[![Image]() Meet Jobicy Copilot — free AI autofill for job applications + remote job alerts ›](#)   [All remote jobs](https://jobicy.com/jobs.md)Open role[![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)](https://jobicy.com/company/openai.md)Remote opportunity at[OpenAI](https://jobicy.com/company/openai.md)

# Principal Software Engineer, Infrastructure Security

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/openai.md)Share21 Sep 2026Published40Listing views1Application actions21 Oct 2026Apply before  Opportunity details

## About this role.

AI SummaryThis principal-level infrastructure security role owns the technical direction, delivery, and long-term operation of foundational security services for OpenAI’s research and production environments. The engineer will build and operate high-scale identity, authorization, proxy, attestation, and key-management capabilities spanning hardware, cloud, Kubernetes, networking, and CI/CD systems. The role requires leading complex cross-functional launches, driving threat modeling and systemic risk remediation, and mentoring senior engineers. Success depends on exceptional distributed-systems engineering, deep cloud-security expertise, and the ability to balance strong security guarantees with reliability, latency, and developer experience. It also includes applying frontier AI models and agents to security automation and detection challenges.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

5/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThis is a principal role responsible for security-critical services operating across planet-scale, adversarially exposed infrastructure. It requires rare depth across distributed systems, cloud and platform security, architecture, operations, and organization-wide technical leadership.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianHighly competitive$455,500US market range$300k–$550k0$605k

AI insightThe disclosed annual base compensation range is USD 401,000 to USD 510,000, with a midpoint of USD 455,500. This is a highly competitive range for a US-based principal infrastructure security engineer; the broader estimated US market range for comparable seniority and scope is approximately USD 300,000 to USD 550,000 annually, excluding equity, bonuses, and other compensation components.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Infrastructure Security](https://jobicy.com/jobs?search_keywords=Infrastructure%20Security.md)[Distributed Systems](https://jobicy.com/jobs?search_keywords=Distributed%20Systems.md)[Cloud Security](https://jobicy.com/jobs?search_keywords=Cloud%20Security.md)[Kubernetes](https://jobicy.com/jobs?search_keywords=Kubernetes.md)[Identity and Access Management](https://jobicy.com/jobs?search_keywords=Identity%20and%20Access%20Management.md)[Authentication and Authorization](https://jobicy.com/jobs?search_keywords=Authentication%20and%20Authorization.md)[Key Management](https://jobicy.com/jobs?search_keywords=Key%20Management.md)[Network Security](https://jobicy.com/jobs?search_keywords=Network%20Security.md)[Threat Modeling](https://jobicy.com/jobs?search_keywords=Threat%20Modeling.md)[Technical Leadership](https://jobicy.com/jobs?search_keywords=Technical%20Leadership.md)

Sample interview questionsHow would you design a highly available authorization service for workloads across multiple clouds and on-premises infrastructure?I would begin by defining the trust boundaries, request latency objectives, availability targets, and failure behavior. I would use strongly authenticated workload identities, policy decision and enforcement separation, regionally resilient control-plane components, cached and short-lived policy artifacts where safe, and explicit auditability. The design would include graceful degradation rules, revocation mechanisms, comprehensive telemetry, and recurring adversarial testing.

Describe how you would safely migrate a large fleet from a legacy service-to-service authentication mechanism to a new identity platform.

I would inventory dependencies and compatibility requirements, define measurable security and reliability success criteria, and build an interoperable migration layer. I would roll out in stages using canaries, shadow validation, observability dashboards, and clear rollback paths, prioritizing critical services and high-risk access paths. Throughout the migration, I would maintain stakeholder alignment, document operational procedures, and remove the legacy path only after adoption and incident-readiness criteria are met.

What are the main security considerations for a key-management platform used by critical production services?

Key material should be protected through strict access controls, hardware-backed protections where appropriate, separation of duties, audited administrative actions, and encryption in transit and at rest. The platform needs robust key generation, rotation, revocation, backup, recovery, and deletion workflows, as well as tenant and environment isolation. I would also model compromise scenarios, limit blast radius through scoped credentials, and continuously monitor anomalous key access or use.

How do you conduct a threat model for a new secure egress proxy?

I first map assets, actors, trust boundaries, data flows, administrative interfaces, and dependencies. I then identify threats such as credential theft, SSRF, policy bypass, DNS manipulation, traffic interception, data exfiltration, and denial of service, ranking them by likelihood and impact. Mitigations would include strong workload identity, default-deny policy enforcement, destination validation, encrypted transport, tamper-evident logging, rate controls, and regular security testing tied to clear owners.

How would you use AI agents responsibly to improve infrastructure-security detection and response?

I would start with constrained, observable use cases such as alert enrichment, log correlation, configuration-drift triage, and proposed remediation steps. Agents should operate with least-privilege access, human approval for consequential actions, comprehensive audit trails, deterministic guardrails, and evaluation against known attack and failure scenarios. Their output should augment security engineers rather than become an unreviewed control plane, with continuous measurement of false positives, missed detections, and operational impact.

About the Team

Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity.

The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but operational in how we execute, and we support every product and research effort at OpenAI. Our tenets include prioritizing for impact, enabling researchers and developers, preparing for future transformative technologies, and fostering a strong, collaborative security culture.

About the Role

OpenAI is seeking a Principal Software Engineer to join the Infrastructure Security (InfraSec) team. InfraSec safeguards the core of OpenAI’s research and production environments: GPU supercomputing clusters, multi-cloud infrastructure, datacenters, networking, storage, and the critical services that power our frontier AI models. Our charter spans everything from bare-metal hardware and firmware to Kubernetes clusters, service meshes, and the data pathways that carry highly sensitive model weights and user data.

As a Principal Software Engineer, you will set technical direction and drive execution of critical foundational services, such as authentication systems, egress/ingress proxies, access brokers, and key management platforms, that demand high standards of reliability, scalability, and software craftsmanship. These systems form the security backbone of OpenAI’s customer and supercomputing environment and must remain robust under intense scale and adversarial pressure.

In this role, you will:

*

Own the architecture and roadmap for one or more core security services (e.g., authN/Z, policy enforcement, secure proxies, key management), taking them from design to rollout to long-term operation.

*

Design and implement planet-scale security systems that provide strong guarantees across hardware, operating systems, Kubernetes, networks, and CI/CD: balancing security, reliability, latency, and developer ergonomics.

*

Lead cross-functional launches with infrastructure and research engineering teams, shaping interfaces, migration plans, and safe rollout strategies across large fleets and critical workflows.

*

Build or evolve security primitives (identity, attestation, authorization, encryption key lifecycle, access mediation) that become platform building blocks for OpenAI.

*

Leverage frontier models and agents to develop automation and detection tooling to continuously identify and mitigate risks in large-scale cloud and on-prem environments.

*

Lead design reviews and threat models for major initiatives, and drive closure on systemic issues.

*

Mentor engineers across InfraSec and partner teams, raising the bar on engineering quality, operational readiness, and secure-by-default practices.

You will thrive in this role if you have:

*

Strong software engineering skills with a track record of shipping and operating reliable distributed systems in production.

*

Experience building or operating critical infrastructure, especially security infrastructure, at planet scale (e.g., auth services, service-to-service proxies, certificate or key-management systems).

*

Deep understanding of security principles, best practices, and common vulnerabilities.

*

Demonstrated ability to lead cross-team technical initiatives: setting direction, aligning stakeholders, driving execution, and delivering measurable outcomes.

*

Expertise and curiosity about using frontier models and agents to effectively solve security challenges.

*

Expertise in securing large-scale cloud platforms (e.g., Azure, AWS, GCP), including multi-cloud networks and cloud-agnostic system design.

*

A proactive mindset, with the ability to identify and address security gaps or inefficiencies through automation and tooling.

*

Strong analytical and problem-solving skills, with an ability to think critically and objectively assess risks.

*

Excellent communication skills, with the ability to convey complex security concepts to executive, technical, and non-technical stakeholders.

About OpenAI

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.

We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.

For additional information, please see [OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement](https://cdn.openai.com/policies/eeo-policy-statement.pdf).

Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.

To notify OpenAI that you believe this job posting is non-compliant, please submit a report through [this form](https://form.asana.com/?d=57018692298241&k=5MqR40fZd7jlxVUh5J-UeA). No response will be provided to inquiries unrelated to job posting compliance.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this [link](https://form.asana.com/?k=bQ7w9h3iexRlicUdWRiwvg&d=57018692298241).

[OpenAI Global Applicant Privacy Policy](https://cdn.openai.com/policies/global-employee-and-contractor-privacy-policy.pdf)

At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

Show more

[Apply now >](https://jobicy.com/jobs/153845-principal-software-engineer-infrastructure-security.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI  Sep 21

### [Principal Security Engineer, Infrastructure Security](https://jobicy.com/jobs/153841-principal-security-engineer-infrastructure-security.md)

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products….

*
![DeleteMe logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/c26c546a-221.png)
DeleteMe  Sep 21

### [Privacy Advisor](https://jobicy.com/jobs/153793-privacy-advisor.md)

DeleteMe is the leader in proactive privacy protection. We help Individuals, Families, Businesses and Security teams reduce their human attack surface by continuously monitoring and removing exposed personal data (PII)…

*
![Oddball logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2022/02/8c034287ffd7b6474f90645b1c72e60a.jpeg)
Oddball  Sep 21

### [ATO Specialist](https://jobicy.com/jobs/153774-ato-specialist.md)

Oddball believes that the best products are built when companies understand and value the things they are working on. We value learning and growth and the ability to make a…

*
![DuckDuckGo logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/11/ab8415dd5798a360323ce06beaf30c35.png)
DuckDuckGo  Sep 21

### [Senior Web Security Engineer, Browser Platform](https://jobicy.com/jobs/151281-senior-web-security-engineer-browser-platform.md)

Who We Are Hi, we’re DuckDuckGo, the online protection company and remote-first team of 300+ on a mission to raise the standard of trust online. Founded in 2008 and profitable…

*
![Fastly logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/10/127f9e4bbbdb8767bef358a23bf7f73d.jpeg)
Fastly  Sep 20

### [Senior Security Technical Account Manager](https://jobicy.com/jobs/153750-senior-security-technical-account-manager.md)

Fastly helps people stay better connected with the things they love. Fastly’s edge cloud platform enables customers to create great digital experiences quickly, securely, and reliably by processing, serving, and…

*
![SkySlope logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2022/01/1e0d9f0517a4959cdef118a420f873a6.jpeg)
SkySlope  Sep 20

### [Security Engineering Manager](https://jobicy.com/jobs/153718-security-engineering-manager.md)

OUR ORIGIN STORY 🎂 In 2011 SkySlope started as an idea born at the kitchen table of our CEO, with just him and two others. Headquartered in Sacramento, California, we…

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI  Sep 20

### [Security Engineer, Insider Threat Detection & Response](https://jobicy.com/jobs/153709-security-engineer-insider-threat-detection-response.md)

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products….

*
![1Password logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/09/WRILS-200909195848-296323.png)
1Password  Sep 20

### [Senior Security Engineer, Incident Response](https://jobicy.com/jobs/153700-senior-security-engineer-incident-response.md)

1Password is growing. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up…

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI  Sep 20

### [Senior Technical Program Manager – Security](https://jobicy.com/jobs/151221-senior-technical-program-manager-security.md)

About the Team OpenAI builds powerful AI systems like ChatGPT, the OpenAI API, and enterprise products that serve millions of users across the globe. As we scale, securing our infrastructure,…

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI  Sep 20

### [Software Engineer, Security Observability](https://jobicy.com/jobs/151224-software-engineer-security-observability.md)

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products….