Cyber Operations Strategist, Critical Harm Operations
Job description
Cyber Operations Strategist, Critical Harm Operations at openai.
About the role
This role focuses on enhancing the quality and scalability of cyber operations within the Critical Harm Operations team. You will apply your deep cybersecurity knowledge to improve operational designs and resolve complex issues related to dual-use technologies. The goal is to create lasting improvements in operational models and empower the team of reviewers.
Key facts
What you'll do
- Guide the cyber operations model, covering standard operating procedures, escalation paths, quality, vendor capabilities, and strategic inputs.
- Act as the primary cyber authority for critical decisions across products like ChatGPT, API, Codex, and emerging AI agents.
- Convert unclear policies, quality issues, appeals, and reviewer disagreements into clear decision rules, training, and tool specifications.
- Develop robust operating systems and quality feedback loops, including golden sets, holdouts, double-labeling, and error classification.
- Improve the skills of both full-time employees and external vendors through onboarding, certification, coaching, and performance reviews.
- Analyze signals from quality, appeals, service level agreements, and backlogs to identify root causes and prioritize effective solutions.
- Create practical solutions such as SQL analyses, scripts, dashboards, LLM evaluation workflows, and automation to enhance decision quality and reduce manual effort.
- Collaborate with various internal teams including Policy, Integrity, Safety Systems, Security, Legal, Product, Engineering, and Investigations to implement changes and prepare for new product launches.
Requirements
- Over 8 years of direct cybersecurity experience in areas like offensive security, threat intelligence, incident response, security research, red teaming, application security, digital forensics, malware analysis, or similar fields.
- Strong understanding of attacker tactics, vulnerability exploitation, credential misuse, malware, persistence, evasion, data exfiltration, cloud or identity abuse, and ambiguous dual-use activities.
- Experience in developing or improving high-stakes operations, reviewer programs, quality assurance systems, escalation workflows, or vendor management programs.
- Ability to translate complex cyber and policy judgments into actionable standard operating procedures, decision trees, training materials, and concise recommendations for reviewers.
- Proficiency in using SQL, Python, C/C++, JavaScript, PowerShell, Bash, APIs, LLM tools, or automation to address operational challenges.
- Knowledge of human-in-the-loop automation, evaluations, monitoring, holdouts, and fallback mechanisms for sensitive workflows.
- Capability to work independently in uncertain situations, communicate clearly with both technical and non-technical audiences, and exercise sound judgment with sensitive information.
- Experience with trust and safety, platform abuse, cyber misuse of AI systems, or large language model safety.
Nice to have
- Experience with golden sets, classifier or prompt evaluations, and reviewer quality programs.
- Experience in enabling global vendor reviewer operations.
Skills & tools
SQL, Python, C/C++, JavaScript, PowerShell, Bash, APIs, LLM tooling, automation
Practical notes
This role offers equity compensation. Background checks will be conducted in accordance with applicable laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act for US-based candidates. Reasonable accommodations for applicants with disabilities are available upon request.