# Software Engineer, Codex -Enterprise Controls
**Company:** [OpenAI](https://scaleengineer.com/companies/openai)
As a Software Engineer on the Codex Enterprise Controls team at OpenAI, you'll design and operate backend systems that enable enterprises to safely deploy and govern AI-powered coding capabilities at scale. This role requires strong expertise in backend engineering, security architecture, identity systems, and enterprise infrastructure—with end-to-end ownership of systems spanning encryption, access controls, policy enforcement, and audit logging for some of the world's most sensitive codebases and organizational data.
**Role:** Backend Engineer
**Seniority:** Mid
**Locations:** San Francisco
**Salary:** 230000–385000 USD
[Apply](https://jobs.ashbyhq.com/openai/fff02c39-1185-427c-bf89-70d7eaa5e3db)
Canonical: https://scaleengineer.com/jobs/openai/software-engineer-codex-enterprise-controls
---
## Responsibilities

- Design and Build Enterprise Backend Systems: Architect and implement production-grade backend systems responsible for data protection, including encryption, key management, access controls, data isolation, and retention mechanisms. These systems will directly safeguard enterprise customer proprietary codebases and sensitive organizational data flowing through Codex.
- Develop the Codex Enterprise Control Plane: Design and operate the comprehensive control plane enabling enterprise administrators to configure, enforce, and monitor how Codex capabilities are deployed and utilized across users, teams, projects, and organizational environments, ensuring governance at scale.
- Build Policy and Governance Infrastructure: Create sophisticated policy systems allowing enterprises to enable or disable specific Codex features, define organizational constraints, implement capability-based access controls, and safely orchestrate rollouts of new AI-powered workflows while maintaining compliance.
- Develop Observable and Scalable Services: Build reliable, highly observable, and horizontally scalable microservices across identity and authentication, authorization frameworks, configuration management, comprehensive audit logging, compliance tracking, and enterprise administration interfaces.
- Cross-Functional Collaboration and Translation: Partner with product, security, infrastructure, go-to-market, and customer success teams to translate complex and often ambiguous enterprise requirements into clean, durable product capabilities and platform abstractions that balance security with usability.
- Define Enterprise-Grade Standards for AI Systems: Contribute to establishing what enterprise-grade reliability, security, and governance means for AI software engineering systems as Codex becomes an integrated trusted teammate within Fortune 500 organizations and large technical teams globally.

## Requirements

### education

- {"name":"Computer Science or Related Field","description":"Bachelor's degree in Computer Science, Computer Engineering, Software Engineering, or equivalent professional experience demonstrating deep technical fundamentals in distributed systems and software architecture."}

### technical

- {"name":"Backend System Design and Architecture","description":"Demonstrated expertise in designing, implementing, and operating distributed systems at scale with focus on reliability, performance, and observability patterns that production systems require."}
- {"name":"Production Backend Programming Languages","description":"Professional proficiency in one or more backend languages such as Python, Go, Rust, Java, or C++ with demonstrated ability to write clean, maintainable, well-tested code in large systems."}
- {"name":"Security Engineering Fundamentals","description":"Strong understanding of security architecture, encryption algorithms, key management systems, secure coding practices, cryptographic protocols, and threat modeling for protecting sensitive data in distributed systems."}
- {"name":"Identity and Access Management Systems","description":"Hands-on experience implementing or working with enterprise authentication and authorization systems including SSO/SAML/OIDC protocols, OAuth 2.0, SCIM provisioning, and Role-Based Access Control (RBAC) patterns."}
- {"name":"Enterprise Governance and Compliance Systems","description":"Experience building audit logging infrastructure, compliance controls, data governance frameworks, retention policies, and systems for tracking and reporting on sensitive operations for regulated environments."}
- {"name":"API Design and Microservices Architecture","description":"Capability to design clean, well-versioned APIs and develop loosely coupled microservices that can scale independently while maintaining strong consistency guarantees for security-sensitive operations."}

### experience

- {"name":"Backend Systems Development Experience","description":"Minimum 3-5 years of professional experience designing and implementing backend systems for production environments, with proven track record of shipping features that scale to millions of operations."}
- {"name":"Security or Infrastructure Engineering","description":"Specific experience with security systems, identity infrastructure, encryption systems, or enterprise platform engineering where understanding of compliance requirements and security best practices is essential."}
- {"name":"Enterprise Software Development","description":"Prior experience working with enterprise customers or building enterprise-focused products where understanding of organizational complexity, compliance requirements, and governance needs directly informed technical decisions."}
- {"name":"Ambiguous Problem-Solving in Fast-Moving Teams","description":"Comfortable operating in 0-to-1 environments where technical and product requirements evolve rapidly, with ability to make sound architectural decisions despite incomplete information and shifting priorities."}

## Skills

### required

- {"name":"Backend Software Engineering","description":"Mastery of backend engineering fundamentals including distributed systems concepts, concurrency patterns, performance optimization, and debugging complex production systems."}
- {"name":"Cryptography and Encryption Systems","description":"Working knowledge of encryption algorithms, key management infrastructure, certificate management, TLS/SSL protocols, and secure data handling patterns for protecting sensitive information."}
- {"name":"Identity and Access Control","description":"Practical expertise with authentication protocols (SAML, OAuth, OIDC), authorization patterns (RBAC, ABAC), directory services, and implementing principle of least privilege in complex systems."}
- {"name":"Cloud Infrastructure and DevOps","description":"Experience with containerization (Docker), orchestration (Kubernetes), cloud platforms (AWS, GCP, Azure), infrastructure-as-code, and deploying applications at scale with proper observability."}
- {"name":"Observability and Monitoring","description":"Ability to design and implement comprehensive logging, metrics collection, distributed tracing, and alerting systems that provide visibility into system behavior and enable rapid incident response."}
- {"name":"Audit Logging and Compliance","description":"Understanding of audit trail design, immutable logging infrastructure, compliance frameworks, data retention requirements, and building systems that satisfy regulatory and security audit needs."}

### preferred

- {"name":"AI/ML Systems Experience","description":"Familiarity with infrastructure and governance challenges specific to AI systems, including model deployment, data governance, prompt handling, and controlling access to sensitive model capabilities."}
- {"name":"Policy Engines and Rules Systems","description":"Experience designing or implementing policy evaluation engines, rules engines, or configuration management systems that allow non-technical users to define and enforce organizational rules."}
- {"name":"Multi-Tenancy Architecture","description":"Prior experience designing multi-tenant systems with strong data isolation guarantees, tenant customization, fair resource allocation, and billing systems that handle complex organizational hierarchies."}
- {"name":"OpenAI or LLM Platform Experience","description":"Prior experience with OpenAI's APIs or other large language model platforms, understanding of LLM capabilities, limitations, and security implications of deploying LLMs in enterprise contexts."}
- {"name":"SOC 2 or Enterprise Compliance","description":"First-hand experience building systems that achieve or maintain SOC 2 Type II certification, HIPAA compliance, or other enterprise compliance frameworks that require rigorous control implementation."}
- {"name":"Go or Rust Programming","description":"Strong proficiency in Go or Rust specifically, given the performance, concurrency, and memory safety requirements of building enterprise control plane infrastructure at scale."}

## Tech stack

### tools

- {"name":"Kubernetes","description":"Container orchestration platform for deploying and managing backend services at scale with strong isolation, health checking, and automated rollout capabilities."}
- {"name":"Docker","description":"Containerization platform enabling consistent deployment, reproducible builds, and clear isolation between services in the enterprise control plane infrastructure."}
- {"name":"Terraform or CloudFormation","description":"Infrastructure-as-code tools for provisioning and managing cloud resources, ensuring reproducible and auditable infrastructure changes in a secure manner."}
- {"name":"Prometheus and Grafana","description":"Monitoring and visualization stack for collecting metrics, setting up alerting, and providing dashboards for observing system health and performance of security-critical services."}
- {"name":"ELK Stack or Cloud Logging","description":"Centralized logging infrastructure for aggregating logs from all enterprise control plane services, enabling structured querying and compliance audit trail maintenance."}

### others

- {"name":"OAuth 2.0 and OpenID Connect","description":"Industry-standard protocols for secure delegation of authentication and authorization, enabling enterprises to integrate Codex with their existing identity providers."}
- {"name":"SAML 2.0","description":"Enterprise federated identity standard enabling single sign-on and enabling organizations to manage Codex access through existing Active Directory and identity management systems."}
- {"name":"SCIM","description":"System for Cross-domain Identity Management standard enabling automated provisioning and deprovisioning of users across Codex as organizational structure changes."}
- {"name":"Encryption Standards (AES-256, RSA)","description":"Industry-standard encryption algorithms for at-rest and in-transit data protection, key management, and ensuring compliance with organizational security requirements."}
- {"name":"TLS/SSL Protocols","description":"Secure communication protocols ensuring encrypted transport of sensitive data between client applications and Codex backend services and between internal services."}

### databases

- {"name":"PostgreSQL","description":"Primary relational database for storing enterprise configuration, audit logs, identity information, and ensuring ACID compliance for security-critical data with strong consistency guarantees."}
- {"name":"Redis","description":"In-memory cache and session store for high-performance access control decisions, policy evaluation caching, and rate limiting in the enterprise control plane."}
- {"name":"Elasticsearch","description":"Distributed search and analytics engine for indexing and querying large volumes of audit logs, enabling compliance officers and security teams to investigate and report on system usage."}

### languages

- {"name":"Python","description":"Primary language for backend service development, scripting automation, and leveraging the rich ecosystem of libraries for security and data handling at OpenAI."}
- {"name":"Go","description":"Used for building high-performance, concurrent backend services, CLIs, and infrastructure tooling with strong typing and rapid compilation enabling quick iteration."}
- {"name":"Rust","description":"Employed for systems requiring maximum performance, memory safety guarantees, and security-critical components where preventing entire categories of vulnerabilities is essential."}

### frameworks

- {"name":"FastAPI or Flask","description":"Python web frameworks for building REST APIs and GraphQL backends serving enterprise control plane interfaces with strong typing support and built-in validation."}
- {"name":"gRPC","description":"High-performance RPC framework for inter-service communication enabling efficient, strongly-typed service-to-service protocols with built-in support for streaming and multiplexing."}
- {"name":"SQLAlchemy","description":"Python ORM for database abstraction, query building, and managing complex data models in enterprise control plane systems with support for migrations and multi-database backends."}

## Benefits

### benefits

- {"name":"Comprehensive Health Insurance","description":"Medical, dental, and vision coverage with competitive premiums and coverage for preventive care, chosen medical procedures, and specialist consultations."}
- {"name":"Retirement Planning","description":"401(k) retirement plans with company matching contributions enabling tax-advantaged savings for long-term financial security."}
- {"name":"Equity and Stock Options","description":"Meaningful equity grants aligning employee and company interests, providing ownership stake and long-term wealth creation potential as OpenAI's AI products reach global scale."}
- {"name":"Paid Time Off","description":"Generous vacation, sick leave, and personal days enabling work-life balance, mental health, and flexibility for personal circumstances."}
- {"name":"Professional Development","description":"Learning budgets, conference attendance, internal training programs, and opportunities to work on cutting-edge AI systems and contribute to research publications."}
- {"name":"Flexible Work Environment","description":"Collaborative office spaces with modern amenities, technical infrastructure, and flexible work arrangements supporting both focused technical work and team collaboration."}
- {"name":"Life and Disability Insurance","description":"Life insurance coverage and long-term disability protection providing financial security for employees and their families."}
- {"name":"Mental Health and Wellness","description":"Access to mental health counseling, wellness programs, fitness resources, and employee assistance programs supporting overall wellbeing."}
- {"name":"Commuter Benefits","description":"Pre-tax commuter benefits for public transportation, parking, or vanpool arrangements in the San Francisco Bay Area."}

## Compensation

- **max:** 300000
- **min:** 180000
- **currency:** USD
- **stockOptions:** true

## Interview process

### steps

- {"name":"Initial Screening and Phone Screen","description":"Initial conversation with a recruiter to discuss background, experience with backend systems and security engineering, career motivation, and alignment with the Codex Enterprise Controls mission. Typically 30-45 minutes."}
- {"name":"Technical Phone Screen","description":"Detailed technical discussion with a backend engineer on the team covering distributed systems design, backend architecture decisions, and approaches to solving complex backend engineering problems. Candidates should be prepared to discuss specific projects and technical tradeoffs."}
- {"name":"System Design Interview","description":"Live technical interview focusing on designing large-scale backend systems with security, compliance, and observability requirements. You'll be asked to architect solutions for problems like building enterprise audit logging, implementing access control systems, or designing a multi-tenant control plane."}
- {"name":"Security and Infrastructure Deep Dive","description":"Technical interview exploring expertise in security engineering, encryption, identity systems, compliance frameworks, and enterprise infrastructure patterns. Expect questions about threat modeling, key rotation strategies, and implementing compliance controls."}
- {"name":"Behavioral and Team Fit","description":"Conversation with a hiring manager or senior team member focused on communication style, working in ambiguous environments, cross-functional collaboration, and your approach to balancing security, velocity, and technical debt in fast-moving teams."}
- {"name":"Leadership and Vision Discussion","description":"Final round with a senior engineer or team lead exploring your vision for enterprise-grade AI systems, how you approach building foundational platform capabilities, and your perspective on the intersection of AI adoption and enterprise governance."}

## Full description
**About the Team**

With Codex we’re building an AI software engineer. One that you can pair with, delegate to, or even ask to take on future tasks proactively. Our team is a fast-moving group within OpenAI, bringing together research, engineering, design, and product. We iteratively build the Codex agent harness and product to get the most out of the model, and we iteratively train the model to be great at complex software engineering tasks.

The Codex team is responsible for building state-of-the-art AI systems that can write code, reason about software, and act as intelligent agents for developers and non-developers alike. We operate across research, engineering, product, and infrastructure; owning the full lifecycle of experimentation, deployment, and iteration on novel coding capabilities.

Codex Enterprise builds the ecosystem, governance, and enterprise capabilities that help Codex spread across developers, teams, and organizations worldwide. The Enterprise Controls team owns the systems that allow companies to safely deploy Codex across their organization while protecting their most sensitive code, data, and internal knowledge.

**About the Role**

As Codex adoption grows inside large organizations, customers are increasingly trusting Codex with their most valuable assets: proprietary codebases, internal documentation, customer data, and sensitive workflows.

This role will help build the enterprise control plane that makes Codex secure, governable, and trustworthy at scale. You will design and operate backend systems that give enterprise administrators visibility and control over how Codex is used across their organization.

You will work across identity, access, encryption, policy enforcement, auditability, and admin controls. This may include systems that let customers manage encryption keys, control which Codex capabilities are enabled, enforce organizational policies, and understand how data flows through Codex.

This role owns systems end-to-end: from architecture and implementation to production operations, with a strong bias for security, reliability, quality, and velocity.

**In this role, you will:**

* Build backend systems that protect enterprise customer data, including encryption, key management, access controls, data isolation, retention controls, and secure data handling patterns.
* Design and operate the Codex enterprise control plane, enabling administrators to configure, enforce, and audit how Codex is used across users, teams, projects, and environments.
* Build policy and governance systems that allow enterprises to enable or disable specific Codex capabilities, define organizational constraints, and safely roll out new AI-powered workflows.
* Develop reliable, observable, and scalable services across identity, authorization, configuration, audit logging, compliance, and enterprise administration.
* Partner closely with product, security, infrastructure, GTM, and customer-facing teams to translate complex enterprise requirements into simple, durable product and platform capabilities.
* Help define what “enterprise-grade” means for AI software engineering systems as Codex becomes a trusted teammate inside the world’s largest organizations.

**You might thrive in this role if you:**

* Have strong backend software engineering fundamentals and experience building production-grade distributed systems.
* Are proficient in one or more backend languages such as Python, Go, Rust, Java, or C++.
* Have experience with security, identity, authorization, encryption, key management, policy systems, or enterprise governance.
* Understand enterprise foundations such as SSO/SAML/OIDC, SCIM, RBAC, audit logging, compliance controls, and data governance.
* Enjoy building foundational platform capabilities that unlock many product surfaces and customer workflows.
* Are comfortable working across ambiguous technical and product requirements, especially in fast-moving 0 → 1 environments.
* Care deeply about reliability, security, observability, and customer trust.

**About OpenAI**

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity. 

We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic. 

For additional information, please see [OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement](https://cdn.openai.com/policies/eeo-policy-statement.pdf).

Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.

To notify OpenAI that you believe this job posting is non-compliant, please submit a report through [this form](https://form.asana.com/?d=57018692298241&k=5MqR40fZd7jlxVUh5J-UeA). No response will be provided to inquiries unrelated to job posting compliance.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this [link](https://form.asana.com/?k=bQ7w9h3iexRlicUdWRiwvg&d=57018692298241).

[OpenAI Global Applicant Privacy Policy](https://cdn.openai.com/policies/global-employee-and-contractor-privacy-policy.pdf)

At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.
