Senior Staff Software Engineer, Identity

Staff · Staff · Full Time

San FranciscoUSD 345k – 405k2w ago
Apply for this role

Opens OpenAI's application page

Role

What you'll do.

Senior Staff Software Engineer at OpenAI leading the design and evolution of enterprise identity infrastructure serving the organization's growing multi-product portfolio. This hands-on technical leadership role requires owning the complete identity stack architecture including SSO, SCIM, tenant models, and permissions systems while driving organizational alignment and setting security standards for systems serving millions of enterprise users globally.

Responsibilities

  • Enterprise Identity Architecture Ownership: Own the complete technical vision and architecture for OpenAI's Enterprise Identity stack, encompassing SSO (Single Sign-On), SCIM (System for Cross-domain Identity Management), tenant architecture, group management, permissions systems, and identity capabilities across enterprise administration surfaces. Define the strategic direction for the multi-year evolution of these foundational systems.
  • Highly Available Systems Design: Lead the design and continuous evolution of highly available, latency-sensitive identity systems that reliably serve a large and diverse global enterprise customer base. Establish and maintain stringent reliability standards for identity infrastructure supporting mission-critical business operations across multiple products.
  • Identity Primitives Standardization: Establish common identity models and reusable primitives that work consistently across OpenAI's expanding product portfolio. Create shared abstractions and patterns that enable the organization to scale identity capabilities without duplicating infrastructure or creating technical debt.
  • Security and Threat Modeling: Set and enforce a high security bar by proactively anticipating abuse cases, identifying failure modes, and evaluating long-term security implications of new capabilities. Conduct adversarial design reviews and establish security patterns that prevent unauthorized access, privilege escalation, and identity-based attacks.
  • Cross-Functional Alignment and Leadership: Drive alignment across enterprise product teams, infrastructure engineering, platform security, and business partners. Resolve architectural ambiguity, influence upstream roadmaps, and ensure identity systems meet the needs of diverse organizational stakeholders while maintaining technical excellence.
  • Technical Leadership and Mentorship: Provide technical leadership to senior engineers and architects, raising the quality of architectural thinking and execution standards across the broader organization. Mentor high-performing engineers, establish best practices for distributed systems design, and create a culture of technical rigor within identity infrastructure teams.

Qualifications

What we look for.

Technical

  • Distributed Systems Architecture

    Expert-level experience designing, building, and operating large-scale distributed systems at the infrastructure or platform level. Must demonstrate mastery of consistency models, replication strategies, partitioning approaches, and failure recovery mechanisms in production environments serving millions of users.

  • Enterprise Identity Infrastructure

    Deep experience with enterprise identity protocols and systems including SSO implementations, SCIM provisioning systems, identity provider integration, OAuth/OpenID Connect flows, JWT authentication, multi-tenant identity models, and group/permission hierarchies in enterprise environments.

  • Tenant Architecture and Multi-Tenancy

    Proven expertise designing and implementing multi-tenant systems that achieve strong isolation, efficient resource utilization, and customizable identity policies for diverse enterprise customers. Experience with tenant-scoped data models, role-based access control (RBAC), and attribute-based access control (ABAC) systems.

  • Security-Focused Systems Design

    Security-first mindset with demonstrated ability to conduct threat modeling, anticipate adversarial attacks, evaluate failure modes, and design systems resistant to privilege escalation, unauthorized access, and identity-based attacks. Understanding of cryptographic primitives and their application to identity systems.

  • High Availability and Reliability Engineering

    Expert experience building systems that meet strict availability and latency SLAs. Knowledge of redundancy patterns, circuit breakers, graceful degradation, monitoring, observability, and incident response for business-critical infrastructure. Experience managing blast radius and preventing cascading failures.

  • API Design and Platform Thinking

    Ability to design clean, intuitive APIs that abstract complex identity operations and enable product teams to integrate securely. Experience establishing design patterns, maintaining backward compatibility, and evolving APIs with minimal friction to downstream consumers.

Education

  • Computer Science or Related Field

    Bachelor's degree in Computer Science, Software Engineering, Computer Engineering, or related technical discipline. Advanced degrees (Master's in Computer Science or related field) are valued but not required with sufficient professional experience at the Staff level.

Experience

  • Staff-Level Architecture Ownership

    5+ years of experience at Staff, Principal, or equivalent level owning the architecture of a broad, business-critical platform or large-scale distributed systems domain. Must demonstrate a track record of setting multi-year technical direction and successfully aligning multiple teams around complex architectural decisions with significant organizational impact.

  • Enterprise Product Scale

    Deep operational understanding of enterprise customer requirements, SLAs, and deployment models. Experience deploying systems to large enterprise customers, managing enterprise adoption challenges, and understanding the needs of complex multi-product environments with demanding reliability and security requirements.

  • Organizational Influence

    Demonstrated ability to influence technical roadmaps and architectural decisions across organizational boundaries without direct authority. Experience navigating ambiguity, building consensus among competing priorities, and executing complex initiatives requiring coordination across multiple teams and stakeholders.

  • Technical Leadership at Scale

    Experience mentoring and developing senior engineers and architects, establishing technical standards, conducting architecture reviews, and raising the quality bar for engineering execution across organizations. Proven ability to balance hands-on technical contribution with organizational leadership responsibilities.

Skills

Required

  • SSO and SAML/OpenID Connect

    Production experience implementing and operating SSO systems, SAML 2.0, OpenID Connect, and OAuth 2.0 protocols in enterprise environments. Understanding of federation, identity provider bridging, and session management in single sign-on architectures.

  • SCIM Provisioning

    Deep experience with System for Cross-domain Identity Management (SCIM) protocols and implementing user/group provisioning pipelines that synchronize identity data across enterprise systems with strong consistency guarantees.

  • Permissions and RBAC/ABAC

    Expert-level knowledge designing and implementing permission systems using Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), or Policy Decision Point (PDP) architectures. Experience with permission evaluation at scale and policy evaluation engines.

  • Distributed Systems Design

    Deep expertise in distributed systems principles including consistency models (strong vs eventual), replication, partitioning, consensus algorithms, and handling failure modes. Ability to make principled tradeoffs between consistency, availability, and partition tolerance.

  • High-Level Programming Languages

    Strong proficiency in at least one high-level programming language (Python, Go, Rust, Java, or TypeScript) with ability to write production-quality code and contribute directly to system implementations when needed.

  • Observability and Monitoring

    Expertise designing monitoring, logging, and observability strategies for complex systems. Experience with metrics collection, distributed tracing, log aggregation, and building alerting systems that provide visibility into system behavior and failures.

Preferred

  • Infrastructure and Kubernetes

    Nice to have

    Experience deploying and operating systems on cloud infrastructure (AWS, GCP, Azure) and container orchestration platforms like Kubernetes. Familiarity with infrastructure-as-code and managing complex, distributed deployments.

  • Multi-Tenant SaaS Architecture

    Nice to have

    Previous experience architecting and scaling multi-tenant SaaS platforms, particularly at high scale. Knowledge of tenant isolation strategies, billing systems, resource quotas, and customization patterns in SaaS environments.

  • Identity Standards and Compliance

    Nice to have

    Familiarity with enterprise identity standards including NIST guidelines, identity governance and administration (IGA), and regulatory compliance requirements (SOC 2, ISO 27001) relevant to enterprise identity systems.

  • Cryptography Fundamentals

    Nice to have

    Working knowledge of cryptographic principles, digital signatures, certificate management, and key rotation strategies. Understanding of how cryptography applies to authentication, authorization, and identity verification.

  • GraphQL and API Design

    Nice to have

    Experience designing and implementing GraphQL APIs or REST APIs at scale. Understanding of API versioning, backward compatibility, and creating intuitive interfaces for complex business logic.

  • Zero-Trust Architecture

    Nice to have

    Familiarity with zero-trust security principles, applying them to identity infrastructure, and implementing continuous authentication and authorization patterns in distributed environments.

Compensation

Pay and benefits.

Base·USD 345,000 – 405,000

Equity·Stock options

Benefits

  • Equity Compensation

    Competitive equity package with stock options reflecting your role as a Staff-level leader at a leading AI company. Equity provides upside participation in OpenAI's growth and long-term value creation.

  • Comprehensive Health Insurance

    Comprehensive medical, dental, and vision insurance plans with competitive employer contribution rates. Coverage extends to employees, spouses, domestic partners, and families.

  • Retirement Planning

    401(k) retirement savings plan with employer matching contributions to support long-term financial planning and wealth building.

  • Unlimited Paid Time Off

    Flexible paid time off policy enabling you to balance work commitments with personal well-being, family time, and professional development.

  • Professional Development

    Opportunities to attend industry conferences, pursue continuing education, and invest in your technical growth and professional development within an AI-focused organization.

  • Remote Work Flexibility

    While this role is based in San Francisco or Mountain View, you may have flexibility for remote work arrangements depending on business needs and team coordination.

  • AI and Technology Resources

    Access to cutting-edge AI models, research resources, and internal tools developed by OpenAI. Opportunity to work directly with advanced AI systems and contribute to frontier AI capabilities.

  • Parental Leave

    Generous parental leave policies supporting work-life balance during major life transitions.

Full posting

Original listing.

About the Team

The Enterprise Identity team builds the identity foundation that enables organizations to adopt and use OpenAI products securely and reliably. The team owns the enterprise identity stack, including SSO, SCIM, tenant architecture, and identity capabilities across the enterprise admin experience and OpenAI's growing multi-product portfolio.

About the Role

We are looking for a hands-on senior technical leader to own the architecture and evolution of OpenAI's Enterprise Identity systems. You will set the long-term technical vision for the entire stack, establish shared identity primitives across products, and be accountable for systems that are foundational to our enterprise business.

This role requires operating well beyond a single service or feature area. You will identify the most consequential architectural investments, align teams around durable solutions, and ensure our identity platform meets an exceptionally high bar for scale, availability, latency, and security.

This role will be based in our San Francisco or Mountain View office.

In this role, you will:

  • Own the technical vision and architecture for the Enterprise Identity stack, including SSO, SCIM, tenant architecture, groups, permissions, and identity capabilities in enterprise administration surfaces.

  • Lead the design and evolution of highly available, latency-sensitive identity systems serving a large and diverse global enterprise customer base.

  • Establish common identity models and primitives that work consistently across OpenAI's products and enable the organization to scale.

  • Set a high security bar by anticipating abuse cases, failure modes, and the long-term implications of new capabilities.

  • Drive alignment across enterprise product, infrastructure, and security partners, resolving ambiguity and influencing roadmaps beyond the immediate team.

  • Provide technical leadership to senior engineers and raise the quality of architecture and execution across the broader organization.

You might thrive in this role if you:

  • Have owned the architecture of a broad, business-critical platform or large-scale distributed-systems domain at the senior-staff level.

  • Have set multi-year technical direction and successfully aligned multiple teams around complex architectural decisions.

  • Understand enterprise identity, enterprise architecture, and the operational needs of large customers in multi-product environments.

  • Have experience with SSO, SCIM, identity providers, tenant models, permissions, groups, or adjacent identity infrastructure.

  • Bring a security-minded, adversarial approach to systems design and instinctively consider how capabilities could fail or be abused.

  • Can move between deep technical judgment, organizational influence, and hands-on leadership where it matters most.

About OpenAI

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity. 

We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.

For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement.

Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.

To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.

OpenAI Global Applicant Privacy Policy

At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

Redirects to OpenAI's application page.

Other roles

More at OpenAI.

View all 102 roles