All remote jobs
Open role
Remote opportunity atOpenAI

Software Engineer, Infrastructure Security

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Published
30Listing views
2Application actions
29 Sep 2026Apply before
Opportunity details

About this role.

AI Summary

This is a senior-level infrastructure security engineering role focused on building foundational security services for large-scale AI research and production environments. The engineer will develop authentication, access-broker, proxy, key-management, encryption, identity, and network-isolation capabilities across bare metal, cloud, Kubernetes, and CI/CD systems. The role requires strong distributed-systems engineering ability as well as deep practical expertise in cloud, network, and platform security. It involves close partnership with infrastructure and research teams while operating systems that protect sensitive model weights, user data, and high-performance compute clusters.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

5/5
EasyHard

Pace & Pressure

5/5
RelaxedFast-paced

Autonomy Level

5/5
GuidedFull ownership

Communication Load

5/5
IndependentCollaborative
AI insightThe position combines advanced software engineering with high-stakes infrastructure security across multi-cloud, on-premises, Kubernetes, networking, and hardware-adjacent environments. Reliability and security requirements are exceptionally high because the systems support frontier AI workloads and must withstand adversarial pressure at significant scale.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianHighly competitive
$307,500
US market range$200k–$350k
AI insightThe disclosed yearly base compensation range is USD 230,000 to USD 385,000, with a midpoint of USD 307,500. This is above the typical US market range for many infrastructure security engineers, but is consistent with a highly senior, high-impact security engineering role at a leading AI company in major US technology markets.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
How would you design a machine-identity platform for services running across Kubernetes clusters and cloud environments?

I would establish a workload identity model rooted in short-lived, cryptographically verifiable credentials, such as SPIFFE identities delivered through SPIRE or an equivalent control plane. The design would include automated certificate issuance and rotation, strong workload attestation, policy-based authorization, audit logging, and resilience across clusters and clouds. I would also define migration paths so legacy services can adopt identity incrementally without disrupting production workloads.

Describe how you would threat-model an egress proxy used by sensitive AI training infrastructure.

I would first identify the assets, trust boundaries, users, upstream and downstream dependencies, and allowed data flows. Key threats would include credential exfiltration, bypass of egress controls, malicious DNS resolution, SSRF, policy misconfiguration, denial of service, and inadequate logging. Controls would include default-deny policies, authenticated workloads, TLS inspection only where appropriate, destination allowlisting, tamper-resistant audit trails, rate limiting, and continuous policy validation.

What approaches would you use to secure Kubernetes-based workloads handling highly sensitive data?

I would apply layered controls: workload identity and mTLS, least-privilege RBAC, admission controls, image provenance and signing, secret-management integration, network policies, runtime detection, and hardened node configurations. I would separate sensitive workloads through strong tenancy and network boundaries, continuously assess cluster configuration drift, and ensure that incident telemetry is available without exposing sensitive payload data.

Tell us about a time you improved the reliability of a critical security or infrastructure service.

A strong example would explain the service's availability or operational risk, the metrics used to quantify the problem, and the engineering changes made. For instance, I would describe introducing redundancy, safe rollouts, automated credential rotation, better observability, and tested recovery procedures for a security-critical control plane. I would conclude with measurable improvements such as reduced incident frequency, lower recovery time, or improved service-level performance.

How do you communicate a significant security risk to engineering and non-technical stakeholders when rapid delivery is also a priority?

I communicate the risk in terms of affected assets, likely attack paths, business or operational impact, and confidence level rather than relying on abstract severity labels alone. I present practical options, including immediate mitigations, longer-term fixes, ownership, and delivery tradeoffs. This helps stakeholders make an informed decision while keeping the conversation focused on reducing risk without unnecessarily blocking critical work.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.

About the Team

Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity.

The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but operational in how we execute, and we support every product and research effort at OpenAI. Our tenets include prioritizing for impact, enabling researchers and developers, preparing for future transformative technologies, and fostering a strong, collaborative security culture.

About the Role

OpenAI is seeking a Security Software Engineer to join the Infrastructure Security (InfraSec) team.

InfraSec safeguards the core of OpenAI’s research and production environments—GPU supercomputing clusters, multi-cloud infrastructure, datacenters, networking, storage, and the critical services that power our frontier AI models. Our charter spans everything from bare-metal hardware and firmware to Kubernetes clusters, service meshes, and the data pathways that carry highly sensitive model weights and user data.

As a Security Software Engineer, you will design and build critical foundational services, such as authentication systems, egress/ingress proxies, access brokers, and key management platforms, that demand high standards of reliability, scalability, and software craftsmanship. These systems form the security backbone of OpenAI’s supercomputing environment and must remain robust under intense scale and adversarial pressure.

In this role, you will:

  • Architect and implement production-grade security services (e.g., auth services, access brokers, secure proxies, key-management infrastructure) that provide strong guarantees across hardware, operating systems, Kubernetes, networks, and CI/CD.

  • Partner with infrastructure and research engineers to embed security into high-performance compute clusters, enabling rapid model training and deployment without compromising protection.

  • Develop automation and detection tooling to continuously identify and mitigate risks in large-scale cloud and on-prem environments.

  • Drive high-impact initiatives such as line-speed encryption, machine identity, and network isolation, continuously raising the security bar for emerging AI workloads.

  • Lead or participate in design reviews and threat models to ensure new systems launch with strong security foundations and operational excellence.

You will thrive in this role if you have:

  • Strong software engineering skills in languages such as Python, Go, Rust, or C/C++, with a track record of shipping and operating high-reliability distributed services.

  • Experience building or operating critical security infrastructure (e.g., auth services, service-to-service proxies, certificate or key-management systems).

  • Deep understanding of security principles, best practices, and common vulnerabilities.

  • Expertise in securing large-scale cloud platforms (e.g., Azure, AWS, GCP), including multi-cloud networks and cloud-agnostic system design.

  • Familiarity with container and orchestration security (Kubernetes, service meshes) and modern authentication/authorization standards (OIDC, mTLS, SPIFFE/SPIRE).

  • A proactive mindset, with the ability to identify and address security gaps or inefficiencies through automation and tooling.

  • A track record of delivering scalable solutions and driving impactful changes across infrastructure in real-world projects.

  • Strong analytical and problem-solving skills, with an ability to think critically and objectively assess security risks.

  • Excellent communication skills, with the ability to convey complex security concepts to technical and non-technical stakeholders.

  • Excitement about collaborating with cross-functional teams to build secure, reliable systems that scale globally.

About OpenAI

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.

We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.

For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement.

Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.

To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.

OpenAI Global Applicant Privacy Policy

At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. View safety guidance.

Log in to save
One quick step before you apply

Create your free account, then apply.

Build a more organized job search on Jobicy and continue to the employer's application when you're ready.

  • Never lose a promising opportunitySave roles and return to them from your dashboard.
  • See your entire search at a glanceTrack applications, stages and next steps in one place.
  • Get matched with relevant remote jobsChoose the alerts and digests that work for you.
Applying is free. The employer's application opens in a new tab.
Add alert
Jobs Talent AI Tools Salaries
Menu