OpenAI
Security Engineer, Host Assurance
About this role
OpenAI is hiring a Security Engineer to build and operate trust infrastructure for bare-metal hosts across its global infrastructure. You'll design core security systems that verify hardware eligibility before production deployment, working at the intersection of hardware, firmware, and large-scale cloud orchestration.
What you'll do
- Design and operate Host Assurance platform components that establish trust in bare-metal hosts before production use
- Build machine identity, certificate issuance, HSM-backed key management, and host attestation systems
- Validate hardware and firmware against vendor claims and detect drift over time
- Eliminate insecure bootstrap patterns while maintaining deployment speed and reliability
- Define observable security properties for host platforms and improve telemetry and validation
- Participate in incident response and debugging for security-critical infrastructure
What they're looking for
- Production systems engineering and reliability at scale
- PKI, HSMs, machine identity, or applied cryptography
- Secure boot, firmware, or hardware security expertise
- Host attestation and platform security mechanisms
- Systems programming across services and low-level trust mechanisms
- Production-quality code writing and failure mode analysis
- Cross-disciplinary collaboration and problem-solving
- Infrastructure automation and operational tooling
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
OpenAI
OpenAI builds AI infrastructure and products, including large-scale data center campuses for AI computing and generative AI applications for enterprise customers. The company is hiring civil engineers, project engineers, electrical design engineers, data center R&D engineers, and AI deployment engineers to expand its infrastructure capabilities and help customers deploy AI solutions.
View all jobs at OpenAILikely interview questions
- Walk us through your experience with PKI, HSM integration, or machine identity systems. How have you designed certificate issuance and enrollment at scale?
- Describe a time you had to balance security rigor with operational practicality. How did you make the secure path the easiest path for users or teams?