All remote jobs
Open role
Remote opportunity atOpenAI

Security Engineer, Insider Threat Detection & Response

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Published
55Listing views
6Application actions
20 Oct 2026Apply before
Opportunity details

About this role.

AI Summary

This Security Engineer role focuses on insider-threat detection and response for OpenAI's sensitive technology, data, and AI infrastructure. The engineer will build and automate detection and investigation workflows, tune detection rules, and lead incident-response activities. Responsibilities include addressing access abuse, intellectual-property theft, data exfiltration, and emerging AI-infrastructure risks. The position requires close technical partnership with HR, Legal, and investigative teams while independently driving risk-reduction projects. Candidates need at least five years of detection, response, or insider-risk experience plus strong systems, cloud, Kubernetes, and scripting knowledge.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

5/5
EasyHard

Pace & Pressure

5/5
RelaxedFast-paced

Autonomy Level

5/5
GuidedFull ownership

Communication Load

5/5
IndependentCollaborative
AI insightThe role combines advanced detection engineering with high-consequence insider-risk investigations across endpoint, cloud, and AI infrastructure. It requires independent judgment, incident leadership, and careful cross-functional communication involving sensitive employee, legal, and security matters.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianAbove market
$325,500
US market range$190k–$300k
AI insightThe disclosed yearly base compensation range is USD 266,000–385,000, with a midpoint of USD 325,500. A typical US market range for a senior detection and response or insider-threat security engineer is approximately USD 190,000–300,000 yearly; this offer is above the general market range, consistent with the specialized scope, seniority, and high-cost US locations.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
How would you design an insider-threat detection program that balances effective monitoring with employee privacy and operational usability?

I would start with a risk assessment that identifies critical assets, likely misuse scenarios, and the minimum telemetry needed to detect them. I would apply data minimization, role-based access, documented investigation thresholds, and clear governance with Legal and HR. Detections would be measured for precision, investigative value, and user friction, then iteratively tuned with stakeholder review.

Describe how you would investigate a potential data-exfiltration event involving a privileged employee.

I would first preserve relevant evidence and establish a timeline using identity, endpoint, cloud, network, and SaaS audit logs. I would validate the employee's access, compare activity to normal baselines, identify the data involved, and determine whether transfers were authorized. I would coordinate escalation and containment through established procedures with Legal, HR, and incident leadership while maintaining need-to-know handling and an auditable record.

What signals would you prioritize for detecting abuse of access in cloud and Kubernetes environments?

I would prioritize anomalous privilege changes, use of dormant or unusual credentials, abnormal secret access, service-account misuse, unexpected cluster administration actions, and access from atypical devices or locations. I would correlate those signals with data-store reads, bulk exports, unusual egress, CI/CD activity, and changes to logging controls. Detection logic should incorporate peer-group baselines and asset criticality to reduce false positives.

How do you evaluate and tune a detection rule after it has been deployed?

I define the intended threat scenario, required telemetry, severity criteria, and expected investigation steps before release. After deployment, I track alert volume, true-positive rate, time to triage, coverage gaps, and analyst feedback. I then adjust thresholds, enrich alerts with useful context, suppress known benign patterns carefully, and regularly test the rule against representative adversary techniques.

Give an example of how you would use Python or another scripting language to improve detection and response operations.

I would build an automated enrichment workflow that ingests an alert, collects associated identity, endpoint, cloud, and network context, and produces a structured investigation timeline. The script could score risk using factors such as privileged access, sensitive-data exposure, unusual egress, and prior alerts, then open or update a case with evidence links. I would include error handling, access controls, logging, and tests so the automation is reliable and safe for operational use.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.

About the Team

Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity.

The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.

About the Role

As a Security Engineer you will join our OpenAI engineers and researchers in building, operating and securing transformational AI technologies. This role will focus on all aspects of Detection & Response but with a strong emphasis on detecting insider threats and influencing controls to safeguard OpenAI’s most sensitive assets. In this role, you will:

In this role, you will:

  • Innovate on Detection and Response infrastructure to engineer and automate end-to-end detection and investigation workflows.

  • Develop, measure, and tune detection rules to ensure effective and sustainable operations.

  • Drive projects across OpenAI’s technology stack with a focus on insider threats, ranging from access abuse and intellectual property theft to novel risks emerging within AI infrastructure.

  • Partner closely with cross-functional stakeholders, including HR, Legal, and peer investigative teams, providing technical expertise and evidence to support investigations.

  • Collaborate on cutting-edge AI research, and use AI to improve OpenAI’s Security posture.

You might thrive in this role if you:

  • 5+ years experience working in a detection/response or insider-risk role.. We are seeking mid-level and senior candidates.

  • You have broad familiarity with operating systems and platforms such as macOS, Windows, Linux, and Kubernetes, along with experience in cloud infrastructure.

  • Knowledge of modern adversary tactics and attack paths, data exfiltration techniques, and have experience running and leading incidents.

  • Proficiency with a scripting language (e.g. Python, Bash, PowerShell, or similar).

  • Independently manage and run projects , balance preventative controls with user friction, and prioritize efforts for risk reduction.

  • You’re motivated by securing transformative technology and can adapt familiar security frameworks to new risks in AI infrastructure

About OpenAI

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.

We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.

For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement.

Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.

To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.

OpenAI Global Applicant Privacy Policy

At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. View safety guidance.

Log in to save
One quick step before you apply

Create your free account, then apply.

Build a more organized job search on Jobicy and continue to the employer's application when you're ready.

  • Never lose a promising opportunitySave roles and return to them from your dashboard.
  • See your entire search at a glanceTrack applications, stages and next steps in one place.
  • Get matched with relevant remote jobsChoose the alerts and digests that work for you.
Applying is free. The employer's application opens in a new tab.
Add alert
Jobs Talent AI Tools Salaries
Menu