Offensive Security Engineer, Agent Products
OpenAI
About the Team
Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.
About the Role
We’re seeking an exceptional Principal-level Offensive Security Engineer focused on deep, hands-on penetration testing of OpenAI’s agent-powered products, infrastructure, and model-integrated application surfaces. You’ll assess complex systems end to end, identify realistic vulnerabilities, validate exploitability and impact, and partner closely with engineering teams to drive durable fixes.
This role will be primarily focused on continuously testing our agent-powered products like Codex and Operator. These systems are uniquely valuable targets because they’re rapidly evolving, can perform sensitive actions on behalf of users, and have large, diverse attack surfaces. You will play a crucial role in securing our agents by finding vulnerabilities that emerge from the interactions between the applications, infrastructure, tools, and models that power them.
You’ll have the chance to not only find vulnerabilities, but actively drive their resolution, build reusable testing approaches, automate offensive security workflows with cutting-edge technologies, and use your attacker perspective to improve the security of OpenAI’s products.
In this role you will:
Conduct deep penetration tests of OpenAI’s agent-powered products, including web applications, APIs, cloud services, identity and authorization flows, CI/CD systems, and model-integrated product surfaces.
Continuously hunt for exploitable vulnerabilities in the interactions between the applications, infrastructure, tools, and models that power our agentic products.
Perform code review, architecture review, and hands-on exploitation to validate risk and identify subtle or novel failure modes.
Produce clear, actionable findings with reproduction steps, exploitability analysis, impact assessment, and practical remediation guidance.
Partner directly with engineering teams to drive fixes, validate remediation, and improve secure design patterns across agentic products.
Build tools, test harnesses, and automation to scale penetration testing across rapidly evolving product surfaces.
Leverage advanced automation and OpenAI technologies to optimize your offensive security work.
Share attacker-informed insights with security and engineering teams to improve threat models, mitigations, and defensive coverage.
You might thrive in this role if you have:
7+ years of hands-on penetration testing, product security assessment, application security, cloud security assessment, or equivalent offensive security experience.
Deep expertise finding, exploiting, documenting, and helping remediate vulnerabilities in complex production systems.
Experience performing offensive security assessments of modern technology products, including web applications, APIs, cloud infrastructure, identity systems, CI/CD pipelines, and distributed services.
Experience designing, developing, or assessing the security of AI-powered systems.
Experience finding, exploiting, and mitigating common vulnerabilities in AI systems, including prompt injection, confused deputies, unsafe tool use, and dynamically generated UI components.
Exceptional skill in code review to identify novel and subtle vulnerabilities.
Proven experience performing offensive security assessments in at least one hyperscaler cloud environment. Azure experience is preferred.
Demonstrated mastery assessing complex technology stacks, including:
Highly customized Kubernetes clusters
Container environments
CI/CD pipelines
GitHub security
macOS and Linux operating systems
Data science tooling and environments
Python-based web services
React-based frontend applications
Strong intuitive understanding of trust boundaries and risk assessment in dynamic contexts.
Excellent coding skills, capable of writing robust tools and automation for offensive security testing.
Ability to communicate complex technical concepts effectively through clear reports, practical remediation guidance, and compelling technical storytelling.
Proven track record of not just finding vulnerabilities, but actively contributing to solutions in complex codebases.
Bonus points:
Background or expertise in AI or data science.
Prior experience working in tech startups or fast-paced technology environments.
Experience in related disciplines such as Software Engineering, Product Security, Application Security, Detection Engineering, Site Reliability Engineering, Security Engineering, or IT Infrastructure.
About OpenAI
OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.
We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.
For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement .
Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.
To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form . No response will be provided to inquiries unrelated to job posting compliance.
We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link .
At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.
- ...seeking an exceptional Staff - Principal level offensive security domain expert to build agents that continuously identify and coordinate... ...combining deep offensive security judgment with agent engineering to build a production system that can operate safely and reliably at...SuggestedFull time
- ...seeking an exceptional Staff - Principal level offensive security domain expert to build agents that continuously identify and coordinate... ...combining deep offensive security judgment with agent engineering to build a production system that can operate safely and reliably at...SuggestedFull time
- Job DescriptionThe RoleThe Staff Product Cybersecurity Engineer, Offensive Product Security role sits within the broader Product Cybersecurity organization at General Motors and focuses on offensive security services that help strengthen confidence in the security of our...SuggestedFull timeLocal areaWork from homeRelocation package
$148.5k - $223.9k
...is the #1 AI CRM, where humans with agents drive customer success together. Here... ...Salesforce.We are looking for a Senior Offensive Security Engineer (Red Team) with a strong, hands-on... ...offensive security operations across our products, platforms, and enterprise...SuggestedFull timeRemote work- Crane Company is seeking an Information Security professional to join its Global Information... ...administration. Prior experience in offensive security is required.In this role, the successful... ...and team members accountableConduct production-safe exploitation of suspected software...SuggestedFull timeWork experience placementLocal areaRemote work
- ...Are you an experienced Senior Offensive Security Engineer that wants to work with cutting-edge cybersecurity technologies and contribute to enhancing... ..., including development teams, IT operations, and product managers, to ensure timely resolution of identified security...Work at officeRemote workFlexible hours
$170k
...applications and next steps. Our partner is looking for a Senior Offensive Security Engineer based in the United States. This role offers the opportunity to operate at the forefront of application and product security within a fast-growing technology environment....Summer workWork at officeImmediate startRemote work$500 per month
...Offensive Security Engineer Netherlands (remote) About ClickHouse Recognized on the 2025 Forbes Cloud 100 list, ClickHouse is one of the... ...and tooling, with focus on supporting our engineering and product teams in improving the security posture of our platforms...Local areaRemote workHome officeFlexible hours$181k
...About the role We are seeking a Senior Security Engineer to build and lead our Offensive Security program. In this role, you will attack Chime's services... ...red team exercises. Partner with Engineering, Product, IT, and other business functions to drive security improvement...Full timeWork at officeLocal areaRemote work- ...Seeking a full-time Offensive Security Engineer, this remote position will manage the development of specialized agents to continuously identify and remediate vulnerabilities across... ...checklists Proficiency in building production-quality software and agent systems with...Full timeRemote work
- ...Wraithwatch Offensive Security Engineer Wraithwatch was founded by security engineers from SpaceX, Palantir... ...technology companies. Our core product is a cyber defense platform utilizing generative artificial intelligence agents to autonomously model a digital twin of...Remote workWeekend work
- ...Senior Offensive Security Engineer (Red Team) Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust... ...offensive security operations across our products, platforms, and enterprise environment....Remote work
$170k
...financial institutions, and fintechs get compelling consumer products to market faster. We deliver a suite of credit and... ...products for our clients and users. We're looking for an Offensive Security Engineer to think like an attacker and validate the security of Array...Full timeSummer workWork at officeImmediate startRemote work- ...To validate the security of products through real-world exploitation, the full-time remote Senior Offensive Security Engineer will identify and demonstrate attack paths against applications and infrastructure, utilizing AI to enhance vulnerability discovery and analysis...Full timeRemote work
$122.8k - $184.2k
...impact every day at Zebra.What We're Looking For:Advanced Product Security Engineer for the Print and Encode business unit, reporting to the Director... ...security certifications (e.g., CISSP, CSSLP, GSEC, or offensive security certifications).Strong communication skills with...Full timeSummer workWork at officeLocal areaFlexible hours$110.93k - $184.88k
...The Product Security Engineer is responsible for conducting comprehensive security assessments on various products, including mobile applications... ...teams to enhance security. The engineer will use both offensive and defensive security tactics to safeguard products and manage...Temporary workWork experience placementLocal areaRemote workRelocation packageFlexible hours- ...Senior Product Security Engineer Hybrid At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one... ...initiatives without explicit authority. Bonus points: Offensive Mastery: Familiarity with offensive security tooling and...Local areaFlexible hours
$137.86k - $250k
...abundance for all. About the Team The Security Engineering team is responsible for protecting our... ...humanoid robotics systems. The Product Security team focuses on the end-to-... ...of experience in product security, offensive security, or a closely related engineering...Temporary workLocal areaRemote workWork from homeFlexible hours- ...; and dramatic increases in productivity. Leading organizations including... ..., The United States Social Security Administration, The United... ...a Senior Product Security Engineer, you will be the cornerstone... ...assurance program. Offensive Security Skills: Show a practical...Remote workWork from homeFlexible hours
$165k - $225k
...IT Team The Application Security team helps Affirm build and launch products that earn customer trust, meet compliance... ...partner closely with product, engineering, infrastructure, risk,... ...about code, is actively developing offensive security skills, and wants to apply...Full timeInternshipWork at officeRemote workFlexible hours- ...Senior Product Security Engineer United Kingdom - Remote Chainguard is the trusted source for... ...open source software engineers and AI agents rely on, Chainguard helps organizations... ...Background in security research or offensive security (bug bounty, CTF, penetration...Local areaRemote workFlexible hours
- ...Staff Product Security Engineer Product Security at Chainalysis keeps our SaaS platform — used by governments, banks, and crypto exchanges to... ...review and guardrails for internal AI platforms and coding agents (LLM gateways, prompt/response controls, agent permissioning...Remote work
$201.3k - $352.3k
Company DescriptionIt all started when engineer Fred Luddy wrote code that automated a tedious... ...people.Job DescriptionThe ServiceNow Security Organization (SSO) The ServiceNow... ...role ServiceNow seeks a senior staff-level product security engineer to serve as a senior technical...Work at officeImmediate startRemote workFlexible hours- ...Staff Product Security Engineer Canada - Remote Chainguard is the trusted source for open source... ...source software engineers and AI agents rely on, Chainguard helps organizations... ...Background in security research or offensive security (bug bounty, CTF, penetration...Local areaRemote workFlexible hours
$180k - $247k
...Secure Every Identity, from AI to Human Identity is the key... ...to you. The Staff Product Security Engineer Opportunity The Security... ...This is a hybrid research, offensive and software engineering role... ...execution runtimes, and AI coding agent container environments....Local areaRemote workWorldwideFlexible hours$160k - $205k
...work with some of the best information security professionals in the world in challenging... ...Pentester to join a team of world-class offensive security professionals. In this role, you... ...and experience by mentoring junior engineers, and assist with monitoring and response...Full timeWork at officeRemote workShift workDay shift$10k
...manage billions, Ramp is the place to do it.About the RoleThe Product Security team helps make Ramp the most secure place for our customers... ...across our technology stack: collaborating with other engineers to triage and fix vulnerabilities discovered internally, through...Full timeWork at officeHome officeFlexible hours$160k - $250k
...and its customers from the most advanced threats by securing our applications. CrowdStrike’s Product Security team breaks the mold of traditional internal... ...CrowdStrike’s products. As a Senior Application Security Engineer you will: ~Dig deep into web applications, find...Full timeWork at office$117.6k - $161.7k
...))We're building a new AI & Offensive Tooling capability inside our Offensive Security organization, and we're looking for a senior engineer who can both build it and use... ...offensive tooling. Write production-quality software and AI agents, LLM-driven planning loops,...Full timeTemporary workApprenticeshipWork at officeRemote workWork from homeHome office$161k - $242k
...Category Engineering Hire Type Employee Job ID 17996 Base Salary Range $161000-$24200... ...customers to rapidly innovate AI-powered products. We deliver industry-leading silicon design... ...before someone else does. You approach security testing with curiosity and rigor, not...Permanent employmentLive inRemote workWorldwide
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Offensive Security Engineer, Agent Products. Be the first to apply!
- offensive security engineer Remote
- staff security engineer Remote
- cloud security engineer Remote
- IT security engineer Remote
- information technology security engineer Remote
- security engineer Remote
- senior application security engineer Remote
- product security engineer Remote
- sr information security engineer Remote
- principal security engineer Remote




