Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Offensive Security Agent Engineer

Full-time

OpenAI

About the Team

Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.

About the Role

We’re seeking an exceptional Staff - Principal level offensive security domain expert to build agents that continuously identify and coordinate remediation of vulnerabilities across OpenAI’s infrastructure and applications. You will be the technical owner of this effort, combining deep offensive security judgment with agent engineering to build a production system that can operate safely and reliably at scale.

As OpenAI increasingly uses automation throughout the company, we believe our security testing must become increasingly automated as well. Advances in model capabilities create an opportunity to test more of our attack surface than would be possible through human effort alone and a need to ensure that we remain ahead of those same capabilities as they become available to attackers.

In this role, you’ll build a portfolio of specialized agents that develop a deep understanding of OpenAI’s infrastructure, applications, processes, and security boundaries. These agents will combine internal context with feedback from running systems to explore our cloud environments, Kubernetes clusters, web applications, endpoints, external attack surface, and other high-value targets.

The goal is for agents to not only discover vulnerabilities, but also to validate exploitability, document impact, drive remediation, and verify fixes. Success will be measured through outcomes like vulnerabilities fixed, attack surface covered, and performance on evals you’ll build.

These systems will operate continuously and with increasing autonomy, while using carefully designed guardrails and human-in-the-loop controls for dangerous actions. They will also learn from feedback from other domain experts throughout the company.

In this role, you will:

  • Serve as the technical owner of OpenAI’s offensive security agents, establishing its architecture, technical direction, operating model, and evaluation strategy.

  • Design and build a portfolio of specialized agents that continuously test OpenAI’s infrastructure and applications from a variety of authenticated and unauthenticated perspectives.

  • Translate expert offensive security workflows and intuition into tools, skills, harnesses, policies, and internal knowledge bases.

  • Build agents that deeply understand OpenAI’s environment by integrating internal context.

  • Develop capabilities for testing cloud and Kubernetes environments, modern web applications, external attack surface, endpoints, and other high-value systems.

  • Build complete vulnerability-management loops that move beyond discovery to impact validation, ownership identification, prioritization, remediation support, progress tracking, and fix verification.

  • Design human-in-the-loop systems that allow offensive security engineers to approve or reject potentially dangerous actions, provide missing context, redirect investigations, and steer agents away from unproductive paths.

  • Create feedback mechanisms that allow agents to learn from the decisions, corrections, and domain expertise of experienced offensive security practitioners.

  • Develop rigorous evaluations that measure meaningful security outcomes and improvements in agent capability over time.

  • Build production-quality infrastructure that allows the system to run continuously, recover from failures, remain observable and debuggable, and operate safely against production systems.

  • Investigate failures in agent reasoning and behavior, identify where models are capable or unreliable, and improve the surrounding tools, context, workflows, and guardrails accordingly.

  • Partner closely with offensive security, infrastructure security, product security, codex security, and engineering teams to ensure findings are high signal, understandable, and actionable.

  • Help define the future of offensive security at OpenAI, with the goal of enabling agents to perform most repeatable security testing while human experts focus on automation and high leverage agent-assisted manual review.

You might thrive in this role if:

  • You have substantial hands-on offensive security experience and strong judgment about which vulnerabilities and attack paths are worth pursuing.

  • You have extensive domain expertise in areas such as cloud security, Kubernetes and container security, web application security, source-code review, Linux security, macOS security, or external attack-surface testing. Expertise in cloud, Kubernetes, and modern web applications is especially valuable.

  • You have experience assessing complex, highly customized environments rather than relying primarily on standardized scanners, checklists, or known-vulnerability detection.

  • You can take an ambiguous offensive security problem, decompose it into a reliable system, and encode the reasoning and workflows of an experienced operator into software.

  • You have built production quality software

  • You have built or meaningfully extended agent systems that use models, tools, structured context, memory, orchestration, and feedback loops to perform complex work.

  • You understand that an impressive agent demonstration is very different from a dependable production system, and you care deeply about evaluations, observability, failure recovery, safety, maintainability, and regression resistance.

  • You have strong intuitions about where current models are capable, where they are unreliable, and how tools, context, scaffolding, and human feedback can expand their useful operating range.

  • You are excited about working closely with frontier models, curious about their emerging capabilities, and constantly look for ways to use them to improve your own workflows.

  • You are energized by the opportunity to serve as a technical owner of an ambitious new system, make foundational architectural decisions, and help grow a team around it.

Bonus points:

  • Background or expertise in AI or data science.

  • Prior experience working in tech startups or fast-paced technology environments.

  • Experience in related disciplines such as Software Engineering, Product Security, Application Security, Detection Engineering, Site Reliability Engineering, Security Engineering, or IT Infrastructure.

About OpenAI

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity. 

We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.

For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement .

Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.

To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form . No response will be provided to inquiries unrelated to job posting compliance.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link .

At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

Vacancy posted 11 days ago
Similar jobs that could be interesting for youBased on the Offensive Security Agent Engineer in Remote vacancy
  •  ...’re seeking an exceptional Staff - Principal level offensive security domain expert to build agents that continuously identify and coordinate remediation...  ...deep offensive security judgment with agent engineering to build a production system that can operate safely... 
    Suggested
    Full time

    OpenAI

    Remote
    a month ago
  • $160k - $205k

     ...work with some of the best information security professionals in the world in challenging...  ...Pentester to join a team of world-class offensive security professionals. In this role, you...  ...and experience by mentoring junior engineers, and assist with monitoring and response... 
    Suggested
    Full time
    Work at office
    Remote work
    Shift work
    Day shift

    Bank of America

    Denver, CO
    4 days ago
  • $148.5k - $223.9k

     ...SalesforceSalesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action...  ...are the future of Salesforce.We are looking for a Senior Offensive Security Engineer (Red Team) with a strong, hands-on attacker mindset to execute... 
    Suggested
    Full time
    Remote work

    Salesforce

    Herndon, VA
    4 days ago
  • $145k - $200k

    Washington, D.C.Information Security /Full-time /HybridA World-Changing CompanyPalantir builds...  ...children, and more.The RolePalantir's Offensive Security team probes our own products,...  ...would. As an Offensive Security Engineer, you will test internal applications and... 
    Suggested
    Full time
    Work experience placement
    Work at office
    Remote work
    Work from home
    Relocation package

    Palantir Technologies

    Washington DC
    3 days ago
  • $224k - $356.5k

    NVIDIA's Product Security organization is looking for a Senior Offensive Security Engineer to push the frontier of AI-driven offensive security. We already run language model agents that audit source code and attack live web applications at fleet scale. These include multi... 
    Suggested
    Full time
    Remote work

    Nvidia

    Durham, NC
    3 days ago
  • Crane Company is seeking an Information Security professional to join its Global Information Security Team. This role involves supporting...  ...of system and network administration. Prior experience in offensive security is required.In this role, the successful candidate will... 
    Full time
    Work experience placement
    Local area
    Remote work

    Crane

    Stamford, CT
    4 days ago
  •  ...Seeking a full-time Senior Offensive Security Engineer focused on enhancing AI-driven offensive security, this remote position will manage the development of autonomous red team agents, improve existing agent capabilities, and mentor team members in advanced offensive... 
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    4 days ago
  • $165k - $200k

    Atlanta (Remote Friendly)Security /Full Time /RemoteGreenlight is a family technology company on a mission to help families raise...  ...of bed every morning.Greenlight is looking for a Staff Offensive Security Engineer for our Security team. This individual will be responsible... 
    Full time
    Work at office
    Local area
    Remote work
    Work from home
    Day shift

    Greenlight Financial Technology

    Atlanta, GA
    13 hours ago
  •  ...Senior Offensive Security Engineer - Pentester Denver, Colorado;Washington, District of Columbia; Seattle, Washington; Charlotte, North Carolina; Jacksonville, Florida; Jersey City, New Jersey; Chicago, Illinois To proceed with your application, you must be at least... 
    Work at office
    Remote work
    Shift work
    Day shift

    Bank of America

    Seattle, WA
    5 days ago
  •  ...phishing with custom domains, social engineering, lateral movement, privilege...  ...resilience, not checkbox compliance. Build offensive tooling. Engineer security platforms, scanning pipelines, and...  .... Design and build LLM-powered agents that detect, classify, triage and fix... 
    Remote work

    CloudWalk

    United States
    3 days ago
  •  ...About the role Mission Strengthen Sporty’s offensive security posture by proactively testing and identifying vulnerabilities across our external...  ..., and endpoint defenses. The Offensive Security Engineer owns the security testing, continuous perimeter monitoring,... 
    Full time
    Work at office
    Local area
    Remote work

    Sporty Group

    Remote
    more than 2 months ago
  • $170k

     ...experiment empower us individually and together deliver the best products for our clients and users. We're looking for an Offensive Security Engineer to think like an attacker and validate the security of Array's products through real-world exploitation. You’re a paid... 
    Full time
    Summer work
    Work at office
    Immediate start
    Remote work

    Array

    Canada
    2 days ago
  • A cybersecurity company is seeking a Solutions Engineer to enhance engagement with clients and drive revenue through specialized knowledge of offensive security solutions. The role involves understanding competitive landscapes, assisting with customer success, and representing... 
    Remote job
    Flexible hours

    Sprocket Security

    Chicago, IL
    4 days ago
  •  ...About the Team The team’s mission is to accelerate the secure evolution of agentic AI systems at OpenAI. To achieve this, the...  ...introduced by agentic AI. About the Role As a Security Engineer on the Agent Security Team , you will be at the forefront of securing OpenAI... 
    Full time
    Remote work

    OpenAI

    Remote
    12 days ago
  • $161k - $242k

     ...Category Engineering Hire Type Employee Job ID 17996 Base Salary Range $161000-$242000 Remote Eligible No Date Posted 07.16.20...  ...finding those weak points before someone else does. You approach security testing with curiosity and rigor, not just running scans but... 
    Permanent employment
    Live in
    Remote work
    Worldwide

    Synopsys Inc

    Austin, TX
    more than 2 months ago
  • $165.2k - $265.5k

     ...connected devices. The Samsara Application Security team protects this vast footprint end-to...  .... As a Staff Application Security Engineer, you’ll drive the overarching technical...  ..., extending, or wiring up AI copilots/agents for security workflows (e.g., automated... 
    Full time
    Remote work
    Relocation package
    Flexible hours
    Shift work

    Samsara

    Remote
    3 days ago
  • $165.2k - $265.5k

     ...vulnerability management and other application security programs. Own efforts to reduce mean...  ...Drive remediation by partnering with engineering teams and providing actionable security...  ...building or integrating AI copilots or agents for security workflows is preferred. ~... 
    Full time
    Remote work
    Relocation
    Flexible hours

    Samsara

    Remote
    2 days ago
  • $150k - $165k

     ...DoW) Red Teams certified by the National Security Agency (NSA) and accredited by United...  ...The Red Team conducts full-spectrum offensive operations to assess and improve the security...  .... ● Collaborate with defensive and engineering teams to improve detection and response... 
    Full time
    Contract work
    Immediate start
    Remote work
    Relocation package
    Monday to Friday
    Shift work
    Day shift

    Resource Management Concepts, Inc.

    Quantico, VA
    4 days ago
  • Job DescriptionThe RoleThe Staff Product Cybersecurity Engineer, Offensive Product Security role sits within the broader Product Cybersecurity organization at General Motors and focuses on offensive security services that help strengthen confidence in the security of our... 
    Full time
    Local area
    Work from home
    Relocation package

    General Motors

    Milford, MI
    4 days ago
  • $139.3k - $203.6k

     ...Meet the Team The Application Security team is a high-impact group...  ...team that balances rigorous offensive security methodologies with cutting...  ...alongside autonomous agents to outpace emerging threats....  ...functional relationships with engineering teams to drive long-term security... 
    Full time
    Temporary work
    Local area
    Remote work
    Flexible hours

    CISCO Systems

    Boulder, CO
    1 day ago
  • $135k - $200k

    Palo Alto, CAInformation Security /Full-time /HybridA World-Changing...  ...a Senior Identity Security Engineer on Palantir's Identity Security...  ...primitives including agent identity, JIT-native governance...  ...identity telemetryRed team, offensive security, or incident response... 
    Full time
    Work experience placement
    Work at office
    Remote work
    Work from home
    Relocation package
    Shift work

    Palantir Technologies

    Palo Alto, CA
    1 day ago
  • $153k - $376k

     ...shape the future of design and collaboration, join us!As a Security Engineer you will identify and drive impactful projects to improve the...  ...insights and security tooling.Help run penetration testing and offensive security exercises against Figma’s AI infrastructure,... 
    Minimum wage
    Full time
    Local area
    Remote work
    Flexible hours

    Figma

    New York, NY
    4 days ago
  •  ...ingenuity of the world’s largest community of security researchers to continuously discover,...  ...point in the security industry. Offensive security is no longer optional - it is the...  ...respect, and accountability.Senior Security Engineer, Detection and ResponseRemote Location:... 
    Apprenticeship
    Local area
    Remote work
    Flexible hours
    Shift work

    HackerOne

    San Francisco, CA
    3 days ago
  •  ...reduce risk by tightly integrating MDR with offensive security, threat hunting, security research, and...  ...is seeking an Associate Security Engineer to join our Security Control Management...  ..., investigate platform health and agent issues, and document work clearly. You... 
    Temporary work
    Local area
    Remote work
    Flexible hours

    CYBERMAXX, LLC

    Linthicum Heights, MD
    9 days ago
  • $145k - $200k

    Washington, D.C.Information Security /Full-time /HybridA World-Changing CompanyPalantir builds...  ...Kerberos ticket anomalies, or reverse-engineered a novel persistence mechanism in a...  ...in adversary simulation, red teaming, or offensive security research — especially against AD... 
    Full time
    Work experience placement
    Work at office
    Remote work
    Work from home
    Relocation package

    Palantir Technologies

    Washington DC
    4 days ago
  • $85 per hour

     ...Security Engineer (Coding Agent Experience) is a remote engineering review track for evaluating production code, debugging traces, and developer-facing AI outputs against real-world correctness standards. Reviewers reproduce failures, write the unit test the model should... 
    Remote job
    For contractors
    10 hours per week

    AuraOne Human Data

    Remote
    a month ago
  • $122.25k - $130k

     ...Units and Fullsteam Corporate on security initiatives and response....  ...Collaborate with Security, IT, and BU Engineering teams to drive effective and...  ...(prompt engineering, agent development, MCP tooling)...  ...~ Hands-on Defensive or Offensive security training or work experience... 
    Work experience placement
    Local area
    Remote work

    Fullsteam Operations LLC

    United States
    5 days ago
  • $118k - $135k

     ...in your future, keep reading. The Opportunity As a Security Engineer - Application Security & Technology Risk , you will help evaluate...  ...signing, and vendor compromise. Familiarity with offensive security and penetration testing methodologies and the ability... 
    Local area
    Remote work
    Worldwide

    Seyfarth Shaw

    Atlanta, GA
    4 days ago
  •  ...Security Engineer Tempo is a layer-1 blockchain purpose-built for stablecoins and real-world payments, born from Stripe's experience in...  ...slots, gas metering, and precompiles. Proven track record of offensive security, such as high rankings in CTFs (e.g., Paradigm CTF)... 
    Full time
    Remote work

    Tempo LLC

    United States
    4 days ago
  • $147.25k - $193.75k

     ...Denver, Leeds and Dublin. This role is remote. As a Security Engineer IIIat Fanatics Betting & Gaming (FBG), your knowledge and...  .... Proficient in purple team operations with expertise in offensive and defensive strategy. Experience with identity management... 
    Full time
    Seasonal work
    Remote work

    Fanatics

    New York, NY
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Offensive Security Agent Engineer. Be the first to apply!