AI Insights
OpenAI

Software Engineer, Identity Infrastructure Engineering

OpenAI · San Francisco, California, US
full-timemid (3-8 yrs)Posted 89d ago
Software EngineeringIC3ICHybrid (3d)Relocation
StackPythonGoAWSAzureGCPOAuthSAMLOpenID ConnectIAMTerraformREST APIsCLI toolingThreat modelingCredential managementAccess policy designRBACMulti-cloud architectureDistributed systems

Summary

A security-focused software engineering role on OpenAI's Identity Infrastructure team, responsible for building and operating IAM systems, multi-cloud security tooling, and access orchestration platforms across AWS, Azure, and GCP.

About the role

About the Team

Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Identity Infrastructure Engineering team sits at the core of this effort, designing and building the identity and access management solutions that protect our model weights, customer data, and critical systems across multiple cloud environments. We partner with teams across OpenAI—Applied Engineering, Research, IT, and Security—to provide a secure and scalable platform for permissioning, orchestration, and innovative AI research.

The role is preferred to be based in San Francisco, Seattle or New York City but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.

About the Role

As a Software Engineer on the Identity Infrastructure Engineering team, you’ll be instrumental in creating, deploying, and operating foundational security tools and infrastructure. You will work with a broad range of technologies to support multi-cloud deployments, ensuring that researchers and engineers can safely build, test, and scale transformative AI systems. The role requires a balance of strong technical depth, cross-functional collaboration, and a passion for embedding secure-by-default principles into every layer of our stack.

We are looking for Software Engineers interested in coming to tackle challenges in these areas:

  • Identity & Access Orchestration: Build and maintain the systems and interfaces that manage user and service identity, ensuring fine-grained access controls are consistent across cloud providers and internal services.

  • Multi-Cloud Security: Design architectures and tooling that protect model weights, custom data, and sensitive assets while operating seamlessly in AWS, Azure, GCP, or future cloud environments.

  • Automation & Tooling: Develop robust frameworks, APIs, and CLI tools that automate recurring security tasks (like provisioning or rotating credentials), freeing teams to focus on AI innovation without sacrificing security.

In this role, you will:

  • Build new features for our IAM platform that seamlessly integrate with evolving cloud services, enabling teams to work efficiently while adhering to security best practices.

  • Drive security innovation by designing tools, processes, and architectures that protect data at scale and reinforce a secure development culture across the organization.

  • Collaborate cross-functionally with researchers, engineers, and compliance teams to address security requirements for multi-cloud deployments, large-scale model training, and emerging AI use cases.

  • Implement and refine access policies that strike the right balance between enabling rapid experimentation and protecting high-value assets, including model weights and customer data.

  • Troubleshoot complex identity or access issues across distributed systems, ensuring minimal downtime and a safe environment for AI research and product teams.

You might thrive in this role if you: 

  • A background in building secure systems—from core IAM services to orchestration layers that manage credentials, roles, or policies at scale.

  • Proficiency in programming languages such as Python, Go, or similar, with a track record of writing high-quality, maintainable code.

  • Experience with modern cloud infrastructure (AWS, Azure, GCP) and familiarity with industry-standard security protocols (OAuth, SAML, OpenID Connect) and authentication/authorization patterns.

  • A security-focused mindset, with knowledge of threat modeling, risk assessment, and the ability to embed security features throughout the software development lifecycle.

  • Excellent collaboration skills—you work well across diverse technical and non-technical teams, turning broad objectives into actionable solutions.

About OpenAI

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity. 

We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.

For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement.

Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.

To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.

OpenAI Global Applicant Privacy Policy

At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

What you'll do

1Build and maintain IAM platform features that integrate with evolving cloud services while enforcing security best practices
2Design tools, processes, and architectures that protect data at scale and reinforce a secure development culture
3Collaborate cross-functionally with researchers, engineers, and compliance teams on multi-cloud and large-scale AI training security requirements
4Implement and refine access policies balancing rapid experimentation with protection of model weights and customer data
5Troubleshoot complex identity and access issues across distributed systems to ensure minimal downtime and security integrity
6Develop APIs, CLI tools, and automation frameworks for provisioning, credential rotation, and recurring security operations

Requirements

3–8+ years of experience building secure systems including IAM services, credential orchestration, and role/policy management at scale
Proficiency in Python, Go, or similar languages with a strong record of writing high-quality, production-grade code
Hands-on experience with multi-cloud infrastructure (AWS, Azure, GCP) and security protocols such as OAuth, SAML, and OpenID Connect
Security-focused engineering mindset with applied knowledge of threat modeling, risk assessment, and secure SDLC practices
Strong cross-functional collaboration skills with the ability to translate broad security objectives into actionable, technical implementations

Nice to have

Kubernetes
HashiCorp Vault
Zero Trust architecture
SCIM
LDAP
Okta
Azure AD
AWS IAM
GCP IAM
Security compliance frameworks

Role overview

Role family
Software Engineering
Level
IC3 — security
Experience
3–8 years
Type
Individual Contributor
Remote policy
Hybrid (3 days)
Visa sponsorship
Not offered

Tech stack analysis

LANGUAGES
PythonGo
INFRASTRUCTURE
AWSAzureGCPMulti-cloud
TOOLS
OAuthSAMLOpenID ConnectCLI toolingREST APIs

Salary estimate

$200K – $320K
AI-estimated salary range
Confidence82%
Reasoning

OpenAI is one of the highest-paying AI companies in the industry. For a mid-to-senior SWE in security/infrastructure based in SF, NYC, or Seattle, total compensation typically ranges from $200K–$320K+ (base + equity + bonus). Security infrastructure engineers at frontier AI labs command premium compensation. Levels.fyi and public OpenAI offer data corroborate this range, with senior ICs often exceeding $300K TC.

See the AI-estimated salary range for this role

Sign up free →

Green flags

6 items
Role sits at the intersection of AI and security — a high-demand, high-growth area with significant career upsidegrowth

Discover all 6 green flags for this role

Sign up free →

Benefits breakdown

See all benefits organized by category — health, financial, time off & more

Sign up free →

Hiring insights

JD quality
7/10
Urgency
medium
Autonomy
high
Team size
small (2-5)

See JD quality score, hiring urgency & team details

Sign up free →

Red flags

PRO4 items
No salary or equity range disclosed, which limits candidate ability to assess compensation fit upfrontcompensation

See all 4 red flags — what the JD isn't telling you

Sign up free →

Interview insights

PRO
Rounds
5
Duration
4 wks
Difficulty
very hard
Take-home
Yes

Get full interview breakdown — rounds, likely topics & prep tips

Sign up free →

Career path

PRO
Next roles
Senior Software Engineer, Identity InfrastructureStaff Security EngineerSecurity Architect

See where this role leads — full career progression

Sign up free →
About the company

OpenAI is the AI research laboratory behind GPT-4, ChatGPT, DALL-E, and the Codex API. With over 200 million weekly active ChatGPT users, OpenAI is at the forefront of large language model development and deployment. The company pursues a mission of building safe artificial general intelligence that benefits all of humanity.

HQSan Francisco, CA, USA
Interview difficultyvery hard
Build vs Maintainboth
Cross-functionalYes