Product Manager, Codex Security Controls & Partner Interfaces

OpenAI

USremote country$293k-$385k/yrPosted Jul 13, 2026
Posting intelligenceActively listed

Skills

openaiasanacsscicd

About the role

ABOUT THE TEAM

OpenAI’s Cyber team works to make frontier AI safe, trusted, and transformative for developers and enterprises.

This team is building the security foundation for Codex: the native controls that govern what Codex can access and do, and the interfaces that allow customers and security partners to inspect, constrain, approve, and respond to Codex activity.

Our goal is to make Codex secure by default, governable by enterprises, and interoperable with the security products customers already trust. This extends the existing product direction around tenant-scoped tools, guarded actions, approval systems, and scalable partner interfaces.

ABOUT THE ROLE

We are looking for a deeply technical Product Manager to help build Codex security controls and the partner ecosystem around them.

This role focuses on securing Codex itself: how identity, permissions, tools, MCP servers, repositories, secrets, networks, and high-impact actions are governed across Codex products.

You will also help define standard interfaces through which authorized customer and partner systems can provide security context, inspect activity, return policy decisions, receive telemetry, and initiate bounded responses.

You will work closely with Codex product and engineering, OpenAI Security and Safety, enterprise customers, and partners across application security, identity, cloud security, data security, infrastructure, and security operations.

IN THIS ROLE YOU WILL

Build native security controls for Codex

Partner with engineering, design, security, and safety teams to develop controls for:

- Identity, roles, permissions, and tenant isolation.

- Access to repositories, files, tools, MCP servers, secrets, networks, and infrastructure.

- Read, write, execute, and deployment authority.

- Human and policy-based approvals.

- Prompt-injection and untrusted-content defenses.

- Audit trails, provenance, stop conditions, revocation, and rollback.

Help establish a graduated authority model in which local, read-only, and reversible actions require less friction than actions involving production systems, credentials, sensitive data, or irreversible changes.

Define partner interfaces

Develop common, versioned interfaces that allow customer-selected security products to participate in Codex workflows.

These interfaces may support:

- Sharing trusted identity, task, resource, and environment context.

- Inspecting code, commands, artifacts, tool calls, or planned actions.

- Returning allow, deny, constrain, or require-approval decisions.

- Exporting normalized execution and security telemetry.

- Pausing activity, revoking access, or requiring reauthorization.

Define clear requirements for authentication, authorization, customer consent, data minimization, latency, retries, failure behavior, auditability, and backwards compatibility.

Ensure integrations use shared platform contracts rather than creating a different Codex architecture for every partner.

Build the partner ecosystem

Work directly with security vendors and enterprise design partners to turn the interfaces into production integrations.

Create partner SDKs, reference implementations, technical documentation, test environments, conformance suites, and certification requirements.

Prioritize partners based on customer value, technical relevance, deployment readiness, and their ability to improve the shared platform—not simply logo value or launch timing.

Turn lessons from individual partner engagements into reusable product capabilities.

Shape the customer experience

Define how enterprise administrators configure and understand Codex security controls, including:

- Policies by user, workspace, repository, environment, tool, or action.

- Approved security providers and permitted data sharing.

- Approval requirements and time-limited exceptions.

- Policy inheritance and conflict resolution.

- Audit, investigation, and incident-response workflows.

Ensure developers receive clear, actionable explanations when an action is blocked or requires approval, rather than an opaque policy error.

Establish evaluation and launch gates

Work with security, safety, research, and engineering teams to test whether controls work under realistic and adversarial conditions.

Evaluate risks such as permission bypass, prompt injection, malicious tools, secret exposure, cross-tenant access, stale authorization, partner outages, conflicting decisions, and incomplete audit evidence.

Help determine when new Codex capabilities have sufficient controls, reliability, and usability for broader deployment.

YOU MIGHT THRIVE IN THIS ROLE IF YOU

- Have built enterprise security, developer-platform, infrastructure, or control-plane products.

- Understand identity, authorization, sandboxing, secrets, tool use, APIs, and audit systems.

- Think naturally in terms of trust boundaries, failure modes, and abuse paths.

- Can balance security, developer productivity, latency, reliability, and customer control.

- Have experience building integrations across complex enterprise systems or partner ecosystems.

- Can turn conflicting partner requirements into a coherent platform.

- Communicate credibly with developers, security architects, CISOs, researchers, and partner product teams.

- Prefer measurable security outcomes and real adoption over demonstrations or integration announcements.

NICE TO HAVE

- Experience in application security, identity, cloud security, data security, source control, CI/CD, SIEM, or enterprise governance.

- Familiarity with RBAC, ABAC, policy-as-code, OAuth, OIDC, workload identity, or secrets management.

- Experience with AI agents, MCP, sandboxed execution, prompt-injection defenses, or agent-security evaluations.

- Experience building SDKs, developer platforms, integration marketplaces, or certification programs.

WHAT SUCCESS LOOKS LIKE

During your first six months, you will have helped establish:

- A clear roadmap for native Codex controls and partner-extensible controls.

- A common architecture for security context, policy decisions, inspection, telemetry, and response.

- Initial reference integrations with a focused group of partners.

- Evaluation and launch criteria for high-risk Codex capabilities.

- Baseline measures for control coverage, bypass resistance, latency, reliability, and developer experience.

During your first year, you will have helped ship meaningful controls across sensitive Codex workflows, brought standardized partner interfaces into production use, and demonstrated that enterprises can grant Codex greater authority without sacrificing visibility, control, or accountability.

About OpenAI

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.

To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form https://form.asana.com/?d=57018692298241&k=5MqR40fZd7jlxVUh5J-UeA. No response will be provided to inquiries unrelated to job posting compliance.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link https://form.asana.com/?k=bQ7w9h3iexRlicUdWRiwvg&d=57018692298241.

OpenAI Global Applicant Privacy Policy https://cdn.openai.com/policies/global-employee-and-contractor-privacy-policy.pdf

At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

Compensation

This Security Engineer role pays $293k-$385k/yr. Within typical range for security engineer roles in United States.

Questions about this role

Click "Apply with AI Applyd" above and you are done. Your resume is rewritten for this advert, the screening questions are answered, and it is submitted on OpenAI's own hiring system. No retyping your history, no fourteen tabs, no evening lost.

Compensation for Security Engineer roles in United States varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Security Engineer hub for United States medians across recent openings.

You never touch the form - the application is filled and submitted for you on OpenAI's own hiring system. It is not marked sent when we press submit. It is marked sent when a confirmation from their system arrives at the address we apply with, and your dashboard shows which stage each application is at until then.

Twelve applicant tracking systems have a real apply path: Workday, Greenhouse, Lever, Ashby, Workable, iCIMS, Personio, Recruitee, Teamtailor, Rippling, Breezy and SmartRecruiters. Your application goes in on the employer's own hiring system, never into an aggregator queue.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.