Security Engineer, Host Assurance

OpenAI

San Francisco (CA)

On-site

USD 130,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading AI research company is seeking a Security Engineer, Host Assurance, to establish trust in hardware platforms across its global infrastructure. This hands-on role involves designing systems that ensure secure and reliable operations in high-stakes environments. Candidates should have strong software engineering skills and expertise in security concepts such as PKI or HSMs. The position is based in San Francisco and involves a hybrid work model, requiring three office days per week.

Qualifications

  • Strong software engineering experience building and operating reliable production systems at scale.
  • Deep expertise in relevant domains like PKI, HSMs, applied cryptography, or firmware security.
  • Ability to work across systems boundaries and write production quality code.

Responsibilities

  • Design, build, and operate components of the Host Assurance platform.
  • Ensure hosts are verifiably trustworthy from delivery through installation.
  • Build and improve systems for host attestation and baseline verification.

Skills

Software engineering experience
Expertise in PKI, HSMs
Production quality code
Comfort with systems boundaries
Building reliable production systems

Job description

About the Team

Security is foundational to OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity.

The Security organization protects OpenAI’s technology, people, and products by building and operating deeply technical systems that must work reliably at massive scale. Our work underpins OpenAI’s commitments around safety, privacy, and security across research, products, and emerging platforms.

The Host Assurance team exists to make bare metal a dependable, scalable foundation for OpenAI: secure by default, verifiable in practice, and resilient across providers and operating models. We operate at the trust boundary between physical hardware and cloud-scale orchestration, ensuring that hosts are eligible to safely run workloads with predictable security properties and auditability.

About the Role

OpenAI is seeking a Security Engineer, Host Assurance to help build the trust foundations for bare-metal platforms across OpenAI’s global infrastructure. This is a deeply hands-on engineering role for a builder who can design, implement, and operate the core security infrastructure that establishes trust in hardware platforms before they are eligible to run workloads.

Success in this role requires strong technical judgment, the ability to work comfortably at low levels of the stack, and a practical mindset for building systems that are secure, reliable, and usable in fast-moving production environments. The systems you build will sit on the critical path of OpenAI’s frontier infrastructure investments and will directly shape how large amounts of compute are brought online – securely, responsibly, and at global scale – underpinning long-lived commitments around privacy, security, and reliability.

You will partner closely with infrastructure, research, and confidential computing initiatives—including novel hardware platforms and emerging deployment models– to make the secure path the easiest path. This role is well suited for engineers who enjoy working across trust services, operating systems, hardware and firmware validation, and infrastructure security, and who are excited by ambiguous, high-impact problems at the boundary of hardware and large-scale systems.

In this role, you will:
  • Design, build, and operate components of the Host Assurance platform that establish trust in bare-metal hosts before they are eligible for production use.

  • Help ensure hosts are verifiably trustworthy from delivery and installation through secure bootstrap and readiness to join orchestration systems.

  • Build and improve systems such as machine identity, certificate issuance and enrollment, HSM-backed or key-management-backed trust services, host attestation, measurement, and baseline verification tooling.

  • Validate delivered hardware and firmware against vendor claims and continuously detect and manage drift over time.

  • Eliminate insecure bootstrap patterns while preserving deployment throughput and operational reliability. Partner with provisioning, fleet, and orchestration teams to deliver paved paths where the secure approach is the easiest approach.

  • Contribute code, reviews, operational improvements, and design guidance for foundational trust services that must be dependable at scale.

  • Help define observable, testable security properties for host platforms and improve the telemetry and validation needed to enforce them in practice.

  • Participate in incident response, debugging, and post-incident improvements for security-critical infrastructure.

  • Work across different deployment models and provider boundaries while maintaining a consistent bar for host trust outcomes.

You might thrive in this role if you:
  • Have strong software engineering experience building and operating reliable production systems at scale.

  • Have deep expertise in at least one relevant domain such as PKI, HSMs, machine identity, applied cryptography, secure boot, firmware or hardware security, host attestation, or low-level platform security.

  • Are comfortable working across systems boundaries, from services and APIs down to host, boot, firmware, or hardware-adjacent trust mechanisms.

  • Can write production quality code and reason clearly about failure modes, operational safety, and long-term maintainability.

  • Have experience replacing fragile or manual security mechanisms with durable, paved-path infrastructure.

  • Balance rigor with pragmatism, and care about making strong security controls deployable in real-world environments.

  • Are self-directed, low ego, and willing to work across disciplines to solve the most important problems.

  • Enjoy building in ambiguous spaces where the architecture is still emerging, stakes are at all time high, and the future is being built.

Workplace & Location
  • This role is preferably based in San Francisco, CA or Seattle, WA. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.

About OpenAI

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.

We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.

For additional information, please see OpenAI’s Aff….

Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.

To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.

OpenAI Global Applicant Privacy Policy

At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer, Host Assurance OpenAI San Francisco
Security Engineer, Host Assurance OpenAI San Francisco

Neura Market • San Francisco (CA), Northern (KY)

Hybrid
USD 190,000 - 260,000
Security Engineer, Host Assurance
Security Engineer, Host Assurance

OpenAI • Los Angeles (CA)

Hybrid
USD 120,000 - 160,000
Hybrid work model
Relocation assistance
Equal opportunity employer
Software Engineer, Infrastructure Security
Software Engineer, Infrastructure Security

algojobs • San Francisco (CA)

On-site
USD 120,000 - 160,000
Software Engineer, Infrastructure Security
Software Engineer, Infrastructure Security

OpenAI • United States

On-site
USD 230,000 - 385,000
Staff Security Reliability Engineer
Staff Security Reliability Engineer

Neura Market • San Francisco (CA)

On-site
USD 170,000 - 210,000
Principal Software Engineer, Infrastructure Security OpenAI Remote - US
Principal Software Engineer, Infrastructure Security OpenAI Remote - US

Neura Market • Northern (KY)

Hybrid
USD 240,000 - 290,000
Principal Security Engineer, Infrastructure Security OpenAI Remote - US
Principal Security Engineer, Infrastructure Security OpenAI Remote - US

Neura Market • Northern (KY)

Hybrid
USD 180,000 - 280,000
Staff Security Reliability Engineer
Staff Security Reliability Engineer

OpenAI • San Francisco (CA)

On-site
USD 293,000 - 385,000
Equity offers
Equal opportunity employer
Security Engineer, Host Assurance – Bare-Metal Trust
Security Engineer, Host Assurance – Bare-Metal Trust

Neura Market • San Francisco (CA), Northern (KY)

Hybrid
USD 190,000 - 260,000
Security Engineer, Infrastructure Security
Security Engineer, Infrastructure Security

OpenAI • San Francisco (CA)

On-site
USD 292,000 - 405,000
Medical, dental, and vision insurance
401(k) retirement plan with employer match
Paid parental leave
+2