Offensive Security Engineer, Agent Products
Job description
About the role
The role centers on conducting deep, hands-on penetration testing against OpenAI's agent-powered products and infrastructure. You will own the end-to-end security assessment of systems that combine applications, infrastructure, and machine learning models. This position is technical and operational, focusing on finding realistic vulnerabilities and validating their exploitability. You will partner closely with engineering teams to ensure findings lead to durable fixes. The role emphasizes proactive threat modeling and continuous testing as products evolve quickly. You will build reusable testing approaches and automation to scale security coverage. Your attacker perspective will directly inform product security strategy and defensive investments. Overall, you will help secure some of the most complex and impactful AI-driven systems in the industry.
Key facts
What you'll do
- Conduct deep penetration tests of OpenAI's agent-powered products, including web applications, APIs, cloud services, identity and authorization flows, CI/CD systems, and model-integrated product surfaces.
- Continuously hunt for exploitable vulnerabilities in the interactions between applications, infrastructure, tools, and models that power our agentic products.
- Perform code review, architecture review, and hands-on exploitation to validate risk and identify subtle or novel failure modes.
- Produce clear, actionable findings with reproduction steps, exploitability analysis, impact assessment, and practical remediation guidance.
- Partner directly with engineering teams to drive fixes, validate remediation, and improve secure design patterns across agentic products.
- Build tools, test harnesses, and automation to scale penetration testing across rapidly evolving product surfaces.
- Leverage advanced automation and OpenAI technologies to optimize your offensive security work.
- Share attacker-informed insights with security and engineering teams to improve threat models, mitigations, and defensive coverage.
- Maintain detailed tracking of testing coverage, hypotheses, and findings to ensure thorough assessment of agent behaviors and integrations.
- Explore emergent attack vectors that arise from multi-step agent workflows and tool-use patterns.
- Collaborate on red team exercises that simulate realistic adversary behaviors against high-value targets.
- Contribute to the security community through internal presentations, documentation, and knowledge sharing.
- Support incident response efforts by providing offensive security context and reproducing adversarial behaviors.
- Evaluate third-party integrations and supply chain components for risks that could affect OpenAI's product surface.
Requirements
- 7+ years of hands-on penetration testing, product security assessment, application security, cloud security assessment, or equivalent offensive security experience.
- Deep expertise finding, exploiting, documenting, and helping remediate vulnerabilities in complex production systems.
- Experience performing offensive security assessments of modern technology products, including web applications, APIs, cloud infrastructure, identity systems, CI/CD pipelines, and distributed services.
- Experience designing, developing, or assessing the security of AI-powered systems.
- Experience finding, exploiting, and mitigating common vulnerabilities in AI systems, including prompt injection, confused deputies, unsafe tool use, and dynamically generated UI components.
- Exceptional skill in code review to identify novel and subtle vulnerabilities.
- Proven experience performing offensive security assessments in at least one hyperscaler cloud environment. Azure experience is preferred.
- Demonstrated mastery assessing complex technology stacks, including highly customized Kubernetes clusters, container environments, CI/CD pipelines, GitHub security, macOS and Linux operating systems, data science tooling and environments, Python-based web services, and React-based frontend applications.
- Strong intuitive understanding of trust boundaries and risk assessment in dynamic contexts.
- Excellent coding skills, capable of writing robust tools and automation for offensive security testing.
- Ability to communicate complex technical concepts effectively through clear reports, practical remediation guidance, and compelling technical storytelling.
- Proven track record of not just finding vulnerabilities, but actively contributing to solutions in complex codebases.
- Demonstrated ability to work independently with minimal supervision while maintaining rigorous documentation and follow-through.
- Comfort operating in a fast-paced, iterative environment where priorities shift based on product changes and emerging threats.
- Willingness to deepen expertise in OpenAI's specific technologies and threat models over time.
Nice to have
- Background or expertise in AI or data science.
- Prior experience working in tech startups or fast-paced technology environments.
- Experience in related disciplines such as Software Engineering, Reverse Engineering, Threat Intelligence, Forensics, or DevSecOps.
- Experience with bug bounty programs or public disclosure processes.
- Familiarity with security research tools, frameworks, and custom scripting.
Practical notes
This role is full-time and remote within the United States. The position may require occasional work during standard business hours for coordination with global teams or for critical incident response. Travel is not expected as part of the core responsibilities. Candidates must be eligible to work in the United States without sponsorship for this role.