
Security Engineer, Application Security

Security Engineer, Application Security
OpenAI
The Security Engineer, Application Security role at OpenAI focuses on identifying and mitigating security vulnerabilities in software applications. The position involves building security tools, conducting code reviews, penetration testing, and fostering a culture of security awareness within the organization. The role is part of a hybrid work model and is based in major cities like San Francisco, Seattle, or New York City, with remote work options available.
Qualification
- Extensive experience in information security, cybersecurity, or a related field, with a significant portion of that experience in leadership or management roles.
- Deep understanding of security technologies, tools, and best practices, including experience with secure coding practices, threat modeling, risk assessments, and incident response.
- Experience in building security tools and frameworks to enhance application security.
- Strong analytical and problem-solving skills to identify and mitigate security vulnerabilities.
- Ability to collaborate effectively with development teams and other stakeholders to promote security awareness and best practices.
Responsibility
- Perform Security Assessments: Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software.
- Develop and Implement Security Tools: Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats.
- Collaborate with Development Teams: Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines.
- Threat Modeling and Risk Assessment: Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies.
- Vulnerability Management: Track, analyze, and manage vulnerabilities in applications, providing guidance and support for remediation efforts.
- Incident Response Support: Assist in investigating, analyzing, and responding to security incidents related to applications, ensuring timely resolution and documentation of incidents.
- Stay Current on Security Trends: Continuously stay updated on the latest security threats, vulnerabilities, and technologies to enhance security measures in applications.




