[![Image]() Meet Jobicy Copilot — free AI autofill for job applications + remote job alerts ›](#)   [All remote jobs](https://jobicy.com/jobs.md)Open role[![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)](https://jobicy.com/company/openai.md)Remote opportunity at[OpenAI](https://jobicy.com/company/openai.md)

# Security Engineer, Insider Threat Detection & Response

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/openai.md)Share20 Sep 2026Published44Listing views5Application actions20 Oct 2026Apply before  Opportunity details

## About this role.

AI SummaryThis Security Engineer role focuses on insider-threat detection and response for OpenAI's sensitive technology, data, and AI infrastructure. The engineer will build and automate detection and investigation workflows, tune detection rules, and lead incident-response activities. Responsibilities include addressing access abuse, intellectual-property theft, data exfiltration, and emerging AI-infrastructure risks. The position requires close technical partnership with HR, Legal, and investigative teams while independently driving risk-reduction projects. Candidates need at least five years of detection, response, or insider-risk experience plus strong systems, cloud, Kubernetes, and scripting knowledge.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

5/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThe role combines advanced detection engineering with high-consequence insider-risk investigations across endpoint, cloud, and AI infrastructure. It requires independent judgment, incident leadership, and careful cross-functional communication involving sensitive employee, legal, and security matters.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianAbove market$325,500US market range$190k–$300k0$358k

AI insightThe disclosed yearly base compensation range is USD 266,000–385,000, with a midpoint of USD 325,500. A typical US market range for a senior detection and response or insider-threat security engineer is approximately USD 190,000–300,000 yearly; this offer is above the general market range, consistent with the specialized scope, seniority, and high-cost US locations.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Insider Threat Detection](https://jobicy.com/jobs?search_keywords=Insider%20Threat%20Detection.md)[Incident Response](https://jobicy.com/jobs?search_keywords=Incident%20Response.md)[Detection Engineering](https://jobicy.com/jobs?search_keywords=Detection%20Engineering.md)[Security Automation](https://jobicy.com/jobs?search_keywords=Security%20Automation.md)[Threat Hunting](https://jobicy.com/jobs?search_keywords=Threat%20Hunting.md)[Cloud Security](https://jobicy.com/jobs?search_keywords=Cloud%20Security.md)[Kubernetes Security](https://jobicy.com/jobs?search_keywords=Kubernetes%20Security.md)[Endpoint Security](https://jobicy.com/jobs?search_keywords=Endpoint%20Security.md)[Python](https://jobicy.com/jobs?search_keywords=Python.md)[Digital Forensics](https://jobicy.com/jobs?search_keywords=Digital%20Forensics.md)

Sample interview questionsHow would you design an insider-threat detection program that balances effective monitoring with employee privacy and operational usability?I would start with a risk assessment that identifies critical assets, likely misuse scenarios, and the minimum telemetry needed to detect them. I would apply data minimization, role-based access, documented investigation thresholds, and clear governance with Legal and HR. Detections would be measured for precision, investigative value, and user friction, then iteratively tuned with stakeholder review.

Describe how you would investigate a potential data-exfiltration event involving a privileged employee.

I would first preserve relevant evidence and establish a timeline using identity, endpoint, cloud, network, and SaaS audit logs. I would validate the employee's access, compare activity to normal baselines, identify the data involved, and determine whether transfers were authorized. I would coordinate escalation and containment through established procedures with Legal, HR, and incident leadership while maintaining need-to-know handling and an auditable record.

What signals would you prioritize for detecting abuse of access in cloud and Kubernetes environments?

I would prioritize anomalous privilege changes, use of dormant or unusual credentials, abnormal secret access, service-account misuse, unexpected cluster administration actions, and access from atypical devices or locations. I would correlate those signals with data-store reads, bulk exports, unusual egress, CI/CD activity, and changes to logging controls. Detection logic should incorporate peer-group baselines and asset criticality to reduce false positives.

How do you evaluate and tune a detection rule after it has been deployed?

I define the intended threat scenario, required telemetry, severity criteria, and expected investigation steps before release. After deployment, I track alert volume, true-positive rate, time to triage, coverage gaps, and analyst feedback. I then adjust thresholds, enrich alerts with useful context, suppress known benign patterns carefully, and regularly test the rule against representative adversary techniques.

Give an example of how you would use Python or another scripting language to improve detection and response operations.

I would build an automated enrichment workflow that ingests an alert, collects associated identity, endpoint, cloud, and network context, and produces a structured investigation timeline. The script could score risk using factors such as privileged access, sensitive-data exposure, unusual egress, and prior alerts, then open or update a case with evidence links. I would include error handling, access controls, logging, and tests so the automation is reliable and safe for operational use.

About the Team

Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity.

The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.

About the Role

As a Security Engineer you will join our OpenAI engineers and researchers in building, operating and securing transformational AI technologies. This role will focus on all aspects of Detection & Response but with a strong emphasis on detecting insider threats and influencing controls to safeguard OpenAI’s most sensitive assets. In this role, you will:

In this role, you will:

*

Innovate on Detection and Response infrastructure to engineer and automate end-to-end detection and investigation workflows.

*

Develop, measure, and tune detection rules to ensure effective and sustainable operations.

*

Drive projects across OpenAI’s technology stack with a focus on insider threats, ranging from access abuse and intellectual property theft to novel risks emerging within AI infrastructure.

*

Partner closely with cross-functional stakeholders, including HR, Legal, and peer investigative teams, providing technical expertise and evidence to support investigations.

*

Collaborate on cutting-edge AI research, and use AI to improve OpenAI’s Security posture.

You might thrive in this role if you:

*

5+ years experience working in a detection/response or insider-risk role.. We are seeking mid-level and senior candidates.

*

You have broad familiarity with operating systems and platforms such as macOS, Windows, Linux, and Kubernetes, along with experience in cloud infrastructure.

*

Knowledge of modern adversary tactics and attack paths, data exfiltration techniques, and have experience running and leading incidents.

*

Proficiency with a scripting language (e.g. Python, Bash, PowerShell, or similar).

*

Independently manage and run projects , balance preventative controls with user friction, and prioritize efforts for risk reduction.

*

You’re motivated by securing transformative technology and can adapt familiar security frameworks to new risks in AI infrastructure

About OpenAI

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.

We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.

For additional information, please see [OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement](https://cdn.openai.com/policies/eeo-policy-statement.pdf).

Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.

To notify OpenAI that you believe this job posting is non-compliant, please submit a report through [this form](https://form.asana.com/?d=57018692298241&k=5MqR40fZd7jlxVUh5J-UeA). No response will be provided to inquiries unrelated to job posting compliance.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this [link](https://form.asana.com/?k=bQ7w9h3iexRlicUdWRiwvg&d=57018692298241).

[OpenAI Global Applicant Privacy Policy](https://cdn.openai.com/policies/global-employee-and-contractor-privacy-policy.pdf)

At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

Show more

[Apply now >](https://jobicy.com/jobs/153709-security-engineer-insider-threat-detection-response.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![Fastly logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/10/127f9e4bbbdb8767bef358a23bf7f73d.jpeg)
Fastly  Sep 20

### [Senior Security Technical Account Manager](https://jobicy.com/jobs/153750-senior-security-technical-account-manager.md)

Fastly helps people stay better connected with the things they love. Fastly’s edge cloud platform enables customers to create great digital experiences quickly, securely, and reliably by processing, serving, and…

*
![SkySlope logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2022/01/1e0d9f0517a4959cdef118a420f873a6.jpeg)
SkySlope  Sep 20

### [Security Engineering Manager](https://jobicy.com/jobs/153718-security-engineering-manager.md)

OUR ORIGIN STORY 🎂 In 2011 SkySlope started as an idea born at the kitchen table of our CEO, with just him and two others. Headquartered in Sacramento, California, we…

*
![1Password logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/09/WRILS-200909195848-296323.png)
1Password  Sep 20

### [Senior Security Engineer, Incident Response](https://jobicy.com/jobs/153700-senior-security-engineer-incident-response.md)

1Password is growing. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up…

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI  Sep 20

### [Senior Technical Program Manager – Security](https://jobicy.com/jobs/151221-senior-technical-program-manager-security.md)

About the Team OpenAI builds powerful AI systems like ChatGPT, the OpenAI API, and enterprise products that serve millions of users across the globe. As we scale, securing our infrastructure,…

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI  Sep 20

### [Software Engineer, Security Observability](https://jobicy.com/jobs/151224-software-engineer-security-observability.md)

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products….

*
![Synthesia logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/c69aad11-221.webp)
Synthesia  Sep 20

### [Application Security Engineering Manager](https://jobicy.com/jobs/146803-application-security-engineering-manager.md)

Synthesia is the world’s leading AI video platform for business, used by over 90% of the Fortune 100. Founded in 2017, the company is headquartered in London, with offices and…

*
![Roboflow logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/8cd75e4b-221.webp)
Roboflow  Sep 19

### [Security Engineer](https://jobicy.com/jobs/153639-security-engineer-2.md)

Who We Are Our mission is to make the world programmable. Sight is one of the key ways we understand the world, and soon this will be true for the…

*
![Ping Identity logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/09/63e8d5a6-221.png)
Ping Identity  Sep 19

### [Demo Engineering Business Analyst](https://jobicy.com/jobs/153623-demo-engineering-business-analyst.md)

About Ping Identity: At Ping Identity, we believe in making digital experiences both secure and seamless for all users, without compromise. We call this digital freedom. And it’s not just…

*
![Nebius logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/d90c0566-221.webp)
Nebius  Sep 18

### [Offensive Security Lead](https://jobicy.com/jobs/149365-offensive-security-lead.md)

About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from…

*
![Nebius logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/d90c0566-221.webp)
Nebius  Sep 18

### [Vulnerability Operation Center Lead](https://jobicy.com/jobs/149362-vulnerability-operation-center-lead.md)

About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from…