Security Engineer, Application Security
Job Description
OpenAI is hiring a Security Engineer focused on Application Security in Seattle, WA (hybrid). In this role, you will help identify and reduce application vulnerabilities by building security tooling, reviewing code, performing penetration testing, and supporting risk and incident response activities.
Responsibilities
- Perform ongoing security assessments, code reviews, and penetration testing to uncover vulnerabilities across applications and software.
- Design, develop, and implement security tools, frameworks, and methodologies to reduce exposure to security threats.
- Collaborate with development teams to embed security best practices throughout the software development lifecycle (SDLC), including secure coding guidance.
- Conduct threat modeling and risk assessments to proactively identify potential risks and define mitigation strategies.
- Track, analyze, and manage application vulnerabilities, providing guidance and support to drive remediation.
- Support application security incident investigation, analysis, and response to support timely resolution and incident documentation.
- Maintain current knowledge of emerging security threats, vulnerabilities, and technologies to continually strengthen application security.
Requirements
- Extensive experience in information security, cybersecurity, or a related field, including a significant portion in leadership or management roles.
- Deep understanding of security technologies, tools, and best practices, including secure coding practices, threat modeling, risk assessments, and incident response.
- Experience in application security, software development, or related work, with strong familiarity with secure coding practices and application security frameworks.
- Proficiency in programming languages such as Python, Java, and C++, along with knowledge of security tools including Burp Suite and OWASP ZAP, plus familiarity with security protocols and encryption methods.
- Strong written and verbal communication skills, including the ability to explain complex security topics to both technical and non-technical audiences.
Technologies
- Python
- Java
- C++
- Burp Suite
- OWASP ZAP
Location and Compensation
Location: Seattle, WA (hybrid).
Salary: USD 234,400 - 385,000 per year.
Benefits
- $234.4K β $385K + Offers Equity
- Relocation assistance to new employees