Software Engineer, Codex -Enterprise Controls
Backend Engineer · Mid · Full Time
Opens OpenAI's application page
Role
What you'll do.
As a Software Engineer on the Codex Enterprise Controls team at OpenAI, you'll design and operate backend systems that enable enterprises to safely deploy and govern AI-powered coding capabilities at scale. This role requires strong expertise in backend engineering, security architecture, identity systems, and enterprise infrastructure—with end-to-end ownership of systems spanning encryption, access controls, policy enforcement, and audit logging for some of the world's most sensitive codebases and organizational data.
Responsibilities
- Design and Build Enterprise Backend Systems: Architect and implement production-grade backend systems responsible for data protection, including encryption, key management, access controls, data isolation, and retention mechanisms. These systems will directly safeguard enterprise customer proprietary codebases and sensitive organizational data flowing through Codex.
- Develop the Codex Enterprise Control Plane: Design and operate the comprehensive control plane enabling enterprise administrators to configure, enforce, and monitor how Codex capabilities are deployed and utilized across users, teams, projects, and organizational environments, ensuring governance at scale.
- Build Policy and Governance Infrastructure: Create sophisticated policy systems allowing enterprises to enable or disable specific Codex features, define organizational constraints, implement capability-based access controls, and safely orchestrate rollouts of new AI-powered workflows while maintaining compliance.
- Develop Observable and Scalable Services: Build reliable, highly observable, and horizontally scalable microservices across identity and authentication, authorization frameworks, configuration management, comprehensive audit logging, compliance tracking, and enterprise administration interfaces.
- Cross-Functional Collaboration and Translation: Partner with product, security, infrastructure, go-to-market, and customer success teams to translate complex and often ambiguous enterprise requirements into clean, durable product capabilities and platform abstractions that balance security with usability.
- Define Enterprise-Grade Standards for AI Systems: Contribute to establishing what enterprise-grade reliability, security, and governance means for AI software engineering systems as Codex becomes an integrated trusted teammate within Fortune 500 organizations and large technical teams globally.
Qualifications
What we look for.
Technical
Backend System Design and Architecture
Demonstrated expertise in designing, implementing, and operating distributed systems at scale with focus on reliability, performance, and observability patterns that production systems require.
Production Backend Programming Languages
Professional proficiency in one or more backend languages such as Python, Go, Rust, Java, or C++ with demonstrated ability to write clean, maintainable, well-tested code in large systems.
Security Engineering Fundamentals
Strong understanding of security architecture, encryption algorithms, key management systems, secure coding practices, cryptographic protocols, and threat modeling for protecting sensitive data in distributed systems.
Identity and Access Management Systems
Hands-on experience implementing or working with enterprise authentication and authorization systems including SSO/SAML/OIDC protocols, OAuth 2.0, SCIM provisioning, and Role-Based Access Control (RBAC) patterns.
Enterprise Governance and Compliance Systems
Experience building audit logging infrastructure, compliance controls, data governance frameworks, retention policies, and systems for tracking and reporting on sensitive operations for regulated environments.
API Design and Microservices Architecture
Capability to design clean, well-versioned APIs and develop loosely coupled microservices that can scale independently while maintaining strong consistency guarantees for security-sensitive operations.
Education
Computer Science or Related Field
Bachelor's degree in Computer Science, Computer Engineering, Software Engineering, or equivalent professional experience demonstrating deep technical fundamentals in distributed systems and software architecture.
Experience
Backend Systems Development Experience
Minimum 3-5 years of professional experience designing and implementing backend systems for production environments, with proven track record of shipping features that scale to millions of operations.
Security or Infrastructure Engineering
Specific experience with security systems, identity infrastructure, encryption systems, or enterprise platform engineering where understanding of compliance requirements and security best practices is essential.
Enterprise Software Development
Prior experience working with enterprise customers or building enterprise-focused products where understanding of organizational complexity, compliance requirements, and governance needs directly informed technical decisions.
Ambiguous Problem-Solving in Fast-Moving Teams
Comfortable operating in 0-to-1 environments where technical and product requirements evolve rapidly, with ability to make sound architectural decisions despite incomplete information and shifting priorities.
Skills
Required
Backend Software Engineering
Mastery of backend engineering fundamentals including distributed systems concepts, concurrency patterns, performance optimization, and debugging complex production systems.
Cryptography and Encryption Systems
Working knowledge of encryption algorithms, key management infrastructure, certificate management, TLS/SSL protocols, and secure data handling patterns for protecting sensitive information.
Identity and Access Control
Practical expertise with authentication protocols (SAML, OAuth, OIDC), authorization patterns (RBAC, ABAC), directory services, and implementing principle of least privilege in complex systems.
Cloud Infrastructure and DevOps
Experience with containerization (Docker), orchestration (Kubernetes), cloud platforms (AWS, GCP, Azure), infrastructure-as-code, and deploying applications at scale with proper observability.
Observability and Monitoring
Ability to design and implement comprehensive logging, metrics collection, distributed tracing, and alerting systems that provide visibility into system behavior and enable rapid incident response.
Audit Logging and Compliance
Understanding of audit trail design, immutable logging infrastructure, compliance frameworks, data retention requirements, and building systems that satisfy regulatory and security audit needs.
Preferred
AI/ML Systems Experience
Nice to haveFamiliarity with infrastructure and governance challenges specific to AI systems, including model deployment, data governance, prompt handling, and controlling access to sensitive model capabilities.
Policy Engines and Rules Systems
Nice to haveExperience designing or implementing policy evaluation engines, rules engines, or configuration management systems that allow non-technical users to define and enforce organizational rules.
Multi-Tenancy Architecture
Nice to havePrior experience designing multi-tenant systems with strong data isolation guarantees, tenant customization, fair resource allocation, and billing systems that handle complex organizational hierarchies.
OpenAI or LLM Platform Experience
Nice to havePrior experience with OpenAI's APIs or other large language model platforms, understanding of LLM capabilities, limitations, and security implications of deploying LLMs in enterprise contexts.
SOC 2 or Enterprise Compliance
Nice to haveFirst-hand experience building systems that achieve or maintain SOC 2 Type II certification, HIPAA compliance, or other enterprise compliance frameworks that require rigorous control implementation.
Go or Rust Programming
Nice to haveStrong proficiency in Go or Rust specifically, given the performance, concurrency, and memory safety requirements of building enterprise control plane infrastructure at scale.
Tech stack
Languages
Frameworks
Databases
Tools
Other
Compensation
Pay and benefits.
Base·USD 230,000 – 385,000
Equity·Stock options
Benefits
Comprehensive Health Insurance
Medical, dental, and vision coverage with competitive premiums and coverage for preventive care, chosen medical procedures, and specialist consultations.
Retirement Planning
401(k) retirement plans with company matching contributions enabling tax-advantaged savings for long-term financial security.
Equity and Stock Options
Meaningful equity grants aligning employee and company interests, providing ownership stake and long-term wealth creation potential as OpenAI's AI products reach global scale.
Paid Time Off
Generous vacation, sick leave, and personal days enabling work-life balance, mental health, and flexibility for personal circumstances.
Professional Development
Learning budgets, conference attendance, internal training programs, and opportunities to work on cutting-edge AI systems and contribute to research publications.
Flexible Work Environment
Collaborative office spaces with modern amenities, technical infrastructure, and flexible work arrangements supporting both focused technical work and team collaboration.
Life and Disability Insurance
Life insurance coverage and long-term disability protection providing financial security for employees and their families.
Mental Health and Wellness
Access to mental health counseling, wellness programs, fitness resources, and employee assistance programs supporting overall wellbeing.
Commuter Benefits
Pre-tax commuter benefits for public transportation, parking, or vanpool arrangements in the San Francisco Bay Area.
Process
Interview steps.
- 01
Initial Screening and Phone Screen
Initial conversation with a recruiter to discuss background, experience with backend systems and security engineering, career motivation, and alignment with the Codex Enterprise Controls mission. Typically 30-45 minutes.
- 02
Technical Phone Screen
Detailed technical discussion with a backend engineer on the team covering distributed systems design, backend architecture decisions, and approaches to solving complex backend engineering problems. Candidates should be prepared to discuss specific projects and technical tradeoffs.
- 03
System Design Interview
Live technical interview focusing on designing large-scale backend systems with security, compliance, and observability requirements. You'll be asked to architect solutions for problems like building enterprise audit logging, implementing access control systems, or designing a multi-tenant control plane.
- 04
Security and Infrastructure Deep Dive
Technical interview exploring expertise in security engineering, encryption, identity systems, compliance frameworks, and enterprise infrastructure patterns. Expect questions about threat modeling, key rotation strategies, and implementing compliance controls.
- 05
Behavioral and Team Fit
Conversation with a hiring manager or senior team member focused on communication style, working in ambiguous environments, cross-functional collaboration, and your approach to balancing security, velocity, and technical debt in fast-moving teams.
- 06
Leadership and Vision Discussion
Final round with a senior engineer or team lead exploring your vision for enterprise-grade AI systems, how you approach building foundational platform capabilities, and your perspective on the intersection of AI adoption and enterprise governance.
Full posting
Original listing.
About the Team
With Codex we’re building an AI software engineer. One that you can pair with, delegate to, or even ask to take on future tasks proactively. Our team is a fast-moving group within OpenAI, bringing together research, engineering, design, and product. We iteratively build the Codex agent harness and product to get the most out of the model, and we iteratively train the model to be great at complex software engineering tasks.
The Codex team is responsible for building state-of-the-art AI systems that can write code, reason about software, and act as intelligent agents for developers and non-developers alike. We operate across research, engineering, product, and infrastructure; owning the full lifecycle of experimentation, deployment, and iteration on novel coding capabilities.
Codex Enterprise builds the ecosystem, governance, and enterprise capabilities that help Codex spread across developers, teams, and organizations worldwide. The Enterprise Controls team owns the systems that allow companies to safely deploy Codex across their organization while protecting their most sensitive code, data, and internal knowledge.
About the Role
As Codex adoption grows inside large organizations, customers are increasingly trusting Codex with their most valuable assets: proprietary codebases, internal documentation, customer data, and sensitive workflows.
This role will help build the enterprise control plane that makes Codex secure, governable, and trustworthy at scale. You will design and operate backend systems that give enterprise administrators visibility and control over how Codex is used across their organization.
You will work across identity, access, encryption, policy enforcement, auditability, and admin controls. This may include systems that let customers manage encryption keys, control which Codex capabilities are enabled, enforce organizational policies, and understand how data flows through Codex.
This role owns systems end-to-end: from architecture and implementation to production operations, with a strong bias for security, reliability, quality, and velocity.
In this role, you will:
Build backend systems that protect enterprise customer data, including encryption, key management, access controls, data isolation, retention controls, and secure data handling patterns.
Design and operate the Codex enterprise control plane, enabling administrators to configure, enforce, and audit how Codex is used across users, teams, projects, and environments.
Build policy and governance systems that allow enterprises to enable or disable specific Codex capabilities, define organizational constraints, and safely roll out new AI-powered workflows.
Develop reliable, observable, and scalable services across identity, authorization, configuration, audit logging, compliance, and enterprise administration.
Partner closely with product, security, infrastructure, GTM, and customer-facing teams to translate complex enterprise requirements into simple, durable product and platform capabilities.
Help define what “enterprise-grade” means for AI software engineering systems as Codex becomes a trusted teammate inside the world’s largest organizations.
You might thrive in this role if you:
Have strong backend software engineering fundamentals and experience building production-grade distributed systems.
Are proficient in one or more backend languages such as Python, Go, Rust, Java, or C++.
Have experience with security, identity, authorization, encryption, key management, policy systems, or enterprise governance.
Understand enterprise foundations such as SSO/SAML/OIDC, SCIM, RBAC, audit logging, compliance controls, and data governance.
Enjoy building foundational platform capabilities that unlock many product surfaces and customer workflows.
Are comfortable working across ambiguous technical and product requirements, especially in fast-moving 0 → 1 environments.
Care deeply about reliability, security, observability, and customer trust.
About OpenAI
OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.
We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.
For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement.
Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.
To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.
We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.
OpenAI Global Applicant Privacy Policy
At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.
Redirects to OpenAI's application page.
Other roles
More at OpenAI.
Systems Test Engineer, End-to-End Validation | Consumer Devices
Mid
Systems Integration Engineer, Build Systems | Consumer Devices
Senior
Software Security Architect, Operating Systems | Consumer Devices
Senior
Software Engineer, API Safety
Senior
Android Systems Engineer, Consumer Devices
Senior