The opportunity
OpenAI’s Governance, Risk, and Compliance team helps ensure security and privacy are grounded in how our products and systems actually operate. Assurance Operations partners with Security, Engineering, Infrastructure, Product, Privacy, and Legal to make controls provable, risk…
What you'll do
Lead external, internal, customer, and certification audit work from scoping: through evidence review, fieldwork, remediation, and closeout.
Build a common control framework linking risk, control intent,: implementation, owner, system, environment, evidence, and applicable frameworks.
Validate actual scope and ownership instead of assuming last year's controls,: product boundaries, or evidence remain accurate.
Use Codex to build and test evidence checks, control mappings, request: triage, owner workflows, monitoring, and remediation reporting.
Partner with engineers on cloud architecture, identity, logging, data flows,: software changes, vulnerabilities, and control effectiveness.
Design maintainable, permission-aware tools that preserve source provenance,: human review, and evidence integrity.
What they're looking for
- Reduce repeated requests and operational burden for control owners through measurable workflow improvements.
- Define roadmaps, decision rights, milestones, success metrics, and clear cross-functional escalations.
- Direct ownership of meaningful audit, security, customer-assurance, or regulatory outcomes.
- Practical knowledge of control design, evidence, testing, operating effectiveness, and remediation.