Model Policy, Frontier Cyber Risk

OpenAI

San Francisco (CA)

Hybrid

USD 207,000 - 295,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

OpenAI is seeking a cybersecurity policy developer in San Francisco to define model behavior in high-risk environments. Responsibilities include designing cybersecurity policies and translating threat models into actionable guidelines.

The ideal candidate should possess strong expertise in cybersecurity, judgment about AI's impacts, and experience with threat models. OpenAI offers a hybrid work model, supporting relocation if needed.

Qualifications

  • Strong judgment about AI's impact on cyber threats.
  • Experience in building threat models in high-risk environments.
  • Ability to translate technical expertise into policy frameworks.

Responsibilities

  • Design and maintain model policies for cybersecurity.
  • Translate threat models into behavioral specifications.
  • Build policy artifacts for training and evaluation systems.

Skills

Cybersecurity expertise
Threat intelligence
Incident response
Exploit development
Strong written communication

Job description

About The Role

Frontier AI systems are rapidly expanding what is possible in cybersecurity and software engineering. These capabilities create major defensive opportunities, but they also raise serious dual‑use and misuse risks across areas such as malware development, exploit discovery, vulnerability chaining, credential abuse, cyber intrusion, and autonomous offensive operations.

In this role, you will help define how OpenAI’s models should behave in high‑risk cybersecurity contexts. You will develop policy frameworks, threat models, taxonomies, evaluations, and behavioral specifications that guide model behavior across training, deployment, and monitoring systems. This role sits at the intersection of cybersecurity, AI safety, threat modeling, evaluation science, and policy implementation.

You will work closely with research, engineering, safety training, preparedness, and product teams to build policies that are technically grounded, measurable, enforceable, and responsive to real‑world cyber risk.

Your Responsibilities
  • Design and maintain model policies for cybersecurity and frontier‑risk domains, especially dual‑use and high‑risk cyber capabilities.
  • Translate cybersecurity threat models into clear behavioral specifications, evaluation criteria, grading guidance, and system‑level mitigations.
  • Define practical boundaries between legitimate security research, defensive workflows, and assistance that could materially enable harmful activity.
  • Build policy artifacts that support implementation across training, evaluation, deployment, monitoring, and escalation systems.
  • Partner with safety researchers, engineers, and evaluation teams to operationalize policies into scalable model behavior and measurable safeguards.
  • Analyze red‑teaming results, deployment data, model failures, over‑refusals, and ambiguous edge cases to improve policy and evaluation quality over time.
  • Identify emerging cyber capability areas where advanced AI systems could lower barriers to misuse or increase operational capability for malicious actors.
  • Contribute to system cards, safety reports, policy documentation, and external communications on OpenAI’s approach to cyber risk mitigation.
We’re Seeking
  • Strong technical expertise in cybersecurity, such as offensive security, defensive security, vulnerability research, malware analysis, incident response, threat intelligence, application security, exploit development, infrastructure security, or cloud security.
  • Strong judgment about how AI systems may affect the cyber threat landscape, including dual‑use, autonomous, or agentic system risks.
  • Ability to distinguish between legitimate security use cases and assistance that could materially enable harmful cyber activity.
  • Experience building or applying threat models to complex technical systems, especially in adversarial or high‑risk environments.
  • Ability to translate technical security expertise into structured policy frameworks, evaluation criteria, operational guidance, and enforcement mechanisms.
  • Comfort using empirical evidence, including evaluations, red‑teaming results, deployment observations, and model failure modes, to inform policy decisions.
  • Strong systems thinking across policy, evaluations, classifiers, training, deployment safeguards, measurement, and monitoring.
  • Ability to work cross‑functionally with researchers, engineers, product teams, policy experts, and operational stakeholders.
  • Strong written communication skills, especially the ability to explain complex technical and security concepts clearly.
  • A pragmatic approach to safety: focused on reducing real‑world risk while preserving legitimate, beneficial, and defensive uses of AI.
Workplace & Location

This role is based in our San Francisco office. We do encourage you to apply even if you prefer a different work location as factors may change over time. We offer relocation support to new employees, and we use a hybrid model: three days in the office per week with optional work from home on Thursdays and Fridays.

Equal Opportunity

We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.

For additional information, please see OpenAI’s Aff… (Affirmative Action and Equal Employment Opportunity Policy Statement).

Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance…

Compensation

Compensation Range: $207K - $295K

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Model Policy, Frontier Cyber Risk
Model Policy, Frontier Cyber Risk

OpenAI • Los Angeles (CA)

Hybrid
USD 207,000 - 295,000
Model Policy, Frontier Cyber Risk
Model Policy, Frontier Cyber Risk

Slope • San Francisco (CA)

On-site
USD 207,000 - 295,000
Medical, dental, and vision insurance
401(k) retirement plan with employer match
Paid parental leave
+4
Researcher, Frontier Cybersecurity Risks
Researcher, Frontier Cybersecurity Risks

OpenAI • Los Angeles (CA)

On-site
USD 295,000 - 445,000
Model Policy
Model Policy

Neura Market • San Francisco (CA)

Hybrid
USD 180,000 - 280,000
Researcher, Frontier Cybersecurity Risks
Researcher, Frontier Cybersecurity Risks

Slope • San Francisco (CA)

On-site
USD 295,000 - 445,000
Researcher, Frontier Cybersecurity Risks
Researcher, Frontier Cybersecurity Risks

OpenAI • San Francisco (CA)

On-site
USD 295,000 - 445,000
Model Policy (Rodrigo)
Model Policy (Rodrigo)

Triwill Group • San Francisco (CA)

On-site
USD 180,000 - 250,000
Relocation assistance
Hybrid work model
Policy Lead: Frontier Cyber Risk & AI Safety
Policy Lead: Frontier Cyber Risk & AI Safety

OpenAI • San Francisco (CA)

Hybrid
USD 207,000 - 295,000
Researcher, Frontier Cybersecurity Risks
Researcher, Frontier Cybersecurity Risks

United States Digital Space LLC • San Francisco (CA)

On-site
USD 140,000 - 230,000
Researcher, Frontier Cybersecurity Risks
Researcher, Frontier Cybersecurity Risks

Applied Methods Ltd • San Francisco (CA)

On-site
USD 30,000 - 45,000