Security Engineer, Application Security
Job Description
OpenAI is seeking a Security Engineer, Application Security to strengthen the security posture of its software applications. In this hybrid role based in Seattle, WA, you will help find and reduce vulnerabilities by building security tooling, reviewing code, performing penetration testing, and executing security assessments across the software lifecycle.
This position focuses on partnering with development teams to embed secure coding practices throughout the SDLC and to provide practical security guidance to relevant stakeholders.
Key Responsibilities
- Perform regular security assessments, code reviews, and penetration testing to uncover vulnerabilities in applications and software.
- Design, develop, and implement security tools, frameworks, and methodologies to help protect applications from security threats.
- Collaborate with development teams to ensure security best practices are applied throughout the SDLC, including secure coding guidelines.
- Carry out threat modeling and risk assessments to identify risks early and define mitigation strategies.
- Track, analyze, and manage vulnerabilities found in applications, and provide guidance and support to drive remediation.
- Support the investigation, analysis, and response to application-related security incidents, ensuring timely resolution and documentation.
- Stay current on security threats, vulnerabilities, and technologies to continuously improve application security.
Requirements
- Extensive experience in information security, cybersecurity, or a related field, with a significant portion of that experience in leadership or management roles.
- Deep understanding of security technologies, tools, and best practices, including experience with secure coding practices, threat modeling, risk assessments, and incident response.
- Experience in application security, software development, or related areas, with strong knowledge of secure coding practices and application security frameworks.
- Proficiency in programming languages such as Python, Java, or C++, plus knowledge of security tools such as Burp Suite and OWASP ZAP, and familiarity with security protocols and encryption methods.
- Strong written and verbal communication skills, with the ability to explain complex security topics to both technical and non-technical audiences.
Technologies
- Python
- Java
- C++
- Burp Suite
- OWASP ZAP
Compensation and Benefits
- $234,400 - $385,000 per year, plus equity offers
- Relocation assistance for new employees