网络操作策略师,关键危害行动
Cyber Operations Strategist, Critical Harm Operations
关于团队
Critical Harm Operations 位于用户安全与风险运营部门,为前沿风险和重大危害构建执行系统,这些系统需要准确、快速、可辩护,并且具备扩展性。网络安全垂直领域将政策转化为审查标准、校准判断、质量系统、升级路径和自动化防护措施。
关于职位
我们正在寻找一位高级网络安全从业者和运营策略专家,以提升我们的网络安全运营在质量、可扩展性和技术严谨性方面的能力。您将结合实际的网络安全判断与系统级运营设计:解决最困难的双重用途问题,优化标准操作流程,提升审查员和供应商的能力,并构建实用的工具和自动化方案。
这是一个高级专家角色。成功的关键不在于处理了多少案件,而在于运营模式和执行该模式的审查员的持续改进。
这个多伦多的职位目前是远程办公,预计将来会转为办公室工作。
在这个职位上,您将:
- 在各个领域优先事项、标准操作流程、升级路径、质量健康、供应商能力、路线图输入等方面推动网络安全运营的运作模式,并协助制定可信访问策略。
- 作为复杂或高风险决策的高级网络安全专家,覆盖ChatGPT、API、Codex、代理和新兴产品界面。
- 将政策模糊性、质量疏漏、申诉和审查员分歧转化为清晰的决策规则、校准示例、培训和工具需求。
- 构建持久的运营系统和质量循环:黄金集、保留样本、双标注、裁决、错误分类法、审查员校准和自动化评估。
- 通过入职培训、认证、指导、定期校准和供应商绩效合作,提升全职员工和外包人员的能力。
- 利用质量、申诉、SLA、积压任务和分歧信号来诊断根本原因并优先处理高杠杆修复。
- 构建实际解决方案——SQL分析、脚本、仪表板、LLM评估流程、证据增强、路由逻辑和轻量级自动化,以提高决策质量并减少手动工作量。
- 与政策、诚信、安全系统、安全、法律、产品、工程和调查团队合作,实现变更的落地并推动发布准备。
如果您具备以下条件,可能会在这个职位上表现出色:
- 具有8年以上在进攻性安全、威胁情报、事件响应、安全研究或红队方面的实际网络安全经验
查看英文原文
ABOUT THE TEAM
Critical Harm Operations sits within User Safety & Risk Operations and builds enforcement systems for Frontier Risk and Material Harm that are accurate, fast, defensible, and built to scale. The Cyber vertical turns policy into reviewer standards, calibrated judgment, quality systems, escalation paths, and automation guardrails.
ABOUT THE ROLE
We are looking for a senior cybersecurity practitioner and operations strategist to raise the quality, scalability, and technical rigor of our Cyber Operations. You will combine hands-on cyber judgment with systems-level operating design: resolve the hardest dual-use questions, evolve SOPs, uplift reviewers and vendors, and build practical tools and automations.
This is a senior IC role. Success is not primarily cases closed; it is durable improvement in the operating model and the reviewers who run it.
This Toronto-based role is currently remote and is expected to transition to an in-office arrangement.
IN THIS ROLE, YOU WILL:
- Drive the Cyber Operations operating model across domain priorities, SOPs, escalation paths, quality health, vendor capability, roadmap inputs and help inform trusted access strategies.
- Serve as the senior cyber expert for complex or high-risk decisions across ChatGPT, API, Codex, agents, and emerging product surfaces.
- Translate policy ambiguity, quality misses, appeals, and reviewer disagreement into clear decision rules, calibration examples, training, and tooling requirements.
- Build durable operating systems and quality loops: golden sets, holdouts, double-labeling, adjudication, error taxonomies, reviewer calibration, and automation evaluations.
- Raise FTE and BPO capability through onboarding, certification, coaching, recurring calibration, and vendor-performance partnership.
- Use quality, appeals, SLA, backlog, and disagreement signals to diagnose root causes and prioritize high-leverage fixes.
- Build hands-on solutions—SQL analyses, scripts, dashboards, LLM eval workflows, evidence enrichment, routing logic, and lightweight automations—that improve decision quality and reduce manual effort.
- Partner with Policy, Integrity, Safety Systems, Security, Legal, Product, Engineering, and Investigations to operationalize changes and drive launch readiness.
YOU MIGHT THRIVE IN THIS ROLE IF YOU HAVE:
- Have 8+ years of hands-on cybersecurity experience in offensive security, threat intelligence, incident response, security research, red teaming, application security, DFIR, malware analysis, or a related field.
- Can reason deeply about attacker tradecraft, vulnerability exploitation, credential abuse, malware, persistence, evasion, exfiltration, cloud or identity abuse, and ambiguous dual-use activity.
- Have built or improved high-stakes operations, reviewer programs, QA systems, escalation workflows, or vendor/BPO programs.
- Can turn complex cyber and policy judgment into reviewer-usable SOPs, decision trees, training, and concise written recommendations.
- Are comfortable using SQL, Python, Python, C/C++, JavaScript, PowerShell, and Bash, APIs, LLM tooling, or automation to solve operational problems.
- Understand human-in-the-loop automation, evaluations, monitoring, holdouts, and fallback paths for sensitive workflows.
- Operate independently in ambiguity, communicate clearly across technical and non-technical audiences, and bring sound judgment and discretion when handling sensitive material.
- Experience with trust and safety, platform abuse, cyber misuse of AI systems, or LLM safety.
NICE TO HAVE:
- Experience with golden sets, classifier or prompt evaluations, and reviewer-quality programs.
- Experience enabling global vendor reviewer operations.
About OpenAI
OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.
We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.
For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement https://cdn.openai.com/policies/eeo-policy-statement.pdf.
Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.
To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form https://form.asana.com/?d=57018692298241&k=5MqR40fZd7jlxVUh5J-UeA. No response will be provided to inquiries unrelated to job posting compliance.
We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link https://form.asana.com/?k=bQ7w9h3iexRlicUdWRiwvg&d=57018692298241.
OpenAI Global Applicant Privacy Policy https://cdn.openai.com/policies/global-employee-and-contractor-privacy-policy.pdf
At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.