OpenAI· Security· San Francisco
Offensive Security Engineer, Hardware
Comp$293K – $490K
Classified Tasks (20)
Automate 0%Augment 70%Human-Only 30%
Augment (14)
AI assists, human decides
Perform comprehensive penetration testing across hardware products, firmware, and related services.
technical
Continuously test hardware products and related services to discover vulnerabilities and weaknesses.
technical
Reverse engineer bootrom images, firmware, and silicon-level components to identify security flaws.
technical
Analyze low-level kernel operations, secure boot processes, and hardware–software interactions for vulnerabilities.
analytical
Build and validate secure boot chains and threat models for hardware platforms.
technical
Develop, automate, and apply offensive security techniques and tooling using advanced automation and OpenAI technologies.
technical
Write and maintain robust offensive tools and automation in C/C++, Python, and assembly for embedded systems.
technical
Conduct code reviews to identify novel and subtle vulnerabilities in firmware and software.
analytical
Assess complex technology stacks, including consumer hardware such as mobile devices, IoT devices, and chipsets, for security weaknesses.
analytical
Prepare and present clear, actionable findings and technical reports to technical and non‑technical stakeholders.
communication
Provide attacker-driven insights to inform risk assessments, threat models, and security strategy.
analytical
Contribute code fixes or mitigation plans within complex codebases to resolve security issues.
technical
Validate security controls and defenses through offensive testing and red-teaming activities.
technical
Automate offensive operations and integrate cutting‑edge technologies to scale testing and exploit development.
technical
Human-Only (6)
Requires human judgment
Collaborate with engineering teams to enhance security and mitigate risks across hardware, firmware, and software.
leadership
Design and execute innovative attack simulations targeting hardware, firmware, and software components.
creative
Use hardware debugging tools (UART, JTAG, SWD, oscilloscopes, logic analyzers) to investigate and exploit hardware issues.
technical
Coordinate with defensive teams to validate mitigations, improve detection, and harden defenses.
communication
Drive remediation by coordinating and working with teams to implement fixes for identified vulnerabilities.
operational
Influence strategic security improvements across the organization by surfacing high-impact risks and recommendations.
leadership
Job description
Offensive Security Engineer, Hardware | OpenAI Careers ## Offensive Security Engineer, Hardware Security - San Francisco Apply now(opens in a new window) **About the Team** Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. **About the Role** We're seeking an exceptional Principal-level Offensive Security Engineer to challenge and strengthen OpenAI's security posture. This role isn't your typical red team job - it's an opportunity to engage broadly and deeply, craft innovative attack simulations, collaborate closely with defensive teams, and influence strategic security improvements across the organization. You'll have the chance to not only find vulnerabilities but actively drive their resolution, automate offensive techniques with cutting-edge technologies, and use your unique attacker perspective to shape our security strategy. This role will be primarily focused on continuously testing our hardware products and related services. **In this role you will:** * Collaborate proactively with engineering teams to enhance security and mitigate risks in hardware, firmware, and software. * Perform comprehensive penetration testing on our diverse suite of products. * Leverage advanced automation and OpenAI technologies to optimize your offensive security work. * Present insightful, actionable findings clearly and compellingly to inspire impactful change. * Influence security strategy by providing attacker-driven insights into risk and threat modeling. **You might thrive in this role if you have:** * 7+ years of hands-on experience or exceptional accomplishments demonstrating equivalent expertise. * Exceptional skill in code review, identifying novel and subtle vulnerabilities. * Demonstrated mastery assessing complex technology stacks, including: + Proven ability to reverse engineer bootrom images, firmware, or silicon-level components. + Deep familiarity with low-level kernel operations, secure boot processes, and hardware-software interactions. + Hands-on experience building and validating secure boot chains and threat models. + Proficiency with hardware debugging tools (UART, JTAG, SWD, oscilloscopes, logic analyzers). + Solid programming skills in C/C++, Python, or assembly for embedded systems. + Industry experience securing consumer hardware (e.g., mobile devices, IoT, chipsets). * Excellent written and verbal communication skills for technical and non-technical audiences. * Strong intuitive understanding of trust boundaries and risk assessment in dynamic contexts. * Excellent coding skills, capable of writing robust tools and automation for offensive operations. * Ability to communicate complex technical concepts effectively through compelling storytelling. * Proven track record of not just finding vulnerabilities but actively contributing to solutions in complex codebases. **Bonus points:** * Prior experience working in tech startups or fast-paced technology environments. * Experience in related disciplines such as Software Engineering (SWE), Detection Engineering, Site Reliability Engineering (SRE), Security Engineering, or IT Infrastructure. **About OpenAI** OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human