Software Engineer, Codex Security

Full Stack Engineer · Mid · Full Time

San FranciscoUSD 230k – 325k1mo ago
Apply for this role

Opens OpenAI's application page

Role

What you'll do.

Join OpenAI's Codex Cyber team to build AI-native application security products that help organizations discover, validate, and remediate real vulnerabilities in software systems. This full-stack role combines product development, backend services, cloud infrastructure, and security analysis pipelines to create the next generation of intelligent vulnerability detection and remediation tools. You'll work as a high-agency software engineer with strong fundamentals across multiple domains, translating complex security research and AI capabilities into intuitive workflows for technical users in a fast-moving, early-stage team.

Responsibilities

  • Build end-to-end product features across the full stack: Design and implement complete features for Codex Security spanning user-facing interfaces, REST APIs, backend services, and workflow tooling. Own the full journey from concept through production deployment, ensuring cohesive experiences that integrate model outputs with security analysis and developer workflows.
  • Own ambiguous 0-to-1 projects and platform initiatives: Take ownership of greenfield projects across product pods, platform security controls, customer deployment workflows, and cyber model infrastructure. Navigate unclear requirements and translate them into crisp, scalable systems that advance OpenAI's security platform capabilities.
  • Translate security research into intuitive developer workflows: Partner with security researchers and ML teams to surface complex model capabilities through interfaces that help teams find, validate, prioritize, and remediate vulnerabilities with high signal. Make advanced security analysis understandable and actionable for technical users.
  • Design scalable systems for enterprise-grade security analysis: Architect observable, performant systems capable of executing long-running security analyses across large codebases and complex enterprise environments. Build infrastructure that scales analysis capabilities while maintaining reliability and data integrity.
  • Collaborate across engineering, product, research, and infrastructure teams: Work closely with product managers, security researchers, infrastructure engineers, and customer-facing partners to iterate rapidly based on real-world feedback. Shape technical direction and architecture decisions as the Codex Cyber product surface grows.
  • Build developer tools and internal platforms: Create infrastructure, internal tooling, and platform controls that help security researchers and AI models improve over time. Ensure Codex Cyber operates safely and reliably while enabling rapid iteration on product features.

Qualifications

What we look for.

Technical

  • Full-stack software engineering fundamentals

    Strong grasp of software design principles, system architecture, and the ability to work effectively across product interfaces, backend services, databases, and infrastructure layers. Demonstrated experience building production systems with attention to reliability, observability, and maintainability.

  • API and service design

    Proficiency designing and implementing well-architected REST APIs and backend services. Experience with API versioning, authentication, rate limiting, and creating interfaces that are intuitive for developer consumption.

  • Cloud infrastructure and deployment

    Practical experience with cloud platforms and containerized deployments. Comfortable with infrastructure-as-code, observability tools, monitoring, and scaling applications to handle enterprise workloads.

  • Data persistence and query optimization

    Understanding of relational and non-relational database design, query optimization, and data modeling. Ability to design schemas and access patterns that support complex analytical and operational workflows.

  • Product-minded development approach

    Ability to translate ambiguous product and user requirements into technical specifications. Strong product instincts paired with the ability to collaborate closely with product teams to validate decisions against real user needs.

Education

  • Bachelor's degree in Computer Science or related field (or equivalent

    Formal education in computer science, software engineering, mathematics, or a closely related discipline. Equivalent professional experience demonstrating mastery of computer science fundamentals will be considered.

Experience

  • 5+ years of full-stack software development

    Substantial experience building production software systems across multiple layers of the stack. Demonstrated ability to own projects end-to-end, ship features to users, and iterate based on feedback.

  • Experience with developer tools or platforms

    Track record building developer-facing tools, APIs, workflow platforms, or internal infrastructure. Understanding of how to design systems that technical users find intuitive and reliable.

  • Application security or security product experience (preferred)

    Background in application security, product security, vulnerability research, defensive security, identity systems, SSO, or secure developer workflows. This is valuable context but not required if you have strong product and platform engineering instincts.

  • Ownership and autonomy in early-stage settings

    Demonstrated success in fast-moving, ambiguous environments. Ability to take high-agency ownership, make reasonable technical decisions with incomplete information, and move projects from concept through production.

Skills

Required

  • Python or Go

    Strong proficiency in Python or Go for backend service development, data processing, and systems programming. These languages are common in security tooling and AI infrastructure.

  • TypeScript/JavaScript

    Experience building user-facing web applications with TypeScript or JavaScript. Ability to work with modern frontend frameworks and create responsive, accessible user interfaces.

  • SQL

    Proficiency writing and optimizing SQL queries, designing normalized schemas, and understanding query performance analysis and indexing strategies.

  • System design and architecture

    Ability to reason about scalability, reliability, and observability when designing systems. Experience with tradeoffs between different architectural approaches (microservices vs monoliths, synchronous vs asynchronous processing, etc.).

  • Version control and development workflows

    Fluency with Git, code review practices, and collaborative development workflows. Ability to write clear commit messages and participate constructively in technical discussions.

  • Testing and observability

    Experience writing unit tests, integration tests, and setting up monitoring/alerting. Understanding of debugging production systems and instrumenting code for observability.

Preferred

  • Application security fundamentals

    Nice to have

    Familiarity with OWASP Top 10, secure coding practices, common vulnerability types (XSS, SQL injection, CSRF, etc.), and threat modeling. Helpful context but learnable on the job.

  • Machine learning systems experience

    Nice to have

    Background working with ML/AI systems, model serving infrastructure, or ML data pipelines. Valuable for understanding how to integrate model outputs with production systems.

  • Kubernetes or container orchestration

    Nice to have

    Experience deploying and managing containerized applications at scale. Understanding of container networking, resource management, and orchestration patterns.

  • Distributed systems and async processing

    Nice to have

    Experience with message queues, event-driven architectures, long-running job processing, or distributed tracing. Relevant for scaling security analysis pipelines.

  • Security analysis or static/dynamic analysis tools

    Nice to have

    Familiarity with SAST, DAST, or other security analysis tools. Understanding of how vulnerability detection and remediation workflows function in practice.

  • Monitoring and observability platforms

    Nice to have

    Experience with observability stacks (Prometheus, Datadog, Splunk, etc.), structured logging, distributed tracing, and incident response tooling.

Tech stack

Languages

PythonTypeScript/JavaScriptGoSQL

Frameworks

React or Vue.jsFastAPI or FlaskNext.js or similar full-stack frameworks

Databases

PostgreSQLRedisVector databases (e.g., Pinecone, Weaviate)

Tools

Docker and container registryKubernetesCloud platforms (AWS, GCP)Git and GitHubMonitoring and logging (Datadog, Prometheus, ELK)

Other

REST API design and OpenAPI/SwaggerSecurity scanning and SAST toolsCI/CD pipelines (GitHub Actions, Jenkins)Async job processing and worker systems

Compensation

Pay and benefits.

Base·USD 230,000 – 325,000

Equity·Stock options

Benefits

  • Comprehensive health coverage

    Medical, dental, and vision insurance plans with OpenAI covering a significant portion of premiums for you and your family members.

  • Retirement savings plan

    401(k) plan with employer matching to support your long-term financial planning and retirement security.

  • Generous paid time off

    Competitive vacation policy, paid sick leave, and company holidays enabling work-life balance and personal wellness.

  • Parental leave

    Paid parental leave for new parents, supporting family planning and providing flexibility during significant life transitions.

  • Equity compensation

    Competitive stock options or equity grants as part of your total compensation, allowing you to participate in OpenAI's long-term success.

  • Professional development and learning

    Opportunities to attend conferences, pursue certifications, and invest in continuous learning to advance your skills in AI, security, and software engineering.

  • Mental health and wellness support

    Access to mental health resources, wellness programs, and employee assistance programs supporting overall wellbeing.

  • Flexible work arrangements

    Opportunities for remote work flexibility and collaborative in-office environments based on role and team requirements.

Process

Interview steps.

  1. 01

    Initial screening conversation

    30-minute call with a recruiter covering your background, experience with full-stack development, familiarity with security concepts, and your interest in the Codex Cyber mission. This is an informal opportunity to learn about the role and determine cultural fit.

  2. 02

    Technical phone interview

    60-minute conversation with a senior engineer from the Codex team. Expect questions around system design, your experience building scalable backend services, API design principles, and how you approach ambiguous technical problems. You may be asked to discuss past projects where you owned complex features end-to-end.

  3. 03

    Product and design thinking assessment

    Collaborative discussion evaluating your product instincts and ability to think through user needs. You may be given a scenario related to security workflows or vulnerability remediation and asked how you would approach building a feature to address it.

  4. 04

    Full-stack technical depth assessment

    90-minute coding interview assessing your ability to write clean, well-structured code across different domains (frontend logic, backend service implementation, SQL queries). You may be asked to build a small prototype or solve problems spanning multiple layers of an application stack.

  5. 05

    Infrastructure and systems design session

    Deep-dive conversation with infrastructure or platform engineers about designing systems for scale. Discussion of how you would architect components for long-running security analyses, handle eventual consistency, design for observability, and scale to enterprise customers.

  6. 06

    Team and collaboration conversations

    Meetings with future team members and cross-functional partners (product, security research, infrastructure) to assess collaboration style, communication clarity, and ability to work effectively across disciplines in a fast-moving environment.

  7. 07

    Final leadership conversation

    30-45 minute conversation with the team lead or engineering manager covering your long-term career interests, how you think about technical leadership and mentorship, your vision for the Codex Cyber platform, and any final questions about OpenAI's culture and mission.

Full posting

Original listing.

About the Team

Codex is OpenAI's software engineering agent. Codex Security extends that work into one of the most important product areas in AI: helping organizations find, validate, prioritize, and fix real vulnerabilities in the software they build and depend on.

The Codex Cyber team is building the product and platform foundations for AI-native application security. This includes Codex Security product experiences, cloud-based security analysis, platform controls across Codex, customer deployment and support tooling, and infrastructure that helps security researchers and cyber models improve over time. The team is early, small, and growing quickly, with a mandate to move fast and hire exceptional builders.

About the Role

We are looking for software engineers first: strong full-stack or product-minded generalists who can own ambiguous product and platform problems end to end. Security experience is helpful, and security curiosity is important, but this is not a role for security specialists who only occasionally write code. The right person is an excellent builder who is excited to work in security and can turn complex research, product, and customer needs into reliable systems.

You will work across user-facing product surfaces, developer workflows, backend services, security analysis pipelines, cloud infrastructure, and internal tooling. You may build features that make Codex Security more useful for application security teams, systems that scale cloud-based security analysis, platform controls that make agentic coding safer, or infrastructure that helps security researchers and models become more effective. You will collaborate closely with engineering, product, security research, infrastructure, and customer-facing partners as Codex Cyber becomes a major product and platform investment for OpenAI.

In this role, you will:

  • Build end-to-end product features for Codex Security, from developer-facing interfaces to APIs, backend services, and workflow tooling.

  • Own ambiguous 0-to-1 projects across product pods, platform security controls, customer deployment workflows, and cyber model infrastructure.

  • Translate security research and model capabilities into intuitive workflows that help teams find, validate, prioritize, and remediate vulnerabilities with high signal.

  • Design scalable, observable systems for long-running analyses across large codebases and enterprise environments.

  • Partner with product, security research, infrastructure, and customer-facing teams to iterate quickly from real-world feedback.

  • Help shape the technical direction and architecture of Codex Cyber as the team and product surface area grow.

You might thrive in this role if you:

  • Are an excellent software engineer with strong fundamentals and enough range to work across product, backend, infrastructure, and developer tooling.

  • Enjoy building high-quality product and platform experiences across the full stack.

  • Are high-agency, low-drama, and comfortable owning features from concept to production in a fast-moving environment.

  • Have built developer tools, workflow-heavy platforms, security products, internal infrastructure, or product features for technical users.

  • Have strong product instincts and care about making complex technical systems understandable and useful.

  • Are excited by security and AI. Direct experience in product security, application security, vulnerability research, defensive security, identity, SSO, or secure developer workflows is a plus, not a requirement.

  • Like ambiguous 0-to-1 work and can turn messy requirements into crisp, scalable systems.

Goals & impact

  • Build AI-native security products that help users find and fix important vulnerabilities in real software systems before attackers do.

  • Increase the usefulness and trustworthiness of Codex Security by turning research insights into dependable workflows, product surfaces, platform controls, and remediation tooling.

  • Help define a new category of security tooling where models reason over real code, validate exploitability, and propose fixes directly in developer workflows.

Key technical challenges

  • Combining model outputs, security analysis, and user workflows into one cohesive product experience.

  • Designing high-confidence validation and remediation flows that distinguish real issues from noisy or speculative findings.

  • Scaling product and platform infrastructure for large repositories, complex enterprise environments, and long-running analyses.

  • Creating developer-friendly interfaces and APIs that make advanced security capabilities understandable and actionable.

  • Building platform controls and internal systems that help Codex Cyber move quickly while meeting OpenAI's bar for safety, security, and reliability.

 
 
 

About OpenAI

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity. 

We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.

For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement.

Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.

To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.

OpenAI Global Applicant Privacy Policy

At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

Redirects to OpenAI's application page.

Other roles

More at OpenAI.

View all 107 roles