Skip to content

Researcher, Automated Red Teaming

OpenAI

San Francisco, USonsite$295k-$445k/yrPosted Feb 23, 2026

At a glance

Highlights

  • Onsite in San Francisco
  • Focus on AI safety and catastrophic risk mitigation
  • Opportunity to lead automated red‑team research

Heads up

  • Onsite requirement
  • High responsibility for catastrophic risk

Why this role might suit you

A candidate with strong AI safety research instincts, hands‑on LLM experience, and a track record in scalable security tooling will thrive leading OpenAI's automated red‑team efforts.

Skills

pythonmachine-learninglarge-language-modelsadversarial-mlsecurity-researchred-teamingevaluation-frameworksdata-structuresalgorithmstestingdistributed-systems

About the role

About the team

Our Safety Systems org ensures that OpenAI’s most capable models can be responsibly developed and deployed. We build evaluations, safeguards, and safety frameworks that help our models behave as intended in real-world settings.

Preparedness is a team within Safety Systems and produces works like OpenAI’s Preparedness Framework. Preparedness tightly connects capability assessment, evaluations, and internal red teaming, and mitigations for frontier models, as well as overall coordination on AGI preparedness. This is fast paced, exciting work that has far reaching importance for the company and for society.

Frontier AI models have the potential to benefit all of humanity, but they also pose increasingly severe risks. To help ensure AI drives positive change, the Preparedness team helps OpenAI prepare for the development of increasingly capable frontier AI models. This team is responsible for identifying, tracking, and mitigating catastrophic risks related to frontier AI systems.

The mission of the Preparedness team is to:

- Closely monitor and predict the evolving capabilities of frontier AI systems, with an eye towards risks whose impact could be catastrophic.

- Ensure we have concrete procedures, infrastructure and partnerships to mitigate these risks and to safely handle the development of powerful AI systems.

About the role

This role leads the Automated Red Teaming (ART) effort: building scalable, research-driven systems that continuously uncover failure modes in our models and safeguards, and translate those findings into actionable, production-facing improvements. The goal is to reduce expected harm by finding the highest-leverage, least-covered weaknesses early and reliably.

In this role, you'll:

- Own the research and technical direction for automated red teaming across catastrophic risk areas, with an initial emphasis on:

- Automated classifier jailbreak discovery (cyber and bio).

- Automated bio threat-development elicitation (worst-feasible planning uplift).

- CoT monitoring evasion probing (and adjacent loss-of-control evaluations).

- Partner closely with:

- Vertical risk teams (Cyber, Bio, Loss of Control) to define threat models, prioritize targets, and land mitigations.

- The Classifiers team to turn discovered attacks into training data, evals, and measurable robustness gains.

- Product / Engineering / Safety stakeholders to ensure ART outputs are operationally useful.

You might thrive in this role if you:

- Feel a strong pull toward AI safety, and you’re motivated by reducing real-world catastrophic risk (not just publishing cool results).

- Love breaking systems (responsibly) — you get energy from finding weird, high-severity failure modes and turning them into concrete fixes.

- Have strong applied research instincts, especially around evaluations: you’re good at designing experiments that are reproducible, interpretable, and hard to fool.

- Bring hands-on experience with LLMs and agents, including multi-turn behaviors, tool use, and the ways models adapt to constraints.

- Are comfortable building scalable automation, not just prototypes — you can turn red-teaming ideas into pipelines that run continuously and produce high-signal outputs.

- Have solid software engineering fundamentals (data structures, algorithms, testing discipline) and you can work effectively in a production-adjacent environment.

- Think in threat models and incentives, and you naturally ask “what would an attacker do next?” or “how would this fail under pressure?”

- Can translate messy findings into action, communicating clearly with researchers, engineers, product, and policy — and driving alignment on what to fix first.

- Care about efficiency and prioritization, and you’re happy to say “no” to low-leverage work to focus on what moves the risk needle.

- Nice to have:

- Experience in adversarial ML, security research / red teaming, abuse prevention systems, or large-scale eval infrastructure.

About OpenAI

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.

We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.

For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement.

Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.

To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.

OpenAI Global Applicant Privacy Policy

At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

Compensation

This Other role pays $295k-$445k/yr. Within typical range for other roles in United States.

Questions about this role

  • How do I apply to this Researcher, Automated Red Teaming role at OpenAI?

    Click "Apply with AI Applyd" above. We auto-fill the application from your resume and answer screening questions in seconds. No copy and paste, no juggling tabs.

  • What's the typical salary for Other in United States?

    Compensation for Other roles in United States varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Other hub for United States medians across recent openings.

  • How fast does AI Applyd auto-apply?

    Most applications complete in under 90 seconds. You can track the status in your dashboard and watch the screenshot proof land the moment the application submits.

  • What ATS does OpenAI use?

    AI Applyd supports Greenhouse, Lever, Ashby, Workday, iCIMS, SmartRecruiters, LinkedIn Easy Apply, and most other ATS platforms. If we can submit through the platform, we do.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.