All remote jobs
Open role
Remote opportunity atOpenAI

Principal Security Engineer, Infrastructure Security

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Published
29Listing views
2Application actions
21 Oct 2026Apply before
Opportunity details

About this role.

AI Summary

OpenAI is hiring a Principal Security Engineer to set strategy and deliver high-impact infrastructure security controls across research and production environments. The role covers security from hardware, firmware, and datacenters through cloud platforms, Kubernetes, networks, storage, and CI/CD. This principal-level engineer will lead cross-functional security programs, conduct threat modeling and design reviews, and balance robust controls with reliability and engineering velocity. Success requires deep cloud and on-premises security expertise, strong judgment under ambiguity, and the ability to mentor engineers and communicate with varied stakeholders.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

5/5
EasyHard

Pace & Pressure

5/5
RelaxedFast-paced

Autonomy Level

5/5
GuidedFull ownership

Communication Load

5/5
IndependentCollaborative
AI insightThis is a principal-level role securing highly sensitive, globally scaled AI infrastructure across many technical layers and organizational boundaries. It requires independent strategic ownership, sophisticated threat judgment, and delivery of durable controls while managing significant reliability and operational tradeoffs.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianHighly competitive
$455,500
US market range$300k–$500k
AI insightThe disclosed yearly salary range is USD 401,000 to USD 510,000, producing a midpoint of USD 455,500. For a U.S.-based principal infrastructure security engineer, a typical estimated base-salary market range is approximately USD 300,000 to USD 500,000; total compensation may be higher depending on equity and incentives.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
How would you create a security strategy for a multi-cloud AI infrastructure that includes GPU clusters, Kubernetes, and sensitive model data?

I would begin with an asset inventory and threat model that identifies trust boundaries, critical data flows, privileged identities, and likely adversaries. I would define a prioritized roadmap around strong identity controls, segmentation, secure hardware and workload baselines, centralized telemetry, and tested incident response, then establish measurable risk-reduction outcomes and rollout milestones with infrastructure partners.

Describe how you would balance a security control rollout with platform reliability and developer velocity.

I would engage platform owners early, document the security objective and operational constraints, and test the control in a representative environment before broad deployment. I would use phased rollouts, automation, clear exception processes, observability, and rollback plans, measuring both security coverage and reliability impact so the final control is durable rather than merely restrictive.

What security risks are particularly important for Kubernetes environments supporting critical workloads?

Key risks include excessive RBAC privileges, compromised service accounts, weak admission controls, vulnerable images, insecure secrets handling, insufficient network isolation, and poor audit visibility. I would address these through least-privilege identity design, workload policy enforcement, image provenance and scanning, secrets management, network policies, runtime detection, and comprehensive logging.

How would you approach securing on-premises datacenter hardware from construction through multi-tenant operation?

I would establish physical-security and supply-chain requirements first, including asset provenance, secure receiving, tamper controls, and lifecycle tracking. Technical controls would include firmware and BMC hardening, secure boot and attestation where available, segmented management networks, tightly controlled break-glass access, continuous inventory, and monitoring for configuration drift and anomalous activity.

Tell us about a time you would need to influence senior stakeholders to accept a significant infrastructure security change.

I would frame the discussion in terms of concrete attack paths, business impact, operational tradeoffs, and viable implementation options rather than presenting security as an abstract requirement. By proposing a staged plan with ownership, success metrics, reliability safeguards, and a transparent risk-acceptance path for exceptions, I can help stakeholders make an informed decision and build alignment around the preferred solution.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.

About the Team

Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity.

The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.

About the Role

OpenAI is seeking a Principal Security Engineer to join our Infrastructure Security (InfraSec) team. InfraSec protects the foundations of OpenAI’s research and production environments, spanning GPU supercomputing clusters, multi-cloud infrastructure, datacenters, networking, storage, and the critical services that power our frontier AI models. Our charter includes securing everything from bare-metal hardware and firmware, to Kubernetes clusters and service meshes, to data storage and access pathways for highly sensitive model weights and user data.

As a principal engineer, you will set technical direction and drive execution on high-impact infrastructure security programs, partnering across various orgs at OpenAI to deliver durable controls that raise the security bar at OpenAI scale.

In this role, you will:

  • Own end-to-end security outcomes for one or more critical infrastructure areas, including multi-quarter strategy, roadmap, and delivery.

  • Design and build security controls across diverse layers (e.g., physical hardware, firmware/BMC, OS, Kubernetes, networks, and CI/CD) to defend against sophisticated adversaries and insider threats.

  • Lead cross-functional programs to deploy security enhancements and control changes across broad-scale infrastructure, balancing security guarantees with reliability and velocity.

  • Take a generalist approach to building security controls, balancing a mix of security expertise and broad technical skillsets to adapt to evolving challenges.

  • Lead and/or drive threat modeling and design reviews for major infrastructure changes, ensuring strong security foundations and operational excellence.

  • Mentor and level up engineers across InfraSec and partner teams, contributing to a strong security culture through guidance, reviews, and technical leadership.

You will thrive in this role if you have:

  • Deep understanding of security principles, best practices, and common vulnerabilities, including strong security judgment under ambiguity

  • A proactive mindset, with the ability to identify and address security gaps or inefficiencies through automation and tooling.

  • Expertise and curiosity about using frontier models and agents to effectively solve security challenges.

  • A track record of leading large, cross-org initiatives from concept to rollout, including navigating tradeoffs, driving alignment, and delivering measurable risk reduction.

  • Deep expertise in the security of cloud platforms (e.g., Amazon AWS, Microsoft Azure), especially securing multi-cloud networks and infrastructure, and designing cloud-agnostic systems.

  • Experience securing on-prem deployments and datacenters from construction to multi-tenant use.

  • Familiarity with container security, orchestration security, and authentication/authorization.

  • Strong analytical and problem-solving skills, with an ability to think critically and objectively assess security risks.

  • Excellent communication skills, with the ability to convey complex security concepts to executive, technical, and non-technical stakeholders.

  • Excitement about collaborating with cross-functional teams to build secure, reliable systems that scale globally.

About OpenAI

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.

We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.

For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement.

Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.

To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.

OpenAI Global Applicant Privacy Policy

At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. View safety guidance.

Log in to save
One quick step before you apply

Create your free account, then apply.

Build a more organized job search on Jobicy and continue to the employer's application when you're ready.

  • Never lose a promising opportunitySave roles and return to them from your dashboard.
  • See your entire search at a glanceTrack applications, stages and next steps in one place.
  • Get matched with relevant remote jobsChoose the alerts and digests that work for you.
Applying is free. The employer's application opens in a new tab.
Add alert
Jobs Talent AI Tools Salaries
Menu