The opportunity
OpenAI’s Hardware organization develops AI-native silicon and system-level solutions for the unique demands of advanced AI workloads. Building on efforts like Jalapeño, the team is developing future generations of AI-native silicon and tightly integrated systems to power the next generation of frontier models.
What you'll do
Own security requirements, threat models, validation strategy, and: launch-readiness evidence for first-party hardware platforms from early design through production deployment.
Design and review secure boot, measured boot, roots of trust, platform: firmware resilience, firmware signing, recovery, and anti-rollback strategies across heterogeneous devices.
Own device identity, provisioning, enrollment, attestation, certificate: lifecycle, and key-management requirements across manufacturing and data center bring-up.
Harden management interfaces and operational access paths across BMCs, hosts,: accelerators, switches, and service tooling, including TLS/mTLS, Redfish, gNMI, SSH, syslog, and break-glass workflows.
Drive security requirements for manufacturing, supply chain, firmware/image: signing, storage encryption, RMA, repair, and decommissioning processes.
Build and drive validation for security-critical hardware and firmware: behavior, including debug lockout, lifecycle transitions, update paths, attestation evidence, and recovery flows.
What they're looking for
- Partner with vendors and contract manufacturers to turn security requirements: into concrete deliverables, test evidence, and launch gates.
- Drive end-to-end closure across design, implementation, manufacturing: readiness, deployment readiness, fleet operations, and incident response when security issues arise.
- Investigate hardware and firmware security issues, assess exploitability and: operational risk, and drive durable fixes with engineering owners.
- + years of hands-on experience, or exceptional accomplishments demonstrating: equivalent expertise, in hardware security, embedded security, firmware security, platform security, or low-level systems security.