Software Engineer, Codex -Enterprise Controls

Backend Engineer · Mid · Full Time

San FranciscoUSD 230k – 385k1mo ago
Apply for this role

Opens OpenAI's application page

Role

What you'll do.

As a Software Engineer on the Codex Enterprise Controls team at OpenAI, you'll design and operate backend systems that enable enterprises to safely deploy and govern AI-powered coding capabilities at scale. This role requires strong expertise in backend engineering, security architecture, identity systems, and enterprise infrastructure—with end-to-end ownership of systems spanning encryption, access controls, policy enforcement, and audit logging for some of the world's most sensitive codebases and organizational data.

Responsibilities

  • Design and Build Enterprise Backend Systems: Architect and implement production-grade backend systems responsible for data protection, including encryption, key management, access controls, data isolation, and retention mechanisms. These systems will directly safeguard enterprise customer proprietary codebases and sensitive organizational data flowing through Codex.
  • Develop the Codex Enterprise Control Plane: Design and operate the comprehensive control plane enabling enterprise administrators to configure, enforce, and monitor how Codex capabilities are deployed and utilized across users, teams, projects, and organizational environments, ensuring governance at scale.
  • Build Policy and Governance Infrastructure: Create sophisticated policy systems allowing enterprises to enable or disable specific Codex features, define organizational constraints, implement capability-based access controls, and safely orchestrate rollouts of new AI-powered workflows while maintaining compliance.
  • Develop Observable and Scalable Services: Build reliable, highly observable, and horizontally scalable microservices across identity and authentication, authorization frameworks, configuration management, comprehensive audit logging, compliance tracking, and enterprise administration interfaces.
  • Cross-Functional Collaboration and Translation: Partner with product, security, infrastructure, go-to-market, and customer success teams to translate complex and often ambiguous enterprise requirements into clean, durable product capabilities and platform abstractions that balance security with usability.
  • Define Enterprise-Grade Standards for AI Systems: Contribute to establishing what enterprise-grade reliability, security, and governance means for AI software engineering systems as Codex becomes an integrated trusted teammate within Fortune 500 organizations and large technical teams globally.

Qualifications

What we look for.

Technical

  • Backend System Design and Architecture

    Demonstrated expertise in designing, implementing, and operating distributed systems at scale with focus on reliability, performance, and observability patterns that production systems require.

  • Production Backend Programming Languages

    Professional proficiency in one or more backend languages such as Python, Go, Rust, Java, or C++ with demonstrated ability to write clean, maintainable, well-tested code in large systems.

  • Security Engineering Fundamentals

    Strong understanding of security architecture, encryption algorithms, key management systems, secure coding practices, cryptographic protocols, and threat modeling for protecting sensitive data in distributed systems.

  • Identity and Access Management Systems

    Hands-on experience implementing or working with enterprise authentication and authorization systems including SSO/SAML/OIDC protocols, OAuth 2.0, SCIM provisioning, and Role-Based Access Control (RBAC) patterns.

  • Enterprise Governance and Compliance Systems

    Experience building audit logging infrastructure, compliance controls, data governance frameworks, retention policies, and systems for tracking and reporting on sensitive operations for regulated environments.

  • API Design and Microservices Architecture

    Capability to design clean, well-versioned APIs and develop loosely coupled microservices that can scale independently while maintaining strong consistency guarantees for security-sensitive operations.

Education

  • Computer Science or Related Field

    Bachelor's degree in Computer Science, Computer Engineering, Software Engineering, or equivalent professional experience demonstrating deep technical fundamentals in distributed systems and software architecture.

Experience

  • Backend Systems Development Experience

    Minimum 3-5 years of professional experience designing and implementing backend systems for production environments, with proven track record of shipping features that scale to millions of operations.

  • Security or Infrastructure Engineering

    Specific experience with security systems, identity infrastructure, encryption systems, or enterprise platform engineering where understanding of compliance requirements and security best practices is essential.

  • Enterprise Software Development

    Prior experience working with enterprise customers or building enterprise-focused products where understanding of organizational complexity, compliance requirements, and governance needs directly informed technical decisions.

  • Ambiguous Problem-Solving in Fast-Moving Teams

    Comfortable operating in 0-to-1 environments where technical and product requirements evolve rapidly, with ability to make sound architectural decisions despite incomplete information and shifting priorities.

Skills

Required

  • Backend Software Engineering

    Mastery of backend engineering fundamentals including distributed systems concepts, concurrency patterns, performance optimization, and debugging complex production systems.

  • Cryptography and Encryption Systems

    Working knowledge of encryption algorithms, key management infrastructure, certificate management, TLS/SSL protocols, and secure data handling patterns for protecting sensitive information.

  • Identity and Access Control

    Practical expertise with authentication protocols (SAML, OAuth, OIDC), authorization patterns (RBAC, ABAC), directory services, and implementing principle of least privilege in complex systems.

  • Cloud Infrastructure and DevOps

    Experience with containerization (Docker), orchestration (Kubernetes), cloud platforms (AWS, GCP, Azure), infrastructure-as-code, and deploying applications at scale with proper observability.

  • Observability and Monitoring

    Ability to design and implement comprehensive logging, metrics collection, distributed tracing, and alerting systems that provide visibility into system behavior and enable rapid incident response.

  • Audit Logging and Compliance

    Understanding of audit trail design, immutable logging infrastructure, compliance frameworks, data retention requirements, and building systems that satisfy regulatory and security audit needs.

Preferred

  • AI/ML Systems Experience

    Nice to have

    Familiarity with infrastructure and governance challenges specific to AI systems, including model deployment, data governance, prompt handling, and controlling access to sensitive model capabilities.

  • Policy Engines and Rules Systems

    Nice to have

    Experience designing or implementing policy evaluation engines, rules engines, or configuration management systems that allow non-technical users to define and enforce organizational rules.

  • Multi-Tenancy Architecture

    Nice to have

    Prior experience designing multi-tenant systems with strong data isolation guarantees, tenant customization, fair resource allocation, and billing systems that handle complex organizational hierarchies.

  • OpenAI or LLM Platform Experience

    Nice to have

    Prior experience with OpenAI's APIs or other large language model platforms, understanding of LLM capabilities, limitations, and security implications of deploying LLMs in enterprise contexts.

  • SOC 2 or Enterprise Compliance

    Nice to have

    First-hand experience building systems that achieve or maintain SOC 2 Type II certification, HIPAA compliance, or other enterprise compliance frameworks that require rigorous control implementation.

  • Go or Rust Programming

    Nice to have

    Strong proficiency in Go or Rust specifically, given the performance, concurrency, and memory safety requirements of building enterprise control plane infrastructure at scale.

Tech stack

Languages

PythonGoRust

Frameworks

FastAPI or FlaskgRPCSQLAlchemy

Databases

PostgreSQLRedisElasticsearch

Tools

KubernetesDockerTerraform or CloudFormationPrometheus and GrafanaELK Stack or Cloud Logging

Other

OAuth 2.0 and OpenID ConnectSAML 2.0SCIMEncryption Standards (AES-256, RSA)TLS/SSL Protocols

Compensation

Pay and benefits.

Base·USD 230,000 – 385,000

Equity·Stock options

Benefits

  • Comprehensive Health Insurance

    Medical, dental, and vision coverage with competitive premiums and coverage for preventive care, chosen medical procedures, and specialist consultations.

  • Retirement Planning

    401(k) retirement plans with company matching contributions enabling tax-advantaged savings for long-term financial security.

  • Equity and Stock Options

    Meaningful equity grants aligning employee and company interests, providing ownership stake and long-term wealth creation potential as OpenAI's AI products reach global scale.

  • Paid Time Off

    Generous vacation, sick leave, and personal days enabling work-life balance, mental health, and flexibility for personal circumstances.

  • Professional Development

    Learning budgets, conference attendance, internal training programs, and opportunities to work on cutting-edge AI systems and contribute to research publications.

  • Flexible Work Environment

    Collaborative office spaces with modern amenities, technical infrastructure, and flexible work arrangements supporting both focused technical work and team collaboration.

  • Life and Disability Insurance

    Life insurance coverage and long-term disability protection providing financial security for employees and their families.

  • Mental Health and Wellness

    Access to mental health counseling, wellness programs, fitness resources, and employee assistance programs supporting overall wellbeing.

  • Commuter Benefits

    Pre-tax commuter benefits for public transportation, parking, or vanpool arrangements in the San Francisco Bay Area.

Process

Interview steps.

  1. 01

    Initial Screening and Phone Screen

    Initial conversation with a recruiter to discuss background, experience with backend systems and security engineering, career motivation, and alignment with the Codex Enterprise Controls mission. Typically 30-45 minutes.

  2. 02

    Technical Phone Screen

    Detailed technical discussion with a backend engineer on the team covering distributed systems design, backend architecture decisions, and approaches to solving complex backend engineering problems. Candidates should be prepared to discuss specific projects and technical tradeoffs.

  3. 03

    System Design Interview

    Live technical interview focusing on designing large-scale backend systems with security, compliance, and observability requirements. You'll be asked to architect solutions for problems like building enterprise audit logging, implementing access control systems, or designing a multi-tenant control plane.

  4. 04

    Security and Infrastructure Deep Dive

    Technical interview exploring expertise in security engineering, encryption, identity systems, compliance frameworks, and enterprise infrastructure patterns. Expect questions about threat modeling, key rotation strategies, and implementing compliance controls.

  5. 05

    Behavioral and Team Fit

    Conversation with a hiring manager or senior team member focused on communication style, working in ambiguous environments, cross-functional collaboration, and your approach to balancing security, velocity, and technical debt in fast-moving teams.

  6. 06

    Leadership and Vision Discussion

    Final round with a senior engineer or team lead exploring your vision for enterprise-grade AI systems, how you approach building foundational platform capabilities, and your perspective on the intersection of AI adoption and enterprise governance.

Full posting

Original listing.

About the Team

With Codex we’re building an AI software engineer. One that you can pair with, delegate to, or even ask to take on future tasks proactively. Our team is a fast-moving group within OpenAI, bringing together research, engineering, design, and product. We iteratively build the Codex agent harness and product to get the most out of the model, and we iteratively train the model to be great at complex software engineering tasks.

The Codex team is responsible for building state-of-the-art AI systems that can write code, reason about software, and act as intelligent agents for developers and non-developers alike. We operate across research, engineering, product, and infrastructure; owning the full lifecycle of experimentation, deployment, and iteration on novel coding capabilities.

Codex Enterprise builds the ecosystem, governance, and enterprise capabilities that help Codex spread across developers, teams, and organizations worldwide. The Enterprise Controls team owns the systems that allow companies to safely deploy Codex across their organization while protecting their most sensitive code, data, and internal knowledge.

About the Role

As Codex adoption grows inside large organizations, customers are increasingly trusting Codex with their most valuable assets: proprietary codebases, internal documentation, customer data, and sensitive workflows.

This role will help build the enterprise control plane that makes Codex secure, governable, and trustworthy at scale. You will design and operate backend systems that give enterprise administrators visibility and control over how Codex is used across their organization.

You will work across identity, access, encryption, policy enforcement, auditability, and admin controls. This may include systems that let customers manage encryption keys, control which Codex capabilities are enabled, enforce organizational policies, and understand how data flows through Codex.

This role owns systems end-to-end: from architecture and implementation to production operations, with a strong bias for security, reliability, quality, and velocity.

In this role, you will:

  • Build backend systems that protect enterprise customer data, including encryption, key management, access controls, data isolation, retention controls, and secure data handling patterns.

  • Design and operate the Codex enterprise control plane, enabling administrators to configure, enforce, and audit how Codex is used across users, teams, projects, and environments.

  • Build policy and governance systems that allow enterprises to enable or disable specific Codex capabilities, define organizational constraints, and safely roll out new AI-powered workflows.

  • Develop reliable, observable, and scalable services across identity, authorization, configuration, audit logging, compliance, and enterprise administration.

  • Partner closely with product, security, infrastructure, GTM, and customer-facing teams to translate complex enterprise requirements into simple, durable product and platform capabilities.

  • Help define what “enterprise-grade” means for AI software engineering systems as Codex becomes a trusted teammate inside the world’s largest organizations.

You might thrive in this role if you:

  • Have strong backend software engineering fundamentals and experience building production-grade distributed systems.

  • Are proficient in one or more backend languages such as Python, Go, Rust, Java, or C++.

  • Have experience with security, identity, authorization, encryption, key management, policy systems, or enterprise governance.

  • Understand enterprise foundations such as SSO/SAML/OIDC, SCIM, RBAC, audit logging, compliance controls, and data governance.

  • Enjoy building foundational platform capabilities that unlock many product surfaces and customer workflows.

  • Are comfortable working across ambiguous technical and product requirements, especially in fast-moving 0 → 1 environments.

  • Care deeply about reliability, security, observability, and customer trust.

About OpenAI

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity. 

We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.

For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement.

Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.

To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.

OpenAI Global Applicant Privacy Policy

At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

Redirects to OpenAI's application page.

Other roles

More at OpenAI.

View all 108 roles