How to apply for Principal Security Engineer, Infrastructure Security

OpenAI

About OpenAI

OpenAI is a frontier AI research and product company working on alignment, policy, and security. It posts specific opportunities it considers high impact, and it notes that it does not necessarily recommend working at other positions there. It also links to external concerns about doing harm by working at a frontier AI company.

About the role

This is a principal security engineer role on the Infrastructure Security team. The team protects GPU supercomputing clusters, multi-cloud infrastructure, datacenters, networking, storage, and services that support frontier AI models, including model weights and user data. The role sets technical direction and drives multi-quarter security programs across OpenAI.

A typical day

A typical day may involve setting technical direction for one or more critical infrastructure areas, reviewing security designs for GPU clusters or multi-cloud services, and working with partner teams to ship durable controls. The job description does not specify daily routines, so ask about team structure, on-call expectations, and how work is split between strategy and execution.

Who OpenAI is looking for

  • Has deep experience securing infrastructure at scale, including bare-metal hardware, firmware, Kubernetes, service meshes, networking, and storage.
  • Can own end-to-end security outcomes for critical infrastructure areas and build multi-quarter strategy and roadmaps.
  • Works across organizations to deliver durable controls rather than one-off fixes.
  • Has experience protecting highly sensitive data such as model weights or user data in cloud and datacenter environments.

Tips for this application

  • Tailor your resume to infrastructure security, not general security. Name specific systems you have secured: GPU clusters, multi-cloud environments, Kubernetes, service meshes, datacenters, networking, or storage.
  • Show principal-level scope. Describe programs you owned end-to-end, the multi-quarter strategy you set, and the cross-org partners you worked with.
  • Reference OpenAI's stated security team tenets: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.
  • Address the company's note about harm. If you have thought about working at a frontier AI company, say so directly in your application materials.
  • Because the role is remote in the US, explain how you have driven security outcomes across distributed teams and remote infrastructure.

What to cover in your cover letter

['A specific infrastructure security program you owned end-to-end, including the multi-quarter strategy and the measurable outcome.', 'How you have secured sensitive assets such as model weights, user data, or production research environments.', 'Your experience partnering across organizations to deliver durable controls at scale.', 'Why you want to work on infrastructure security at OpenAI specifically, given its stated mission and the concerns it links to.']

Draft a cover letter

Research before applying

  • Read OpenAI's security team tenets and the role's listed infrastructure areas: GPU supercomputing clusters, multi-cloud, datacenters, networking, storage, Kubernetes, and service meshes.
  • Read the 80,000 Hours career review on working at an AI lab, which OpenAI links in its company description, so you can speak to the concerns it raises.
  • Look at OpenAI's published research and product surface to understand what infrastructure the security team protects.
  • Check what OpenAI has said publicly about security, alignment, and policy to understand how this role fits the mission.
OpenAI website

Likely interview topics

Based on the job description, expect questions about:

  • How you would set a multi-quarter strategy for one critical infrastructure area, such as GPU supercomputing clusters or multi-cloud networking.
  • Your approach to securing bare-metal hardware, firmware, and the path to Kubernetes and service meshes.
  • How you would protect model weights and user data across storage, access pathways, and multi-cloud infrastructure.
  • How you prioritize for impact and enable researchers while raising the security bar.
  • How you drive execution across organizations when you do not have direct authority.
Practise interview questions

Common mistakes to avoid

  • Applying with a general security background and no evidence of infrastructure depth such as hardware, firmware, Kubernetes, networking, or storage.
  • Describing only incident response or tooling work instead of principal-level ownership of multi-quarter strategy and cross-org execution.
  • Ignoring OpenAI's own note about concerns working at a frontier AI company, which leaves a gap in your application.

Deadline

No deadline is listed. Roles without a deadline usually close once the employer has enough candidates, so apply soon if you are interested.