Software Engineer, Codex Security
Full Stack Engineer · Mid · Full Time
Opens OpenAI's application page
Role
What you'll do.
Join OpenAI's Codex Cyber team to build AI-native application security products that help organizations discover, validate, and remediate real vulnerabilities in software systems. This full-stack role combines product development, backend services, cloud infrastructure, and security analysis pipelines to create the next generation of intelligent vulnerability detection and remediation tools. You'll work as a high-agency software engineer with strong fundamentals across multiple domains, translating complex security research and AI capabilities into intuitive workflows for technical users in a fast-moving, early-stage team.
Responsibilities
- Build end-to-end product features across the full stack: Design and implement complete features for Codex Security spanning user-facing interfaces, REST APIs, backend services, and workflow tooling. Own the full journey from concept through production deployment, ensuring cohesive experiences that integrate model outputs with security analysis and developer workflows.
- Own ambiguous 0-to-1 projects and platform initiatives: Take ownership of greenfield projects across product pods, platform security controls, customer deployment workflows, and cyber model infrastructure. Navigate unclear requirements and translate them into crisp, scalable systems that advance OpenAI's security platform capabilities.
- Translate security research into intuitive developer workflows: Partner with security researchers and ML teams to surface complex model capabilities through interfaces that help teams find, validate, prioritize, and remediate vulnerabilities with high signal. Make advanced security analysis understandable and actionable for technical users.
- Design scalable systems for enterprise-grade security analysis: Architect observable, performant systems capable of executing long-running security analyses across large codebases and complex enterprise environments. Build infrastructure that scales analysis capabilities while maintaining reliability and data integrity.
- Collaborate across engineering, product, research, and infrastructure teams: Work closely with product managers, security researchers, infrastructure engineers, and customer-facing partners to iterate rapidly based on real-world feedback. Shape technical direction and architecture decisions as the Codex Cyber product surface grows.
- Build developer tools and internal platforms: Create infrastructure, internal tooling, and platform controls that help security researchers and AI models improve over time. Ensure Codex Cyber operates safely and reliably while enabling rapid iteration on product features.
Qualifications
What we look for.
Technical
Full-stack software engineering fundamentals
Strong grasp of software design principles, system architecture, and the ability to work effectively across product interfaces, backend services, databases, and infrastructure layers. Demonstrated experience building production systems with attention to reliability, observability, and maintainability.
API and service design
Proficiency designing and implementing well-architected REST APIs and backend services. Experience with API versioning, authentication, rate limiting, and creating interfaces that are intuitive for developer consumption.
Cloud infrastructure and deployment
Practical experience with cloud platforms and containerized deployments. Comfortable with infrastructure-as-code, observability tools, monitoring, and scaling applications to handle enterprise workloads.
Data persistence and query optimization
Understanding of relational and non-relational database design, query optimization, and data modeling. Ability to design schemas and access patterns that support complex analytical and operational workflows.
Product-minded development approach
Ability to translate ambiguous product and user requirements into technical specifications. Strong product instincts paired with the ability to collaborate closely with product teams to validate decisions against real user needs.
Education
Bachelor's degree in Computer Science or related field (or equivalent
Formal education in computer science, software engineering, mathematics, or a closely related discipline. Equivalent professional experience demonstrating mastery of computer science fundamentals will be considered.
Experience
5+ years of full-stack software development
Substantial experience building production software systems across multiple layers of the stack. Demonstrated ability to own projects end-to-end, ship features to users, and iterate based on feedback.
Experience with developer tools or platforms
Track record building developer-facing tools, APIs, workflow platforms, or internal infrastructure. Understanding of how to design systems that technical users find intuitive and reliable.
Application security or security product experience (preferred)
Background in application security, product security, vulnerability research, defensive security, identity systems, SSO, or secure developer workflows. This is valuable context but not required if you have strong product and platform engineering instincts.
Ownership and autonomy in early-stage settings
Demonstrated success in fast-moving, ambiguous environments. Ability to take high-agency ownership, make reasonable technical decisions with incomplete information, and move projects from concept through production.
Skills
Required
Python or Go
Strong proficiency in Python or Go for backend service development, data processing, and systems programming. These languages are common in security tooling and AI infrastructure.
TypeScript/JavaScript
Experience building user-facing web applications with TypeScript or JavaScript. Ability to work with modern frontend frameworks and create responsive, accessible user interfaces.
SQL
Proficiency writing and optimizing SQL queries, designing normalized schemas, and understanding query performance analysis and indexing strategies.
System design and architecture
Ability to reason about scalability, reliability, and observability when designing systems. Experience with tradeoffs between different architectural approaches (microservices vs monoliths, synchronous vs asynchronous processing, etc.).
Version control and development workflows
Fluency with Git, code review practices, and collaborative development workflows. Ability to write clear commit messages and participate constructively in technical discussions.
Testing and observability
Experience writing unit tests, integration tests, and setting up monitoring/alerting. Understanding of debugging production systems and instrumenting code for observability.
Preferred
Application security fundamentals
Nice to haveFamiliarity with OWASP Top 10, secure coding practices, common vulnerability types (XSS, SQL injection, CSRF, etc.), and threat modeling. Helpful context but learnable on the job.
Machine learning systems experience
Nice to haveBackground working with ML/AI systems, model serving infrastructure, or ML data pipelines. Valuable for understanding how to integrate model outputs with production systems.
Kubernetes or container orchestration
Nice to haveExperience deploying and managing containerized applications at scale. Understanding of container networking, resource management, and orchestration patterns.
Distributed systems and async processing
Nice to haveExperience with message queues, event-driven architectures, long-running job processing, or distributed tracing. Relevant for scaling security analysis pipelines.
Security analysis or static/dynamic analysis tools
Nice to haveFamiliarity with SAST, DAST, or other security analysis tools. Understanding of how vulnerability detection and remediation workflows function in practice.
Monitoring and observability platforms
Nice to haveExperience with observability stacks (Prometheus, Datadog, Splunk, etc.), structured logging, distributed tracing, and incident response tooling.
Tech stack
Languages
Frameworks
Databases
Tools
Other
Compensation
Pay and benefits.
Base·USD 230,000 – 325,000
Equity·Stock options
Benefits
Comprehensive health coverage
Medical, dental, and vision insurance plans with OpenAI covering a significant portion of premiums for you and your family members.
Retirement savings plan
401(k) plan with employer matching to support your long-term financial planning and retirement security.
Generous paid time off
Competitive vacation policy, paid sick leave, and company holidays enabling work-life balance and personal wellness.
Parental leave
Paid parental leave for new parents, supporting family planning and providing flexibility during significant life transitions.
Equity compensation
Competitive stock options or equity grants as part of your total compensation, allowing you to participate in OpenAI's long-term success.
Professional development and learning
Opportunities to attend conferences, pursue certifications, and invest in continuous learning to advance your skills in AI, security, and software engineering.
Mental health and wellness support
Access to mental health resources, wellness programs, and employee assistance programs supporting overall wellbeing.
Flexible work arrangements
Opportunities for remote work flexibility and collaborative in-office environments based on role and team requirements.
Process
Interview steps.
- 01
Initial screening conversation
30-minute call with a recruiter covering your background, experience with full-stack development, familiarity with security concepts, and your interest in the Codex Cyber mission. This is an informal opportunity to learn about the role and determine cultural fit.
- 02
Technical phone interview
60-minute conversation with a senior engineer from the Codex team. Expect questions around system design, your experience building scalable backend services, API design principles, and how you approach ambiguous technical problems. You may be asked to discuss past projects where you owned complex features end-to-end.
- 03
Product and design thinking assessment
Collaborative discussion evaluating your product instincts and ability to think through user needs. You may be given a scenario related to security workflows or vulnerability remediation and asked how you would approach building a feature to address it.
- 04
Full-stack technical depth assessment
90-minute coding interview assessing your ability to write clean, well-structured code across different domains (frontend logic, backend service implementation, SQL queries). You may be asked to build a small prototype or solve problems spanning multiple layers of an application stack.
- 05
Infrastructure and systems design session
Deep-dive conversation with infrastructure or platform engineers about designing systems for scale. Discussion of how you would architect components for long-running security analyses, handle eventual consistency, design for observability, and scale to enterprise customers.
- 06
Team and collaboration conversations
Meetings with future team members and cross-functional partners (product, security research, infrastructure) to assess collaboration style, communication clarity, and ability to work effectively across disciplines in a fast-moving environment.
- 07
Final leadership conversation
30-45 minute conversation with the team lead or engineering manager covering your long-term career interests, how you think about technical leadership and mentorship, your vision for the Codex Cyber platform, and any final questions about OpenAI's culture and mission.
Full posting
Original listing.
About the Team
Codex is OpenAI's software engineering agent. Codex Security extends that work into one of the most important product areas in AI: helping organizations find, validate, prioritize, and fix real vulnerabilities in the software they build and depend on.
The Codex Cyber team is building the product and platform foundations for AI-native application security. This includes Codex Security product experiences, cloud-based security analysis, platform controls across Codex, customer deployment and support tooling, and infrastructure that helps security researchers and cyber models improve over time. The team is early, small, and growing quickly, with a mandate to move fast and hire exceptional builders.
About the Role
We are looking for software engineers first: strong full-stack or product-minded generalists who can own ambiguous product and platform problems end to end. Security experience is helpful, and security curiosity is important, but this is not a role for security specialists who only occasionally write code. The right person is an excellent builder who is excited to work in security and can turn complex research, product, and customer needs into reliable systems.
You will work across user-facing product surfaces, developer workflows, backend services, security analysis pipelines, cloud infrastructure, and internal tooling. You may build features that make Codex Security more useful for application security teams, systems that scale cloud-based security analysis, platform controls that make agentic coding safer, or infrastructure that helps security researchers and models become more effective. You will collaborate closely with engineering, product, security research, infrastructure, and customer-facing partners as Codex Cyber becomes a major product and platform investment for OpenAI.
In this role, you will:
Build end-to-end product features for Codex Security, from developer-facing interfaces to APIs, backend services, and workflow tooling.
Own ambiguous 0-to-1 projects across product pods, platform security controls, customer deployment workflows, and cyber model infrastructure.
Translate security research and model capabilities into intuitive workflows that help teams find, validate, prioritize, and remediate vulnerabilities with high signal.
Design scalable, observable systems for long-running analyses across large codebases and enterprise environments.
Partner with product, security research, infrastructure, and customer-facing teams to iterate quickly from real-world feedback.
Help shape the technical direction and architecture of Codex Cyber as the team and product surface area grow.
You might thrive in this role if you:
Are an excellent software engineer with strong fundamentals and enough range to work across product, backend, infrastructure, and developer tooling.
Enjoy building high-quality product and platform experiences across the full stack.
Are high-agency, low-drama, and comfortable owning features from concept to production in a fast-moving environment.
Have built developer tools, workflow-heavy platforms, security products, internal infrastructure, or product features for technical users.
Have strong product instincts and care about making complex technical systems understandable and useful.
Are excited by security and AI. Direct experience in product security, application security, vulnerability research, defensive security, identity, SSO, or secure developer workflows is a plus, not a requirement.
Like ambiguous 0-to-1 work and can turn messy requirements into crisp, scalable systems.
Goals & impact
Build AI-native security products that help users find and fix important vulnerabilities in real software systems before attackers do.
Increase the usefulness and trustworthiness of Codex Security by turning research insights into dependable workflows, product surfaces, platform controls, and remediation tooling.
Help define a new category of security tooling where models reason over real code, validate exploitability, and propose fixes directly in developer workflows.
Key technical challenges
Combining model outputs, security analysis, and user workflows into one cohesive product experience.
Designing high-confidence validation and remediation flows that distinguish real issues from noisy or speculative findings.
Scaling product and platform infrastructure for large repositories, complex enterprise environments, and long-running analyses.
Creating developer-friendly interfaces and APIs that make advanced security capabilities understandable and actionable.
Building platform controls and internal systems that help Codex Cyber move quickly while meeting OpenAI's bar for safety, security, and reliability.
About OpenAI
OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.
We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.
For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement.
Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.
To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.
We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.
OpenAI Global Applicant Privacy Policy
At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.
Redirects to OpenAI's application page.
Other roles
More at OpenAI.
Software Engineer, API Safety
Senior
Data Engineer, Monetization Data Platform
Senior
Software Engineer, Plugin Developer Platform
Senior
Product Engineer, Full Stack - Agents
Senior
Engineering Manager, Artifacts
Manager