远程工作雷达

安全工程师,应用安全

Security Engineer, Application Security

开发工程限定地区(需当地身份)
公司Openai
薪资$266,000 - $445,000
工作地点San Francisco / US - Remote
地域资格限定地区(需当地身份)
时区要求无特别要求
用工类型FullTime
发布时间2024-10-02
数据来源Ashby
前往企业招聘页投递 →
注意地域限制:该职位明确限定在 US - Remote 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

关于团队

安全是OpenAI使命的基石,确保通用人工智能造福全人类。安全团队保护OpenAI的技术、人员和产品。我们在构建方面是技术性的,但在工作中是运营性的,致力于支持OpenAI的所有产品和研究。我们的安全团队原则包括:优先考虑影响力,赋能研究人员,为未来变革性技术做好准备,并推动强大的安全文化。

关于职位

作为应用安全安全工程师,你将负责通过构建安全工具、代码审查、渗透测试和安全评估来识别和缓解软件应用程序中的安全漏洞。

我们寻找那些会与开发团队紧密合作的人,以确保安全编码实践贯穿整个软件开发生命周期,防止安全风险在出现前就被发现。你还将为开发人员和其他利益相关者提供安全指导,推动组织内部的安全意识文化。

该职位优选设在旧金山、西雅图或纽约市,但可能考虑远程工作。我们采用每周3天在办公室的混合工作模式,并为新员工提供搬迁协助。

在此职位中,你将:

- 执行安全评估:定期进行安全评估、代码审查和渗透测试,以识别应用程序和软件中的漏洞。
- 开发和实施安全工具:设计、开发和实施安全工具、框架和方法,以保护应用程序免受安全威胁。
- 与开发团队协作:与开发团队紧密合作,确保安全最佳实践贯穿整个软件开发生命周期(SDLC),包括安全编码指南。
- 威胁建模和风险评估:进行威胁建模和风险评估,主动识别潜在风险并制定缓解策略。
- 漏洞管理:跟踪、分析和管理应用程序中的漏洞,为修复工作提供指导和支持。
- 事件响应支持:协助调查、分析和应对与应用程序相关的安全事件,确保及时解决并记录事件。
- 跟进安全趋势:持续关注安全趋势,保持对最新安全技术和威胁的了解。

查看英文原文

About the Team

Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.

About the Role

As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments.

We’re looking for people who will work closely with development teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge. You will also provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization.

The role is preferred to be based in San Francisco, Seattle or New York City but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.

In this role, you will:

- Perform Security Assessments: Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software.

- Develop and Implement Security Tools: Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats.

- Collaborate with Development Teams: Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines.

- Threat Modeling and Risk Assessment: Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies.

- Vulnerability Management: Track, analyze, and manage vulnerabilities in applications, providing guidance and support for remediation efforts.

- Incident Response Support: Assist in investigating, analyzing, and responding to security incidents related to applications, ensuring timely resolution and documentation of incidents.

- Stay Current on Security Trends: Continuously stay updated on the latest security threats, vulnerabilities, and technologies to enhance security measures in applications.

You might thrive in this role if you:

- Extensive experience in information security, cybersecurity, or a related field, with a significant portion of that experience in leadership or management roles.

- Deep understanding of security technologies, tools, and best practices, including experience with secure coding practices, threat modeling, risk assessments, and incident response.

- Experience in application security, software development, or related areas with a strong understanding of secure coding practices and application security frameworks.

- Proficiency in programming languages (such as Python, Java, C++, etc.), knowledge of security tools (e.g., Burp Suite, OWASP ZAP), and familiarity with security protocols and encryption methods.

- Strong written and verbal communication skills, with the ability to explain complex security issues to both technical and non-technical audiences

About OpenAI

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.

We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.

For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement https://cdn.openai.com/policies/eeo-policy-statement.pdf.

Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.

To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form https://form.asana.com/?d=57018692298241&k=5MqR40fZd7jlxVUh5J-UeA. No response will be provided to inquiries unrelated to job posting compliance.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link https://form.asana.com/?k=bQ7w9h3iexRlicUdWRiwvg&d=57018692298241.

OpenAI Global Applicant Privacy Policy https://cdn.openai.com/policies/global-employee-and-contractor-privacy-policy.pdf

At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

本页面信息整理自 Ashby,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

学习产品经理

OpenaiSan Francisco$293,000 - $385,000FullTime21 天前
AI职能支持全球可投(据职位描述推断)

← 返回全部职位