability, document impact, drive remediation, and verify fixes. Success will be measured through outcomes like vulnerabilities fixed, attack surface covered, and performance on evals you’ll build.

These systems will operate continuously and with increasing autonomy, while using carefully designed guardrails and human-in-the-loop controls for dangerous actions. They will also learn from feedback from other domain experts throughout the company.

In this role, you will:

  • Serve as the technical owner of OpenAI’s offensive security agents, establishing its architecture, technical direction, operating model, and evaluation strategy.
  • Design and build a portfolio of specialized agents that continuously test OpenAI’s infrastructure and applications from a variety of authenticated and unauthenticated perspectives.
  • Translate expert offensive security workflows and intuition into tools, skills, harnesses, policies, and internal knowledge bases.
  • Build agents that deeply understand OpenAI’s environment by integrating internal context.
  • Develop capabilities for testing cloud and Kubernetes environments , modern web applications , external attack surface, endpoints, and other high-value systems.
  • Build complete vulnerability-management loops that move beyond discovery to impact validation, ownership identification, prioritization, remediation support, progress tracking, and fix verification.
  • Design human-in-the-loop systems that allow offensive security engineers to approve or reject potentially dangerous actions, provide missing context, redirect investigations, and steer agents away from unproductive paths.
  • Create feedback mechanisms that allow agents to learn from the decisions, corrections, and domain expertise of experienced offensive security practitioners.
  • Develop rigorous evaluations that measure meaningful security outcomes and improvements in agent capability over time.
  • Build production-quality infrastructure that allows the system to run continuously, recover from failures, remain observable and debuggable, and operate safely against production systems.
  • Investigate failures in agent reasoning and behavior, identify where models are capable or unreliable, and improve the surrounding tools, context, workflows, and guardrails accordingly.
  • Partner closely with offensive security, infrastructure security, product security, codex security, and engineering teams to ensure findings are high signal, understandable, and actionable.
  • Help define the future of offensive security at OpenAI, with the goal of enabling agents to perform most repeatable security testing while human experts focus on automation and high leverage agent-assisted manual review.

You might thrive in this role if:

  • You have substantial hands-on offensive security experience and strong judgment about which vulnerabilities and attack paths are worth pursuing.
  • You have extensive domain expertise in areas such as cloud security , Kubernetes and container security , web application security , source-code review, Linux security, macOS security, or external attack-surface testing. Expertise in cloud , Kubernetes , and modern web applications is especially valuable.
  • You have experience assessing complex, highly customized environments rather than relying primarily on standardized scanners, checklists, or known-vulnerability detection.
  • You can take an ambiguous offensive security problem, decompose it into a reliable system, and encode the reasoning and workflows of an experienced operator into software.
  • You have built production quality software .
  • You have built or meaningfully extended agent systems that use models, tools, structured context, memory, orchestration, and feedback loops to perform complex work.
  • You understand that an impressive agent demonstration is very different from a dependable production system, and you care deeply about evaluations, observability, failure recovery, safety, maintainability, and regression resistance.
  • You have strong intuitions about where current models are capable, where they are unreliable, and how tools, context, scaffolding, and human feedback can expand their useful operating range.
  • You are excited about working closely with frontier models , curious about their emerging capabilities, and constantly look for ways to use them to improve your own workflows.
  • You are energized by the opportunity to serve as a technical owner of an ambitious new system, make foundational architectural decisions, and help grow a team around it.

Bonus points:

  • Background or expertise in AI or data science .
  • Prior experience working in tech startups or fast-paced technology environments.
  • Experience in related disciplines such as Software Engineering , Product Security , Application Security , Detection Engineering , Site Reliability Engineering , Security Engineering , or IT Infrastructure .
Vacancy posted a month ago
Similar jobs that could be interesting for youBased on the Staff/Principal Offensive Security Engineer - AI Agents in Remote vacancy
  •  ...We’re seeking an exceptional Staff - Principal level offensive security domain expert to build agents that continuously identify and...  ...security judgment with agent engineering to build a production system that...  ...Background or expertise in AI or data science . Prior experience... 
    Suggested
    Full time

    OpenAI

    Remote
    a month ago
  •  ...About the Team Security is at the foundation of OpenAI’s mission...  ...re seeking an exceptional Principal-level Offensive Security Engineer focused on deep, hands-on...  ...testing of OpenAI’s agent-powered products, infrastructure...  ...assessing the security of AI-powered systems. ~... 
    Suggested
    Full time

    OpenAI

    Remote
    17 days ago
  • $148.5k - $223.9k

     ...CategoryProductJob DetailsAbout SalesforceSalesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition...  ...future of Salesforce.We are looking for a Senior Offensive Security Engineer (Red Team) with a strong, hands-on attacker mindset... 
    Suggested
    Full time
    Remote work

    Salesforce

    Maryland
    4 days ago
  • $224k - $356.5k

    NVIDIA's Product Security organization is looking for a Senior Offensive Security Engineer to push the frontier of AI-driven offensive security. We already run language model agents that audit source code and attack live web applications at fleet scale. These include multi... 
    Suggested
    Full time
    Remote work

    Nvidia

    Austin, TX
    3 days ago
  • $165k - $200k

    Atlanta (Remote Friendly)Security /Full Time /RemoteGreenlight is a family technology...  ...morning.Greenlight is looking for a Staff Offensive Security Engineer for our Security team. This...  ...We may use artificial intelligence (AI) tools to support parts of the hiring... 
    Suggested
    Full time
    Work at office
    Local area
    Remote work
    Work from home
    Day shift

    Greenlight Financial Technology

    Atlanta, GA
    5 hours ago
  •  ...Seeking a full-time Senior Offensive Security Engineer focused on enhancing AI-driven offensive security, this remote position will manage the development of autonomous red team agents, improve existing agent capabilities, and mentor team members in advanced offensive... 
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    4 days ago
  •  ...with custom domains, social engineering, lateral movement, privilege...  ...checkbox compliance. Build offensive tooling. Engineer security platforms, scanning pipelines...  ...the team's impact. Weaponize AI for defense. Design and build LLM-powered agents that detect, classify,... 
    Remote work

    CloudWalk

    United States
    3 days ago
  • $170k

     ...products for our clients and users. We're looking for an Offensive Security Engineer to think like an attacker and validate the security of...  ...create meaningful business risk—not theoretical findings. AI should be one of your primary tools, enabling you to analyze... 
    Full time
    Summer work
    Work at office
    Immediate start
    Remote work

    Array

    Canada
    2 days ago
  •  ...About the Team The team’s mission is to accelerate the secure evolution of agentic AI systems at OpenAI. To achieve this, the team designs,...  ...by agentic AI. About the Role As a Security Engineer on the Agent Security Team , you will be at the forefront of securing... 
    Full time
    Remote work

    OpenAI

    Remote
    12 days ago
  • $161k - $242k

     ...Category Engineering Hire Type Employee Job ID 17996 Base Salary Range $161000-$242000...  ..., enabling customers to rapidly innovate AI-powered products. We deliver industry-leading...  ...before someone else does. You approach security testing with curiosity and rigor, not just... 
    Permanent employment
    Live in
    Remote work
    Worldwide

    Synopsys Inc

    Austin, TX
    more than 2 months ago
  • Crane Company is seeking an Information Security professional to join its Global Information Security Team. This role involves supporting...  ...of system and network administration. Prior experience in offensive security is required.In this role, the successful candidate will... 
    Full time
    Work experience placement
    Local area
    Remote work

    Crane

    Stamford, CT
    4 days ago
  • $153k - $376k

     ...translating designs into code, or iterating with AI. From idea to product, Figma empowers...  ...design and collaboration, join us!As a Security Engineer you will identify and drive impactful...  ....Help run penetration testing and offensive security exercises against Figma’s AI... 
    Minimum wage
    Full time
    Local area
    Remote work
    Flexible hours

    Figma

    New York, NY
    4 days ago
  • $160k - $205k

     ...work with some of the best information security professionals in the world in challenging...  ...Pentester to join a team of world-class offensive security professionals. In this role, you...  ...and experience by mentoring junior engineers, and assist with monitoring and response... 
    Full time
    Work at office
    Remote work
    Shift work
    Day shift

    Bank of America

    Jacksonville, FL
    4 days ago
  •  ...HackerOne Platform unites agentic AI solutions with the ingenuity...  ...world’s largest community of security researchers to continuously...  ...in the security industry. Offensive security is no longer optional...  ...accountability.Senior Security Engineer, Detection and ResponseRemote... 
    Apprenticeship
    Local area
    Remote work
    Flexible hours
    Shift work

    HackerOne

    San Francisco, CA
    3 days ago
  • $139.3k - $203.6k

     ...the Team The Application Security team is a high-impact...  ...that balances rigorous offensive security methodologies with cutting-edge AI-driven automation. We are...  ...alongside autonomous agents to outpace emerging threats...  ...relationships with engineering teams to drive long-term... 
    Full time
    Temporary work
    Local area
    Remote work
    Flexible hours

    CISCO Systems

    Austin, TX
    1 day ago
  • $145k - $200k

    Washington, D.C.Information Security /Full-time /HybridA World-Changing CompanyPalantir builds...  ...children, and more.The RolePalantir's Offensive Security team probes our own products,...  ...would. As an Offensive Security Engineer, you will test internal applications and... 
    Full time
    Work experience placement
    Work at office
    Remote work
    Work from home
    Relocation package

    Palantir Technologies

    Washington DC
    3 days ago
  • $85 per hour

     ...Security Engineer (Coding Agent Experience) is a remote engineering review track for evaluating production code, debugging traces, and developer-facing AI outputs against real-world correctness standards. Reviewers reproduce failures, write the unit test the model should... 
    Remote job
    For contractors
    10 hours per week

    AuraOne Human Data

    Remote
    a month ago
  • $115k - $190k

     ...Description Job Description Web Developer Security Engineer Clearance Requirement: Public Trust...  .../Scripting: Python, Node.js, Java AI-Assisted Development Tools (e.g.,...  ...Penetration Tester (GWEB), OR CASE Offensive Security (One Required): OSWE, OR... 
    Remote work

    Nationwide IT Services

    Washington DC
    12 days ago
  • $131.3k - $237.35k

     ...Our team of hackers and engineers have experience...  ...We are looking for a Security Engineer to own the security...  ..., and deliver advanced AI-cyber capabilities. You...  ...cross-domain solutions Offensive security background - penetration...  ...required Non-human/agent identity and secrets... 
    Local area
    Immediate start
    Remote work

    Leidos

    Boulder, CO
    4 days ago
  •  ...Senior Offensive Security Engineer - Pentester Denver, Colorado;Washington, District of Columbia; Seattle, Washington; Charlotte, North Carolina; Jacksonville, Florida; Jersey City, New Jersey; Chicago, Illinois To proceed with your application, you must be at least... 
    Work at office
    Remote work
    Shift work
    Day shift

    Bank of America

    Washington DC
    5 days ago
  • $122.25k - $130k

     ...Fullsteam Corporate on security initiatives and response...  ..., software, AI systems, and external attack...  ...with Security, IT, and BU Engineering teams to drive effective...  ...workflows (prompt engineering, agent development, MCP...  ...Hands-on Defensive or Offensive security training or work... 
    Work experience placement
    Local area
    Remote work

    Fullsteam Operations LLC

    United States
    5 days ago
  • $200k - $240k

     ...Security Engineer, Detection & Response United States (Remote) Liftoff is a leading AI-powered performance marketing platform for the mobile app economy. Our end-to-end...  ...Close the feedback loop between the team's offensive and proactive findings and detection... 
    Full time
    Remote work

    Liftoff Inc

    United States
    1 day ago
  • $118k - $135k

     ...Opportunity As a Security Engineer - Application Security...  ..., integrations, AI-enabled technologies,...  ...Access policies, service principals, application registrations...  .... Familiarity with offensive security and...  ...firm. Our professional staff are a collaborative team... 
    Local area
    Remote work
    Worldwide

    Seyfarth Shaw

    Atlanta, GA
    4 days ago
  •  ...Security Engineer Tempo is a layer-1 blockchain purpose-built for stablecoins and real-world...  ...design partners who are global leaders in AI, e-commerce, and financial services:...  ...precompiles. Proven track record of offensive security, such as high rankings in CTFs... 
    Full time
    Remote work

    Tempo LLC

    United States
    4 days ago
  • About BreachLock BreachLock is a global leader in AI‑powered penetration testing and attack surface management. We help...  ...The Role We're looking for a technically strong Sales Engineer with an offensive security background to join our US sales team. You will be the trusted... 
    Remote job

    BreachLock, Inc.

    Washington DC
    2 days ago
  • Washington DCTechnology - Security /RemoteThe Senior Security Engineer II will be responsible for designing, implementing, and maintaining security services...  ...such as API Security, WAF, etc.In-depth knowledge of AI/LLM and machine learning architectures and best practices... 
    Temporary work
    Work at office
    Remote work
    Work from home
    Flexible hours

    Aledade

    Washington DC
    4 days ago
  • $81k - $155k

     ...#VTeamLife.What you’ll be doing...The GN&T Network Security team is looking for a highly motivated and experienced Engineer to join the Network Security Defense team. The...  ..., lookups, and dashboards for threat analysis.AI Tooling: Experience utilizing Claude Code or other... 
    Full time
    Temporary work
    Part time
    Work experience placement
    Work at office
    Work from home
    Flexible hours
    Shift work
    3 days per week

    Verizon

    New Jersey
    4 days ago
  •  ...re Oscar. We're hiring a Senior Product Security Engineer 1 to join our Security Team.Oscar is the...  ...traditional application security and modern AI-driven engineering, ensuring that our "...  ...integrating security reviews into AI agent processes that bypass traditional ticketing... 
    Full time
    Work experience placement
    Work at office
    Remote work

    Oscar Health Insurance

    San Francisco, CA
    2 days ago
  • $165k - $242k

    CoreWeave is The Essential Cloud for AI. Built for pioneers by pioneers, CoreWeave delivers...  ...more at .What You’ll Do:The Enterprise Security team at CoreWeave is responsible for...  ...join.About the Role:As a Senior Security Engineer, Enterprise Security, you’ll design and ship... 
    Permanent employment
    Full time
    Temporary work
    For contractors
    Casual work
    Work at office
    Remote work
    Flexible hours

    CoreWeave

    New York, NY
    4 days ago
  •  ...About the role Mission Strengthen Sporty’s offensive security posture by proactively testing and identifying vulnerabilities across our external...  ..., and endpoint defenses. The Offensive Security Engineer owns the security testing, continuous perimeter monitoring,... 
    Full time
    Work at office
    Local area
    Remote work

    Sporty Group

    Remote
    more than 2 months ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff/Principal Offensive Security Engineer - AI Agents. Be the first to apply!