OpenAI logo

Model Policy, Frontier Cyber Risk

OpenAI

San Francisco, USremote country$207k-$295k/yrPosted May 12, 2026

At a glance

Highlights

  • Hybrid work model (3 days in office)
  • Relocation support
  • Well‑stocked kitchens, in‑house meals, nap rooms

Heads up

  • Onsite three days per week
  • Hybrid schedule may limit full remote flexibility

Why this role might suit you

The role offers a unique blend of cybersecurity expertise and AI safety policy work at a leading AI organization, with hybrid office flexibility, strong support resources, and the chance to shape frontier risk mitigation.

Skills

cybersecuritythreat-modelingmalware-analysisincident-responsevulnerability-researchexploit-developmentcloud-securityai-safetypolicy-frameworksevaluation-sciencered-teamingmodel-evaluationsecurity-researchrisk-assessmentsystems-thinking

About the role

About the Team

Our Safety Systems https://openai.com/safety/safety-systems team is at the forefront of OpenAI's mission to build and deploy safe AGI, driving our commitment to AI safety and fostering a culture of trust and transparency.

Within Safety Systems, the Model Policy team aligns model behavior with desired human values and norms. We co-design policy with models and for models by driving rapid policy taxonomy iteration based on data and defining evaluation criteria for foundational models’ ability to reason about safety.

About the Role

Frontier AI systems are rapidly expanding what is possible in cybersecurity and software engineering. These capabilities create major defensive opportunities, but they also raise serious dual-use and misuse risks across areas such as malware development, exploit discovery, vulnerability chaining, credential abuse, cyber intrusion, and autonomous offensive operations.

In this role, you will help define how OpenAI’s models should behave in high-risk cybersecurity contexts. You will develop policy frameworks, threat models, taxonomies, evaluations, and behavioral specifications that guide model behavior across training, deployment, and monitoring systems. This role sits at the intersection of cybersecurity, AI safety, threat modeling, evaluation science, and policy implementation.

You will work closely with research, engineering, safety training, preparedness, and product teams to build policies that are technically grounded, measurable, enforceable, and responsive to real-world cyber risk.

Your Responsibilities:

- Design and maintain model policies for cybersecurity and frontier-risk domains, especially dual-use and high-risk cyber capabilities.

- Translate cybersecurity threat models into clear behavioral specifications, evaluation criteria, grading guidance, and system-level mitigations.

- Define practical boundaries between legitimate security research, defensive workflows, and assistance that could materially enable harmful activity.

- Build policy artifacts that support implementation across training, evaluation, deployment, monitoring, and escalation systems.

- Partner with safety researchers, engineers, and evaluation teams to operationalize policies into scalable model behavior and measurable safeguards.

- Analyze red-teaming results, deployment data, model failures, over-refusals, and ambiguous edge cases to improve policy and evaluation quality over time.

- Identify emerging cyber capability areas where advanced AI systems could lower barriers to misuse or increase operational capability for malicious actors.

- Contribute to system cards, safety reports, policy documentation, and external communications on OpenAI’s approach to cyber risk mitigation.

We’re Seeking:

- Strong technical expertise in cybersecurity, such as offensive security, defensive security, vulnerability research, malware analysis, incident response, threat intelligence, application security, exploit development, infrastructure security, or cloud security.

- Strong judgment about how AI systems may affect the cyber threat landscape, including dual-use, autonomous, or agentic system risks.

- Ability to distinguish between legitimate security use cases and assistance that could materially enable harmful cyber activity.

- Experience building or applying threat models to complex technical systems, especially in adversarial or high-risk environments.

- Ability to translate technical security expertise into structured policy frameworks, evaluation criteria, operational guidance, and enforcement mechanisms.

- Comfort using empirical evidence, including evaluations, red-teaming results, deployment observations, and model failure modes, to inform policy decisions.

- Strong systems thinking across policy, evaluations, classifiers, training, deployment safeguards, measurement, and monitoring.

- Ability to work cross-functionally with researchers, engineers, product teams, policy experts, and operational stakeholders.

- Strong written communication skills, especially the ability to explain complex technical and security concepts clearly.

- A pragmatic approach to safety: focused on reducing real-world risk while preserving legitimate, beneficial, and defensive uses of AI.

Our relevant publications:

- Accelerating the cyber defense ecosystem that protects us all https://openai.com/index/accelerating-cyber-defense-ecosystem/

- Safety at every step https://openai.com/safety/

- Safety evaluations hub https://openai.com/safety/evaluations-hub/

- GPT‑5.5 System Card https://openai.com/index/gpt-5-5-system-card/

- OpenAI Model Spec https://openai.com/index/introducing-the-model-spec/

Workplace & Location

This role is based in our San Francisco office. We do encourage you to apply even if you prefer a different work location as factors may change over time.

We offer relocation support to new employees, and we use a hybrid model: three days in the office per week with optional work from home on Thursdays and Fridays.

Our open-plan offices have height-adjustable desks, conference rooms, phone booths, well-stocked kitchens full of snacks and drinks, three in-house prepared meals daily, a private outdoor space for working in the sun or socializing, nap rooms, private bike storage, and more.

About OpenAI

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.

To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form https://form.asana.com/?d=57018692298241&k=5MqR40fZd7jlxVUh5J-UeA. No response will be provided to inquiries unrelated to job posting compliance.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link https://form.asana.com/?k=bQ7w9h3iexRlicUdWRiwvg&d=57018692298241.

OpenAI Global Applicant Privacy Policy https://cdn.openai.com/policies/global-employee-and-contractor-privacy-policy.pdf

At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

Compensation

This Security Engineer role pays $207k-$295k/yr. Within typical range for security engineer roles in United States.

Questions about this role

  • How do I apply to this Model Policy, Frontier Cyber Risk role at OpenAI?

    Click "Apply with AI Applyd" above. We auto-fill the application from your resume and answer screening questions in seconds. No copy and paste, no juggling tabs.

  • What's the typical salary for Security Engineer in United States?

    Compensation for Security Engineer roles in United States varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Security Engineer hub for United States medians across recent openings.

  • How fast does AI Applyd auto-apply?

    Most applications complete in under 90 seconds. You can track the status in your dashboard and watch the screenshot proof land the moment the application submits.

  • What ATS does OpenAI use?

    AI Applyd supports Greenhouse, Lever, Ashby, Workday, iCIMS, SmartRecruiters, LinkedIn Easy Apply, and most other ATS platforms. If we can submit through the platform, we do.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.