Offensive Security Engineer, Agent Products
Core
Principal-level offensive security engineer conducting deep penetration testing of OpenAI's agent-powered products, infrastructure, and model-integrated application surfaces.
Role type
Principal, hands-on IC offensive security engineer
Builds
Reusable testing approaches, automated offensive security workflows, and secure design patterns for agent products like Codex and Operator
Domain
AI/ML security, cloud infrastructure, and agentic product security
Deliverable
production ML models | product features
Required skills
Penetration testing, vulnerability exploitation, code review, architecture review, automation development, cloud security assessment, AI system security assessment, prompt injection mitigation, confused deputy mitigation, trust boundary analysis
Preferred skills
Azure cloud environment experience, Kubernetes cluster assessment, container environment security, CI/CD pipeline security, Python tooling development, React frontend security
Technologies
Kubernetes, containers, CI/CD pipelines, GitHub Actions, macOS, Linux, Python, React, Azure
Responsibilities
Conduct deep penetration tests of agent-powered products including web apps, APIs, and cloud services; hunt for exploitable vulnerabilities in application-infrastructure-model interactions; perform code and architecture reviews to identify subtle failure modes; produce actionable findings with exploitability analysis and remediation guidance; partner with engineering teams to drive fixes and improve secure design patterns; build tools and test harnesses to scale penetration testing; leverage OpenAI technologies to optimize offensive security workflows
Seniority
Principal, hands-on IC