Skip to main content
Back to Jobs

Product Manager, Codex Security Controls & Partner Interfaces

Hiring in US only

This employer appears to hire only in the region above. Confirm you're eligible to be hired there before applying.

Build native security controls for Codex to govern identity and permissions

As a Product Manager on OpenAI's Cyber team, you will build native security controls for Codex, focusing on identity, roles, permissions, tenant isolation, and access to repositories, files, tools, MCP servers, secrets, networks, and infrastructure. You will also help define standard interfaces for customer and partner security systems to inspect activity, return policy decisions, receive telemetry, and initiate bounded responses. This role in...

Why This Role?

Work on securing Codex by default and making it governable by enterprises and interoperable with trusted security products

Key Responsibilities

  • Build native security controls for Codex identity, roles, permissions, and tenant isolation
  • Develop controls for access to repositories, files, tools, MCP servers, secrets, networks, and infrastructure
  • Define authority levels for read, write, execute, and deployment actions based on risk and reversibility
  • Design human and policy-based approval workflows for high-impact actions
  • Develop prompt-injection and untrusted-content defenses for Codex
  • Establish audit trails, provenance tracking, stop conditions, revocation, and rollback mechanisms

Requirements

  • Deep technical background in product management
  • Experience with identity, permissions, and access control systems
  • Familiarity with security concepts such as tenant isolation, secrets management, and network controls
  • Ability to collaborate with engineering, design, security, and safety teams
  • Experience defining interfaces for partner systems to integrate with security workflows
  • Understanding of audit trails, policy enforcement, and secure software development practices

Required Skills

product managementcybersecurityai securitypartner managementtechnical leadershipsecurity controlsidentity and access managementpartner interface designtechnical collaborationrisk-based authorization

Indonesia Context

Working Hours Overlap:
Minimal overlap — opposite hours
See remote (USD) vs local pay →
View Original Description from Ashby Job Boards

Original description from Ashby Job Boards

ABOUT THE TEAM OpenAI’s Cyber team works to make frontier AI safe, trusted, and transformative for developers and enterprises. This team is building the security foundation for Codex: the native controls that govern what Codex can access and do, and the interfaces that allow customers and security partners to inspect, constrain, approve, and respond to Codex activity. Our goal is to make Codex secure by default, governable by enterprises, and interoperable with the security products customers already trust. This extends the existing product direction around tenant-scoped tools, guarded actions, approval systems, and scalable partner interfaces. ABOUT THE ROLE We are looking for a deeply technical Product Manager to help build Codex security controls and the partner ecosystem around them. This role focuses on securing Codex itself: how identity, permissions, tools, MCP servers, repositories, secrets, networks, and high-impact actions are governed across Codex products. You will also help define standard interfaces through which authorized customer and partner systems can provide security context, inspect activity, return policy decisions, receive telemetry, and initiate bounded responses. You will work closely with Codex product and engineering, OpenAI Security and Safety, enterprise customers, and partners across application security, identity, cloud security, data security, infrastructure, and security operations. IN THIS ROLE YOU WILL Build native security controls for Codex Partner with engineering, design, security, and safety teams to develop controls for: - Identity, roles, permissions, and tenant isolation. - Access to repositories, files, tools, MCP servers, secrets, networks, and infrastructure. - Read, write, execute, and deployment authority. - Human and policy-based approvals. - Prompt-injection and untrusted-content defenses. - Audit trails, provenance, stop conditions, revocation, and rollback. Help establish a graduated authority model in which local, read-only, and reversible actions require less friction than actions involving production systems, credentials, sensitive data, or irreversible changes. Define partner interfaces Develop common, versioned interfaces that allow customer-selected security products to participate in Codex workflows. These interfaces may support: - Sharing trusted identity, task, resource, and environment context. - Inspecting code, commands, artifacts, tool calls, or planned actions. - Returning allow, deny, constrain, or require-approval decisions. - Exporting normalized execution and security telemetry. - Pausing activity, revoking access, or requiring reauthorization. Define clear requirements for authentication, authorization, customer consent, data minimization, latency, retries, failure behavior, auditability, and backwards compatibility. Ensure integrations use shared platform contracts rather than creating a different Codex architecture for every partner. Build the partner ecosystem Work directly with security vendors and enterprise design partners to turn the interfaces into production integrations. Create partner SDKs, reference implementations, technical documentation, test environments, conformance suites, and certification requirements. Prioritize partners based on customer value, technical relevance, deployment readiness, and their ability to improve the shared platform—not simply logo value or launch timing. Turn lessons from individual partner engagements into reusable product capabilities. Shape the customer experience Define how enterprise administrators configure and understand Codex security controls, including: - Policies by user, workspace, repository, environment, tool, or action. - Approved security providers and permitted data sharing. - Approval requirements and time-limited exceptions. - Policy inheritance and conflict resolution. - Audit, investigation, and incident-response workflows. Ensure developers receive clear, actionable explanations when an action is blocked or requires approval, rather than an opaque policy error. Establish evaluation and launch gates Work with security, safety, research, and engineering teams to test whether controls work under realistic and adversarial conditions. Evaluate risks such as permission bypass, prompt injection, malicious tools, secret exposure, cross-tenant access, stale authorization, partner outages, conflicting decisions, and incomplete audit evidence. Help determine when new Codex capabilities have sufficient controls, reliability, and usability for broader deployment. YOU MIGHT THRIVE IN THIS ROLE IF YOU - Have built enterprise security, developer-platform, infrastructure, or control-plane products. - Understand identity, authorization, sandboxing, secrets, tool use, APIs, and audit systems. - Think naturally in terms of trust boundaries, failure modes, and abuse paths. - Can balance security, developer productivity, latency, reliability, and customer control. - Have experience building integrations across complex enterprise systems or partner ecosystems. - Can turn conflicting partner requirements into a coherent platform. - Communicate credibly with developers, security architects, CISOs, researchers, and partner product teams. - Prefer measurable security outcomes and real adoption over demonstrations or integration announcements. NICE TO HAVE - Experience in application security, identity, cloud security, data security, source control, CI/CD, SIEM, or enterprise governance. - Familiarity with RBAC, ABAC, policy-as-code, OAuth, OIDC, workload identity, or secrets management. - Experience with AI agents, MCP, sandboxed execution, prompt-injection defenses, or agent-security evaluations. - Experience building SDKs, developer platforms, integration marketplaces, or certification programs. WHAT SUCCESS LOOKS LIKE During your first six months, you will have helped establish: - A clear roadmap for native Codex controls and partner-extensible controls. - A common architecture for security context, policy decisions, inspection, telemetry, and response. - Initial reference integrations with a focused group of partners. - Evaluation and launch criteria for high-risk Codex capabilities. - Baseline measures for control coverage, bypass resistance, latency, reliability, and developer experience. During your first year, you will have helped ship meaningful controls across sensitive Codex workflows, brought standardized partner interfaces into production use, and demonstrated that enterprises can grant Codex greater authority without sacrificing visibility, control, or accountability. About OpenAI OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.  We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic. For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement https://cdn.openai.com/policies/eeo-policy-statement.pdf. Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations. To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form https://form.asana.com/?d=57018692298241&k=5MqR40fZd7jlxVUh5J-UeA. No response will be provided to inquiries unrelated to job posting compliance. We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link https://form.asana.com/?k=bQ7w9h3iexRlicUdWRiwvg&d=57018692298241. OpenAI Global Applicant Privacy Policy https://cdn.openai.com/policies/global-employee-and-contractor-privacy-policy.pdf At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

Salary Context

Similar Product roles on LokerDollar pay around $225.72k/yr (range $50.633k–385k/yr, n=90 active listings).

Hiring at OpenAI

OpenAI has 68 other active roles on LokerDollar and has been hiring here since Mar 27, 2026 — across Product, Engineering, Data & Analytics.

View all OpenAI openings →
Company
OpenAI
Source
Ashby Job Boards
Salary
Job Type
full time
Location
United States · Remote
Category
Seniority
senior
PostedVerified
Jul 13, 2026

Share this job

Help a friend find their next remote role.

Frequently asked questions

Is Product Manager, Codex Security Controls & Partner Interfaces at OpenAI a remote job?
Yes. Product Manager, Codex Security Controls & Partner Interfaces at OpenAI is a fully remote role open to candidates worldwide.
What is the salary for Product Manager, Codex Security Controls & Partner Interfaces at OpenAI?
The listed pay range for this role is $293k–385k/yr.
What type of employment is Product Manager, Codex Security Controls & Partner Interfaces at OpenAI?
This is a full time position.
How do I apply?
Click the "Apply" button on this page to go to the official application at OpenAI.

Explore related

Market data & reports

Salary & skill-demand research built from our own listings data.

From the blog