About the job
About the Team:
At OpenAI, security is integral to our mission of ensuring that artificial general intelligence benefits all of humanity.
Codex Security, our pioneering security agent, is designed to scan GitHub Cloud repositories, verify genuine vulnerabilities, and collaborate with Codex to generate effective fixes.
About the Role:
In this critical position, you will spearhead initiatives to identify, characterize, and prioritize vulnerabilities across multiple layers in advanced AI systems, including data pipelines, training and inference runtimes, and system supply chains. Your work will encompass offensive research, technical documentation, product enhancement, and serving as OpenAI’s primary technical liaison to select external partners, including potential U. S. government stakeholders.
Key Responsibilities:
Conduct comprehensive security research on real-world software systems to uncover intricate vulnerabilities across extensive codebases and distributed architectures.
Validate vulnerabilities identified by AI-driven security agents through the development of proofs-of-concept and exploit demonstrations.
Collaborate with engineering teams to optimize automated vulnerability discovery, validation, and remediation workflows within product development.
Create high-quality security datasets and evaluations that will enhance the cybersecurity capabilities of models.
Advance AI models used for vulnerability discovery and remediation by establishing datasets, evaluations, and feedback mechanisms based on real-world research.
Publish insightful technical write-ups, research findings, and vulnerability analyses to elevate application security standards.
You Will Excel If You:
Possess extensive experience in vulnerability research, exploit development, or offensive security.
Demonstrate a strong command of advanced offensive security techniques.
Are well-versed in AI/ML infrastructure (data, training, inference, schedulers, accelerators) and can perform comprehensive threat modeling.
Exhibit the ability to work independently, unify diverse teams, and meet tight deadlines.
Communicate effectively and succinctly with both technical experts and decision-makers.
Have a passion for enhancing the security of widely utilized software and open-source platforms.

