安全工程师,应用安全
查看雇主原标题
Security Engineer, Application SecurityOpenAI · New York City · $266k – $445k
职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。
为什么值得关注?
发现指数 71/100,仅依据与该职位一起存储的证据计算。
- 新的雇主官方职位
- 已披露薪资
- 远程职位
- 检测到搬迁支持关键词
分数构成
- 时效性 (随职位发布时间变化)+18
- 雇主官方来源+15
- 已披露薪资+15
- 远程职位+8
- 提及搬迁+6
- 稀有职位+1
- 公司来源健康度+8
该职位未包含:提及签证担保、未出现在监控的职位板上。
这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。
职位描述
机器翻译关于团队 安全是 OpenAI 使命的基石,确保通用人工智能造福全人类。安全团队保护 OpenAI 的技术、人员和产品。我们在构建的内容上注重技术,但在工作方式上注重运营,并致力于支持 OpenAI 的所有产品和研究。我们安全团队的原则包括:优先考虑影响力、赋能研究人员、为未来的变革性技术做好准备,以及培养强大的安全文化。
关于该职位 作为应用安全方向的安全工程师,您将通过构建安全工具、代码审查、渗透测试和安全评估,负责识别和缓解软件应用程序中的安全漏洞。
我们正在寻找能够与开发团队紧密合作的人才,以确保安全编码实践贯穿整个软件开发生命周期,在安全风险出现之前加以预防。您还将为开发人员和其他利益相关者提供安全指导,在组织内培养安全意识文化。
该职位优先考虑在旧金山、西雅图或纽约市工作,但也可考虑远程工作。我们采用每周 3 天到办公室的混合工作模式,并为新员工提供搬迁援助。
在该职位中,您将: • 执行安全评估:定期进行安全评估、代码审查和渗透测试,以识别应用程序和软件中的漏洞。
• 开发和实施安全工具:设计、开发和实施安全工具、框架和方法,以保护应用程序免受安全威胁。
• 与开发团队协作:与开发团队紧密合作,确保安全最佳实践贯穿整个软件开发生命周期(SDLC),包括安全编码指南。
• 威胁建模和风险评估:进行威胁建模和风险评估,以主动识别潜在风险并制定缓解策略。
• 漏洞管理:跟踪、分析和管理应用程序中的漏洞,为修复工作提供指导和支持。
• 事件响应支持:协助调查、分析和响应与应用程序相关的安全事件,确保及时解决并做好记录
岗位职责
作为安全工程师(应用安全),您将负责通过构建安全工具、代码审查、渗透测试和安全评估,识别并缓解软件应用程序中的安全漏洞。 我们正在寻找能够与开发团队紧密合作,确保安全编码实践贯穿整个软件开发生命周期,在安全风险出现之前加以预防的人才。您还将为开发人员和其他利益相关者提供安全指导,在组织内培养安全意识文化。 该职位优先考虑常驻旧金山、西雅图或纽约市,但也可考虑远程工作。我们采用每周3天到办公室的混合工作模式,并为新员工提供搬迁协助。 在此职位上,您将: • 执行安全评估:定期开展安全评估、代码审查和渗透测试,以识别应用程序和软件中的漏洞。
• 开发和实施安全工具:设计、开发并实施安全工具、框架和方法论,以保护应用程序免受安全威胁。
• 与开发团队协作:与开发团队紧密合作,确保安全最佳实践贯穿整个软件开发生命周期(SDLC),包括安全编码指南。
• 威胁建模和风险评估:开展威胁建模和风险评估,主动识别潜在风险并制定缓解策略。
• 漏洞管理:跟踪、分析并管理应用程序中的漏洞,为修复工作提供指导和支持。
• 事件响应支持:协助调查、分析并响应与应用程序相关的安全事件,确保及时解决并记录事件。
• 紧跟安全趋势:持续了解最新的安全威胁、漏洞和技术,以增强应用程序中的安全措施。
如果您具备以下条件,可能会在该职位上表现出色: • 在信息安全、网络安全或相关领域拥有丰富经验,其中相当一部分经验来自领导或管理岗位。
• 对安全技术、工具和最佳实践有深入理解,包括在安全编码实践、威胁建模、风险评估和事件响应方面的经验。
• 在应用安全、软件开发或相关领域有经验,并对安全编码实践和应用程序安全框架有深入理解。
• 熟练掌握编程语言(如Python、Java、C++等),了解安全工具(例如Burp Suite、OWASP ZAP),并熟悉安全协议和加密方法。
• 具备出色的书面和口头沟通能力,能够向技术和非技术受众解释复杂的安全问题
关于OpenAI OpenAI是一家AI研究和部署公司,致力于确保通用人工智能造福全人类。我们不断拓展AI系统能力的边界,并寻求通过我们的产品将其安全地部署到世界各地。AI是一种极其强大的工具,其创建必须以安全性和人类需求为核心,而为了实现我们的使命,我们必须包容并重视构成人类全貌的众多不同视角、声音和经历。 我们是提供平等机会的雇主,不因种族、宗教、肤色、国籍、性别、性取向、年龄、退伍军人身份、残疾、遗传信息或其他适用的受法律保护特征而歧视任何人。 如需了解更多信息,请参阅OpenAI的《平权行动与平等就业机会政策声明》。 对申请人的背景调查将依照适用法律进行,对于美国候选人,有逮捕或定罪记录的合格申请人将依据相关法律获得就业考虑,包括《旧金山公平机会条例》、《洛杉矶县雇主公平机会条例》和《加州公平机会法》。对于非建制洛杉矶县的员工:我们合理认为,犯罪历史可能与以下工作职责存在直接、不利和负面的关系,可能导致有条件录用通知被撤回:保护委托给您的计算机硬件免遭盗窃、丢失或损坏;在雇佣终止或任务结束时归还您持有的所有计算机硬件(包括其中包含的数据);以及对专有、机密和非公开信息保密。此外,工作职责要求访问安全且受保护的信息技术系统及相关数据安全义务。 如您认为该职位发布不合规,请通过此表单提交报告以通知OpenAI。与职位发布合规无关的询问将不予回复。 我们致力于为残障申请人提供合理便利,可通过此链接提出请求。 OpenAI全球申请人隐私政策 在OpenAI,我们相信人工智能有潜力帮助人们解决巨大的全球挑战,我们希望AI带来的益处能够被广泛共享。加入我们,共同塑造技术的未来。
以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。
查看雇主原文
职位描述
About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments. We’re looking for people who will work closely with development teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge. You will also provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization. The role is preferred to be based in San Francisco, Seattle or New York City but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees. In this role, you will: • Perform Security Assessments : Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software.
• Develop and Implement Security Tools : Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats.
• Collaborate with Development Teams : Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines.
• Threat Modeling and Risk Assessment : Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies.
• Vulnerability Management : Track, analyze, and manage vulnerabilities in applications, providing guidance and support for remediation efforts.
• Incident Response Support : Assist in investigating, analyzing, and responding to security incidents related to applications, ensuring timely resolution and documentatio
岗位职责
As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments. We’re looking for people who will work closely with development teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge. You will also provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization. The role is preferred to be based in San Francisco, Seattle or New York City but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees. In this role, you will: • Perform Security Assessments : Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software.
• Develop and Implement Security Tools : Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats.
• Collaborate with Development Teams : Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines.
• Threat Modeling and Risk Assessment : Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies.
• Vulnerability Management : Track, analyze, and manage vulnerabilities in applications, providing guidance and support for remediation efforts.
• Incident Response Support : Assist in investigating, analyzing, and responding to security incidents related to applications, ensuring timely resolution and documentation of incidents.
• Stay Current on Security Trends : Continuously stay updated on the latest security threats, vulnerabilities, and technologies to enhance security measures in applications.
You might thrive in this role if you: • Extensive experience in information security, cybersecurity, or a related field, with a significant portion of that experience in leadership or management roles.
• Deep understanding of security technologies, tools, and best practices, including experience with secure coding practices, threat modeling, risk assessments, and incident response.
• Experience in application security, software development, or related areas with a strong understanding of secure coding practices and application security frameworks.
• Proficiency in programming languages (such as Python, Java, C++, etc.), knowledge of security tools (e.g., Burp Suite, OWASP ZAP), and familiarity with security protocols and encryption methods.
• Strong written and verbal communication skills, with the ability to explain complex security issues to both technical and non-technical audiences
About OpenAI OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity. We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic. For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement . Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations. To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form . No response will be provided to inquiries unrelated to job posting compliance. We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link . OpenAI Global Applicant Privacy Policy At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.