How to apply for Senior Technical Program Manager - Security
OpenAI
About OpenAI
OpenAI is a frontier AI research and product company that builds ChatGPT, the OpenAI API, and enterprise products used by millions. Teams work on alignment, policy, and security. The job posting notes that OpenAI posts specific opportunities it thinks may be high impact, and it links to an external career review discussing concerns about working at a frontier AI lab.
About the role
This is a senior technical program manager role focused on security, privacy, IT, and compliance programs that span infrastructure, product, and policy. The work includes reducing internal data access, preventing misuse, and shipping security capabilities. The role is deeply technical and execution-focused, and covers insider threat, information security, physical security, and information technology challenges.
A typical day
The posting does not describe a specific daily routine, so ask about it in interviews. Based on the listed scope, a typical day likely involves coordinating across engineering, legal, policy, and product teams on security, privacy, IT, and compliance programs, and pushing critical initiatives toward delivery.
Who OpenAI is looking for
- Has run complex, cross-functional security or compliance programs at a technical company, working across engineering, legal, policy, and product teams.
- Can operate in ambiguity, apply structured program management, and make principled judgment calls on security and data access tradeoffs.
- Has direct exposure to at least some of: insider threat, information security, physical security, or IT program delivery.
- Communicates clearly with both technical and non-technical partners and can drive execution without direct authority.
Tips for this application
- Read the 80,000 Hours career review linked in the posting before applying, since OpenAI explicitly points candidates to concerns about working at a frontier AI lab.
- Tailor your resume to show programs you personally drove, with the specific security or compliance outcome and the teams involved.
- Name the domains you have worked in: insider threat, information security, physical security, IT, privacy, or compliance. The posting lists these explicitly.
- Show evidence of execution in ambiguity, for example programs where scope changed or no clear owner existed and you created structure.
- Avoid generic TPM language. Use concrete examples of reducing data access, preventing misuse, or shipping security capabilities.
What to cover in your cover letter
['One or two programs you led that reduced internal data access or prevented misuse, with measurable results.', 'How you have worked across engineering, legal, policy, and product boundaries to deliver a security or compliance outcome.', 'Your judgment on security tradeoffs, especially where speed, privacy, and compliance conflicted.', "Why this specific role at OpenAI, given the posting's own note about the concerns of working at a frontier AI lab."]
Draft a cover letterResearch before applying
- Read the 80,000 Hours career review on working at an AI lab, which the posting links directly.
- Read OpenAI's published work on alignment, policy, and security, plus its enterprise and API product documentation.
- Look at OpenAI's public statements on data access, privacy, and compliance commitments to understand the program areas this role covers.
- Check what is publicly known about OpenAI's security organization and how security spans infrastructure, applied engineering, legal, policy, and product.
Likely interview topics
Based on the job description, expect questions about:
- How you have run a cross-functional security program from scoping to delivery, including how you handled competing priorities.
- A time you reduced internal data access or addressed an insider threat risk, and how you measured the result.
- How you make decisions when security, privacy, product, and policy goals conflict.
- How you drive execution when scope is ambiguous and ownership is unclear.
- Your view on the tradeoffs of working on security at a frontier AI company, given the concerns OpenAI links to in the posting.
Common mistakes to avoid
- Applying with only general TPM experience and no security, privacy, IT, or compliance program work.
- Ignoring the posting's own link to concerns about working at a frontier AI lab and not addressing the topic at all.
- Describing team-level achievements without saying what you personally drove, since the role is execution-focused.
Deadline
No deadline is listed. Roles without a deadline usually close once the employer has enough candidates, so apply soon if you are interested.