How to apply for Security Engineer, Infrastructure Security

OpenAI

About OpenAI

OpenAI is a frontier AI research and product company working on alignment, policy, and security. It posts specific opportunities it considers high impact, and it does not necessarily recommend working at other OpenAI positions. Candidates should weigh concerns about doing harm by working at a frontier AI company, as covered in the 80,000 Hours career review linked in the posting.

About the role

This Security Engineer role sits on the Infrastructure Security (InfraSec) team, which protects the foundations of OpenAI's research and production environments. The scope spans GPU supercomputing clusters, multi-cloud infrastructure, datacenters, networking, storage, bare-metal hardware and firmware, Kubernetes clusters and service meshes, and access pathways for model weights and user data. The work involves designing and building security controls against sophisticated adversaries and insider threats, and driving deployment of those controls across broad-scale infrastructure with engineering and security teams.

A typical day

A typical day likely involves designing or reviewing security controls across hardware, firmware, Kubernetes, networking, or CI/CD layers, and working with engineering teams to deploy those changes across broad infrastructure. The posting does not describe a fixed daily routine, so ask the team in interviews how they split time between design, deployment, and incident work, and how they coordinate across datacenters, multi-cloud, and research environments.

Who OpenAI is looking for

  • Has hands-on experience building security controls at multiple layers: physical hardware, firmware/BMC, OS, Kubernetes, networks, and CI/CD.
  • Has worked on infrastructure security at scale, ideally across GPU supercomputing clusters, multi-cloud environments, datacenters, networking, or storage.
  • Can collaborate with engineering and security teams to deploy control changes across large, distributed environments rather than only writing point solutions.
  • Understands threats from both sophisticated external adversaries and insider threats, and designs controls with those threat models in mind.

Tips for this application

  • Tailor your resume to the exact layers listed in the posting: firmware/BMC, OS, Kubernetes, networks, CI/CD, GPU clusters, multi-cloud, datacenters, storage. Name the ones you have actually worked on.
  • Show evidence of deploying security controls at broad scale, not just designing them. Describe rollouts, cross-team coordination, and how changes landed in production.
  • Address insider threat and sophisticated adversary models directly. Give concrete examples of controls you built for those cases.
  • Note that the posting says OpenAI does not necessarily recommend working at other OpenAI positions. Apply for this specific InfraSec role rather than a generalist security opening.
  • Read the 80,000 Hours career review linked in the posting and be ready to speak to your own reasoning about working at a frontier AI company.

What to cover in your cover letter

['Specific infrastructure layers you have secured: name hardware, firmware/BMC, OS, Kubernetes, networking, storage, or CI/CD, and what you built at each.', 'Experience securing large-scale compute, such as GPU supercomputing clusters or multi-cloud environments, and the concrete controls you deployed.', 'How you have worked with engineering teams to roll out security changes across broad infrastructure, including how you handled resistance or operational risk.', 'Your reasoning for working on security at a frontier AI company, including how you think about the concerns raised in the 80,000 Hours career review.']

Draft a cover letter

Research before applying

  • Read the OpenAI security team's stated tenets in the posting: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. Be ready to discuss how you have worked under similar principles.
  • Read the 80,000 Hours career review on working at an AI lab, linked in the posting, and form your own view on the concerns it raises.
  • Research OpenAI's published work on alignment, policy, and security to understand how the InfraSec team's charter connects to the broader mission.
  • Look into what is publicly known about OpenAI's infrastructure, such as its use of GPU supercomputing clusters and multi-cloud environments, to ground your answers in the actual environment.
OpenAI website

Likely interview topics

Based on the job description, expect questions about:

  • How you would design security controls for GPU supercomputing clusters, including hardware, firmware/BMC, and OS layers.
  • Your approach to securing Kubernetes clusters and service meshes in a multi-cloud environment.
  • How you would protect access pathways to highly sensitive model weights and user data.
  • How you prioritize security work across datacenters, networking, storage, and CI/CD when resources are limited.
  • How you would defend against insider threats and sophisticated adversaries in a research and production environment.
Practise interview questions

Common mistakes to avoid

  • Applying as a generalist security engineer without addressing the specific layers in the posting, such as firmware/BMC, Kubernetes, GPU clusters, or CI/CD.
  • Describing security designs without evidence of deploying them across broad-scale infrastructure with engineering teams.
  • Ignoring the posting's note about concerns working at a frontier AI company, or treating the 80,000 Hours career review as irrelevant to the application.

Deadline

No deadline is listed. Roles without a deadline usually close once the employer has enough candidates, so apply soon if you are interested.