About the RoleWe're looking for a
Software Security Architect to define the security architecture for OpenAI's next-generation operating system. You'll work alongside hardware security architects and partner with operating system, silicon, firmware, privacy, and product teams to protect users, their devices, and their data.
This is a senior, hands-on role for someone who can connect operating system internals, hardware-backed security, and real-world product constraints. Your work will shape the platform's trust model, protect sensitive information, and set the technical foundations for AI that is safe, private, and under user control.
In this role, you will:- Define the operating system's security architecture, trust boundaries, privilege model, and protections for sensitive user data.
- Partner with hardware security architects to integrate roots of trust, secure elements, trusted execution environments, and processor security capabilities into the operating system.
- Design foundational platform defenses, including secure boot, code signing, attestation, secure updates, key protection, and device recovery.
- Establish isolation and access controls across the kernel, applications, system services, and AI workloads.
- Define guardrails for how AI applications and agents access information, use sensors and tools, retain context, and act on a user's behalf.
- Lead threat modeling and architecture reviews across the platform, translating emerging threats into practical, enforceable requirements.
- Prototype solutions, review security-critical systems code, and guide engineering teams through complex technical and product tradeoffs.
Minimum Qualifications:- Deep experience designing or securing operating systems, kernels, embedded platforms, hypervisors, or other privileged systems software.
- Complex understanding of operating system internals, including memory protection, process isolation, executable loading, device drivers, and privilege boundaries.
- Experience building security architectures that span hardware, firmware, operating systems, applications, and cloud services.
You might thrive in this role if you:- Bring practical expertise in secure boot, code signing, device identity, attestation, trusted execution, and hardware-backed key protection.
- Can write or review systems code in C, C++, Rust, or comparable languages, with a strong grasp of secure development and exploit mitigation.
- Build rigorous threat models, influence cross-functional engineering teams, and communicate security tradeoffs clearly.
- Care deeply about user privacy, personal agency, and building systems that earn trust through their design.
Helpful experience:- Shipping security technologies for consumer operating systems, mobile platforms, or connected devices.
- Kernel hardening, memory-safety mitigations, virtualization-based security, or secure enclave integration.
- Security architecture for AI agents, sensitive-context isolation, permissioned tool use, or prompt-injection resistance.
- Device provisioning, manufacturing security, secure recovery, or lifecycle security for hardware products.