FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Offensive Security Engineer
OpenAISecurity expert specializing in building agents for offensive security. Driving vulnerability identification and remediation across OpenAI's infrastructure and applications.
Posted 7/23/2026full-timeRemote • California, District of Columbia, New York, Washington • 🇺🇸 United StatesMid-LevelSenior💰 $347,000 - $490,000 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive expertise in offensive security, particularly in cloud security, Kubernetes, and web application security, while building production-quality systems that integrate human feedback and advanced evaluation mechanisms. Capable of translating complex security workflows into effective tools and systems that enhance security testing and operational efficiency.
Highest-signal resume keywords
Offensive Security ExperienceCloud Security ExpertiseKubernetes Security KnowledgeProduction Quality Software DevelopmentAgent Systems Development
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Offensive SecurityCloud SecurityKubernetes SecurityWeb Application SecuritySource-Code ReviewLinux SecurityMacOS SecurityVulnerability ManagementSystem ArchitectureComplex Environment Assessment
Soft Skills
Strong JudgmentProblem DecompositionCollaborationCuriosityTeam Leadership
Tools & Technologies
Agent SystemsFeedback LoopsObservability ToolsDebugging ToolsAutomation Tools
Industry Keywords
External Attack Surface TestingHuman-in-the-Loop SystemsSecurity EvaluationsFailure RecoverySecurity Testing
Tech Stack
Tools & technologiesCloudKubernetesLinuxMacOS
About the role
Key responsibilities & impact- Serve as the technical owner of OpenAI’s offensive security agents, establishing its architecture, technical direction, operating model, and evaluation strategy.
- Design and build a portfolio of specialized agents that continuously test OpenAI’s infrastructure and applications from a variety of authenticated and unauthenticated perspectives.
- Translate expert offensive security workflows and intuition into tools, skills, harnesses, policies, and internal knowledge bases.
- Build agents that deeply understand OpenAI’s environment by integrating internal context.
- Develop capabilities for testing cloud and Kubernetes environments, modern web applications, external attack surface, endpoints, and other high-value systems.
- Build complete vulnerability-management loops that move beyond discovery to impact validation, ownership identification, prioritization, remediation support, progress tracking, and fix verification.
- Design human-in-the-loop systems that allow offensive security engineers to approve or reject potentially dangerous actions, provide missing context, redirect investigations, and steer agents away from unproductive paths.
- Create feedback mechanisms that allow agents to learn from the decisions, corrections, and domain expertise of experienced offensive security practitioners.
- Develop rigorous evaluations that measure meaningful security outcomes and improvements in agent capability over time.
- Build production-quality infrastructure that allows the system to run continuously, recover from failures, remain observable and debuggable, and operate safely against production systems.
- Investigate failures in agent reasoning and behavior, identify where models are capable or unreliable, and improve the surrounding tools, context, workflows, and guardrails accordingly.
- Partner closely with offensive security, infrastructure security, product security, codex security, and engineering teams to ensure findings are high signal, understandable, and actionable.
- Help define the future of offensive security at OpenAI, with the goal of enabling agents to perform most repeatable security testing while human experts focus on automation and high leverage agent-assisted manual review.
Requirements
What you’ll need- You have substantial hands-on offensive security experience and strong judgment about which vulnerabilities and attack paths are worth pursuing.
- You have extensive domain expertise in areas such as cloud security, Kubernetes and container security, web application security, source-code review, Linux security, macOS security, or external attack-surface testing. Expertise in cloud, Kubernetes, and modern web applications is especially valuable.
- You have experience assessing complex, highly customized environments rather than relying primarily on standardized scanners, checklists, or known-vulnerability detection.
- You can take an ambiguous offensive security problem, decompose it into a reliable system, and encode the reasoning and workflows of an experienced operator into software.
- You have built production quality software
- You have built or meaningfully extended agent systems that use models, tools, structured context, memory, orchestration, and feedback loops to perform complex work.
- You understand that an impressive agent demonstration is very different from a dependable production system, and you care deeply about evaluations, observability, failure recovery, safety, maintainability, and regression resistance.
- You have strong intuitions about where current models are capable, where they are unreliable, and how tools, context, scaffolding, and human feedback can expand their useful operating range.
- You are excited about working closely with frontier models, curious about their emerging capabilities, and constantly look for ways to use them to improve your own workflows.
- You are energized by the opportunity to serve as a technical owner of an ambitious new system, make foundational architectural decisions, and help grow a team around it.
Benefits
Comp & perks- Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts
- Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)
- 401(k) retirement plan with employer match
- Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)
- Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees
- 13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick or safe time (1 hour per 30 hours worked, or more, as required by applicable state or local law)
- Mental health and wellness support
- Employer-paid basic life and disability coverage
- Annual learning and development stipend to fuel your professional growth
- Daily meals in our offices, and meal delivery credits as eligible
- Relocation support for eligible employees
- Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.