All remote jobs
Open role
Remote opportunity atOpenAI

Principal Software Engineer, Infrastructure Security

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Published
20Listing views
0Application actions
21 Oct 2026Apply before
Opportunity details

About this role.

AI Summary

This principal-level infrastructure security role owns the technical direction, delivery, and long-term operation of foundational security services for OpenAI’s research and production environments. The engineer will build and operate high-scale identity, authorization, proxy, attestation, and key-management capabilities spanning hardware, cloud, Kubernetes, networking, and CI/CD systems. The role requires leading complex cross-functional launches, driving threat modeling and systemic risk remediation, and mentoring senior engineers. Success depends on exceptional distributed-systems engineering, deep cloud-security expertise, and the ability to balance strong security guarantees with reliability, latency, and developer experience. It also includes applying frontier AI models and agents to security automation and detection challenges.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

5/5
EasyHard

Pace & Pressure

5/5
RelaxedFast-paced

Autonomy Level

5/5
GuidedFull ownership

Communication Load

5/5
IndependentCollaborative
AI insightThis is a principal role responsible for security-critical services operating across planet-scale, adversarially exposed infrastructure. It requires rare depth across distributed systems, cloud and platform security, architecture, operations, and organization-wide technical leadership.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianHighly competitive
$455,500
US market range$300k–$550k
AI insightThe disclosed annual base compensation range is USD 401,000 to USD 510,000, with a midpoint of USD 455,500. This is a highly competitive range for a US-based principal infrastructure security engineer; the broader estimated US market range for comparable seniority and scope is approximately USD 300,000 to USD 550,000 annually, excluding equity, bonuses, and other compensation components.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
How would you design a highly available authorization service for workloads across multiple clouds and on-premises infrastructure?

I would begin by defining the trust boundaries, request latency objectives, availability targets, and failure behavior. I would use strongly authenticated workload identities, policy decision and enforcement separation, regionally resilient control-plane components, cached and short-lived policy artifacts where safe, and explicit auditability. The design would include graceful degradation rules, revocation mechanisms, comprehensive telemetry, and recurring adversarial testing.

Describe how you would safely migrate a large fleet from a legacy service-to-service authentication mechanism to a new identity platform.

I would inventory dependencies and compatibility requirements, define measurable security and reliability success criteria, and build an interoperable migration layer. I would roll out in stages using canaries, shadow validation, observability dashboards, and clear rollback paths, prioritizing critical services and high-risk access paths. Throughout the migration, I would maintain stakeholder alignment, document operational procedures, and remove the legacy path only after adoption and incident-readiness criteria are met.

What are the main security considerations for a key-management platform used by critical production services?

Key material should be protected through strict access controls, hardware-backed protections where appropriate, separation of duties, audited administrative actions, and encryption in transit and at rest. The platform needs robust key generation, rotation, revocation, backup, recovery, and deletion workflows, as well as tenant and environment isolation. I would also model compromise scenarios, limit blast radius through scoped credentials, and continuously monitor anomalous key access or use.

How do you conduct a threat model for a new secure egress proxy?

I first map assets, actors, trust boundaries, data flows, administrative interfaces, and dependencies. I then identify threats such as credential theft, SSRF, policy bypass, DNS manipulation, traffic interception, data exfiltration, and denial of service, ranking them by likelihood and impact. Mitigations would include strong workload identity, default-deny policy enforcement, destination validation, encrypted transport, tamper-evident logging, rate controls, and regular security testing tied to clear owners.

How would you use AI agents responsibly to improve infrastructure-security detection and response?

I would start with constrained, observable use cases such as alert enrichment, log correlation, configuration-drift triage, and proposed remediation steps. Agents should operate with least-privilege access, human approval for consequential actions, comprehensive audit trails, deterministic guardrails, and evaluation against known attack and failure scenarios. Their output should augment security engineers rather than become an unreviewed control plane, with continuous measurement of false positives, missed detections, and operational impact.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.

About the Team

Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity.

The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but operational in how we execute, and we support every product and research effort at OpenAI. Our tenets include prioritizing for impact, enabling researchers and developers, preparing for future transformative technologies, and fostering a strong, collaborative security culture.

About the Role

OpenAI is seeking a Principal Software Engineer to join the Infrastructure Security (InfraSec) team. InfraSec safeguards the core of OpenAI’s research and production environments: GPU supercomputing clusters, multi-cloud infrastructure, datacenters, networking, storage, and the critical services that power our frontier AI models. Our charter spans everything from bare-metal hardware and firmware to Kubernetes clusters, service meshes, and the data pathways that carry highly sensitive model weights and user data.

As a Principal Software Engineer, you will set technical direction and drive execution of critical foundational services, such as authentication systems, egress/ingress proxies, access brokers, and key management platforms, that demand high standards of reliability, scalability, and software craftsmanship. These systems form the security backbone of OpenAI’s customer and supercomputing environment and must remain robust under intense scale and adversarial pressure.

In this role, you will:

  • Own the architecture and roadmap for one or more core security services (e.g., authN/Z, policy enforcement, secure proxies, key management), taking them from design to rollout to long-term operation.

  • Design and implement planet-scale security systems that provide strong guarantees across hardware, operating systems, Kubernetes, networks, and CI/CD: balancing security, reliability, latency, and developer ergonomics.

  • Lead cross-functional launches with infrastructure and research engineering teams, shaping interfaces, migration plans, and safe rollout strategies across large fleets and critical workflows.

  • Build or evolve security primitives (identity, attestation, authorization, encryption key lifecycle, access mediation) that become platform building blocks for OpenAI.

  • Leverage frontier models and agents to develop automation and detection tooling to continuously identify and mitigate risks in large-scale cloud and on-prem environments.

  • Lead design reviews and threat models for major initiatives, and drive closure on systemic issues.

  • Mentor engineers across InfraSec and partner teams, raising the bar on engineering quality, operational readiness, and secure-by-default practices.

You will thrive in this role if you have:

  • Strong software engineering skills with a track record of shipping and operating reliable distributed systems in production.

  • Experience building or operating critical infrastructure, especially security infrastructure, at planet scale (e.g., auth services, service-to-service proxies, certificate or key-management systems).

  • Deep understanding of security principles, best practices, and common vulnerabilities.

  • Demonstrated ability to lead cross-team technical initiatives: setting direction, aligning stakeholders, driving execution, and delivering measurable outcomes.

  • Expertise and curiosity about using frontier models and agents to effectively solve security challenges.

  • Expertise in securing large-scale cloud platforms (e.g., Azure, AWS, GCP), including multi-cloud networks and cloud-agnostic system design.

  • A proactive mindset, with the ability to identify and address security gaps or inefficiencies through automation and tooling.

  • Strong analytical and problem-solving skills, with an ability to think critically and objectively assess risks.

  • Excellent communication skills, with the ability to convey complex security concepts to executive, technical, and non-technical stakeholders.

About OpenAI

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.

We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.

For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement.

Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.

To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.

OpenAI Global Applicant Privacy Policy

At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. View safety guidance.

Log in to save
One quick step before you apply

Create your free account, then apply.

Build a more organized job search on Jobicy and continue to the employer's application when you're ready.

  • Never lose a promising opportunitySave roles and return to them from your dashboard.
  • See your entire search at a glanceTrack applications, stages and next steps in one place.
  • Get matched with relevant remote jobsChoose the alerts and digests that work for you.
Applying is free. The employer's application opens in a new tab.
Add alert
Jobs Talent AI Tools Salaries
Menu