How to apply for Principal Software Engineer, Infrastructure Security

OpenAI

About OpenAI

OpenAI is a frontier AI research and product company, renowned for developing cutting-edge models like GPT and DALL·E. Working here means contributing to transformative AI technologies while navigating complex ethical and security challenges, making it a unique environment for engineers passionate about impact and responsibility.

About the role

As Principal Software Engineer for Infrastructure Security, you'll own the architecture and execution of critical security services protecting OpenAI's infrastructure and models. This role involves designing planet-scale security systems, leading cross-functional launches, and developing automation tooling using frontier models, directly shaping the safety of cutting-edge AI.

A typical day

Your day might start with a stand-up with your security infrastructure team, reviewing threat models for a new model training pipeline. You'll then dive into designing a secure multi-cloud architecture, collaborating with infrastructure engineers on rollout plans. Afternoons could involve code reviews for automation tooling and mentoring junior engineers on secure design patterns.

Who OpenAI is looking for

  • Expert in infrastructure security and cloud security with proven experience designing secure systems at massive scale (e.g., AWS, GCP, on-prem).
  • Strong leader who has led cross-functional engineering initiatives and mentored engineers, driving alignment across teams.
  • Proficient in Python or Go with an automation mindset, capable of building tooling to detect and mitigate risks.
  • Deep understanding of security principles, threat modeling, and secure-by-default practices, with a track record of implementing them in production.

Tips for this application

  • Highlight specific examples of designing security systems for large-scale distributed environments, including trade-offs between security, reliability, and latency.
  • Showcase your experience with automation and detection tooling, ideally using AI/ML models (e.g., anomaly detection) – mention any work with frontier models.
  • Emphasize cross-functional leadership: describe how you influenced infrastructure teams and drove secure rollouts at scale.
  • Tailor your resume to include metrics: e.g., reduced incident response time by X%, secured Y million requests per second.
  • Research OpenAI's published security research and blog posts, and mention how your experience aligns with their approach to safety and alignment.

What to cover in your cover letter

['Your passion for securing AI infrastructure and understanding of the unique risks at frontier AI companies.', 'Specific examples of leading large-scale security initiatives and collaborating with infrastructure teams.', 'Your automation expertise and how you leverage programming to build proactive security measures.', "Alignment with OpenAI's mission: ensure your work contributes to safe and beneficial AI."]

Draft a cover letter

Research before applying

  • Read OpenAI's security and safety research papers, especially on alignment and adversarial robustness.
  • Understand OpenAI's infrastructure stack: they use Azure, Kubernetes, and custom hardware – know the basics.
  • Review recent blog posts about their security posture, such as the 'Preparedness Framework' and 'Security Best Practices'.
  • Familiarize yourself with industry challenges in AI security, like model extraction, data poisoning, and supply chain attacks.
OpenAI website

Likely interview topics

Based on the job description, expect questions about:

  • Design a secure multi-tenant system for training large models, balancing isolation and performance.
  • How would you threat model a cloud-based AI training pipeline? Walk through your approach.
  • Describe a time you led a cross-functional security launch that involved trade-offs between security and user experience.
  • How would you detect and respond to a novel attack on a distributed GPU cluster?
  • Explain your experience with securing infrastructure as code and implementing secure-by-default patterns.
Practise interview questions

Common mistakes to avoid

  • Don't focus only on traditional security roles without emphasizing scale and AI-specific challenges.
  • Avoid vague statements about 'passion for security' without concrete examples of system design and automation.
  • Don't neglect the cross-functional aspect: failing to highlight leadership and collaboration with non-security teams.

Deadline

No deadline is listed. Roles without a deadline usually close once the employer has enough candidates, so apply soon if you are interested.