Product Manager, Codex Security Controls & Partner Interfaces
openai
Job Score
100 ptsAbout the Team
OpenAI’s Cyber team works to make frontier AI safe, trusted, and transformative for developers and enterprises.
This team is building the security foundation for Codex: the native controls that govern what Codex can access and do, and the interfaces that allow customers and security partners to inspect, constrain, approve, and respond to Codex activity.
Our goal is to make Codex secure by default, governable by enterprises, and interoperable with the security products customers already trust. This extends the existing product direction around tenant-scoped tools, guarded actions, approval systems, and scalable partner interfaces.
About the Role
We are looking for a deeply technical Product Manager to help build Codex security controls and the partner ecosystem around them.
This role focuses on securing Codex itself: how identity, permissions, tools, MCP servers, repositories, secrets, networks, and high-impact actions are governed across Codex products.
You will also help define standard interfaces through which authorized customer and partner systems can provide security context, inspect activity, return policy decisions, receive telemetry, and initiate bounded responses.
You will work closely with Codex product and engineering, OpenAI Security and Safety, enterprise customers, and partners across application security, identity, cloud security, data security, infrastructure, and security operations.
In this Role you Will
Build native security controls for Codex
Partner with engineering, design, security, and safety teams to develop controls for:
Identity, roles, permissions, and tenant isolation.
Access to repositories, files, tools, MCP servers, secrets, networks, and infrastructure.
Read, write, execute, and deployment authority.
Human and policy-based approvals.
Prompt-injection and untrusted-content defenses.
Audit trails, provenance, stop conditions, revocation, and rollback.
Help establish a graduated authority model in which local, read-only, and reversible actions require less friction than actions involving production systems, credentials, sensitive data, or irreversible changes.
Define partner interfaces
Develop common, versioned interfaces that allow customer-selected security products to participate in Codex workflows.
These interfaces may support:
Sharing trusted identity, task, resource, and environment context.
Inspecting code, commands, artifacts, tool calls, or planned actions.
Returning allow, deny, constrain, or require-approval decisions.
Exporting normalized execution and security telemetry.
Pausing activity, revoking access, or requiring reauthorization.
Define clear requirements for authentication, authorization, customer consent, data minimization, latency, retries, failure behavior, auditability, and backwards compatibility.
Ensure integrations use shared platform contracts rather than creating a different Codex architecture for every partner.
Build the partner ecosystem
Work directly with security vendors and enterprise design partners to turn the interfaces into production integrations.
Create partner SDKs, reference implementations, technical documentation, test environments, conformance suites, and certification requirements.
Prioritize partners based on customer value, technical relevance, deployment readiness, and their ability to improve the shared platform—not simply logo value or launch timing.
Turn lessons from individual partner engagements into reusable product capabilities.
Shape the customer experience
Define how enterprise administrators configure and understand Codex security controls, including:
Policies by user, workspace, repository, environment, tool, or action.
Approved security providers and permitted data sharing.
Approval requirements and time-limited exceptions.
Policy inheritance and conflict resolution.
Audit, investigation, and incident-response workflows.
Ensure developers receive clear, actionable explanations when an action is blocked or requires approval, rather than an opaque policy error.
Establish evaluation and launch gates
Work with security, safety, research, and engineering teams to test whether controls work under realistic and adversarial conditions.
Evaluate risks such as permission bypass, prompt injection, malicious tools, secret exposure, cross-tenant access, stale authorization, partner outages, conflicting decisions, and incomplete audit evidence.
Help determine when new Codex capabilities have sufficient controls, reliability, and usability for broader deployment.
You Might Thrive in This Role If You
Have built enterprise security, developer-platform, infrastructure, or control-plane products.
Understand identity, authorization, sandboxing, secrets, tool use, APIs, and audit systems.
Think naturally in terms of trust boundaries, failure modes, and abuse paths.
Can balance security, developer productivity, latency, reliability, and customer control.
Have experience building integrations across complex enterprise systems or partner ecosystems.
Can turn conflicting partner requirements into a coherent platform.
Communicate credibly with developers, security architects, CISOs, researchers, and partner product teams.
Prefer measurable security outcomes and real adoption over demonstrations or integration announcements.
Nice to Have
Experience in application security, identity, cloud security, data security, source control, CI/CD, SIEM, or enterprise governance.
Familiarity with RBAC, ABAC, policy-as-code, OAuth, OIDC, workload identity, or secrets management.
Experience with AI agents, MCP, sandboxed execution, prompt-injection defenses, or agent-security evaluations.
Experience building SDKs, developer platforms, integration marketplaces, or certification programs.
What Success Looks Like
During your first six months, you will have helped establish:
A clear roadmap for native Codex controls and partner-extensible controls.
A common architecture for security context, policy decisions, inspection, telemetry, and response.
Initial reference integrations with a focused group of partners.
Evaluation and launch criteria for high-risk Codex capabilities.
Baseline measures for control coverage, bypass resistance, latency, reliability, and developer experience.
During your first year, you will have helped ship meaningful controls across sensitive Codex workflows, brought standardized partner interfaces into production use, and demonstrated that enterprises can grant Codex greater authority without sacrificing visibility, control, or accountability.
About OpenAI
OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.
We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.
For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement.
Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.
To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.
We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.
OpenAI Global Applicant Privacy Policy
At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.
About Product Management
Product Management is one of the most strategically relevant areas in technology organizations. The Product Manager is responsible for defining product vision, prioritizing features, and coordinating multidisciplinary teams to deliver value to users.
Essential skills include strategic thinking, data analysis, communication, leadership, and technical knowledge. Tools like Jira, Confluence, Miro, and analytics platforms are fundamental in daily work.
Salaries for PMs range from entry-level to senior positions at major tech companies, with growing opportunities for international remote work.
About Marketing
The Marketing area is strategic for the growth and positioning of any company. It encompasses traditional marketing, brand management, market research, trade marketing, product marketing, and market intelligence. Marketing professionals are responsible for planning and executing strategies that connect brands to their target audience.
Key skills include brand management, market research, competitive analysis, product marketing, trade marketing, pricing, relationship marketing, and channel development. Knowledge of research tools (Nielsen, Kantar, Ipsos), BI, and advanced spreadsheets is a differentiator.
Marketing professionals in technology companies are highly valued, especially those who master product marketing, go-to-market strategy, and data-driven marketing. The field offers opportunities from analyst to CMO, with a focus on growth, brand positioning, and return on investment.
About Product Manager
The Product Manager (PM) is the professional responsible for defining the strategy, vision, and roadmap of a digital product. They work at the intersection of technology, business, and user experience (UX), leading the discovery and delivery of solutions that solve real problems in a viable way for the company.
Key skills include product discovery, data and metrics analysis (AARRR, NPS, LTV), user research, go-to-market strategy, roadmapping, strategic prioritization, and leadership by influence. Tools like Amplitude, Mixpanel, Hotjar, Jira, and Notion are fundamental.
Product Managers play a central role in the growth of startups, scale-ups, and large technology companies, with career progression opportunities to Product Leader, Head of Product, and Chief Product Officer (CPO).
About Public Relations
The Public Relations (PR) area focuses on managing the reputation, image, and communication of an organization with its various stakeholders (such as clients, investors, employees, media, and the community). PR professionals develop corporate communication strategies, manage media relations (press relations), organize institutional events, and work in image crisis prevention and management.
Discover Other Areas
Understand the scope of work, key skills, and tools used in different career areas.
About People Analyst
The People Analyst is the professional responsible for transforming people data into strategic insights for HR decision-making. They combine data analysis knowledge with people management vision to help organizations understand workforce metrics, turnover, engagement, and diversity.
Key skills include people analytics, workforce analytics, turnover and retention analysis, HR metrics (time-to-hire, cost-per-hire, e-NPS), data visualization (Power BI, Tableau, Visier), workforce planning, and compensation analysis. Knowledge of statistics, SQL, and people analytics tools is a differentiator.
People Analysts in technology companies are highly valued, especially those who can translate complex people data into actionable insights for retention, diversity, and growth strategies. The field offers opportunities from HR analyst to head of people analytics, with a focus on data-driven people management.
About Web Master
The Web Master is the professional responsible for maintaining, securing, and ensuring the technical performance of websites and web applications. They manage servers, hosting infrastructure, uptime monitoring, and ensure everything runs fast and reliably.
Key skills include server management (Apache, Nginx), hosting (AWS, Google Cloud, Azure), CDN (Cloudflare), SSL, DNS, web security (WAF, firewall), performance (Core Web Vitals, cache, compression), and versioning (Git, CI/CD). Knowledge of Docker, WordPress, cPanel, and monitoring (Sentry, New Relic) is a differentiator.
Web Masters in technology companies are highly valued, especially those who master DevOps, SRE, and can guarantee uptime and performance at scale. The field offers opportunities from junior webmaster to SRE and infrastructure engineer, with a focus on reliability, security, and speed.
About Sales
The Sales area is responsible for generating revenue and expanding the customer base. B2B and B2C sales professionals are fundamental for sustainable growth of any organization.
Key skills include prospecting, negotiation, CRM (Salesforce, HubSpot), sales enablement, and value consulting. The consultative and data-driven approach is increasingly valued.
Consultative sellers and senior Sales Managers have very high earning potential, with OTE (On-Target Earnings) that can exceed monthly salaries in technology companies.
About Business Analysis
The Business Analyst (BA) is the professional responsible for identifying problems, opportunities, and solutions in organizational processes, acting as a bridge between business areas and the technology development team. They gather and specify requirements, map value streams, design future processes, and help ensure that software deliveries align with the company's strategic goals.
About Talent Acquisition
Talent Acquisition is the strategic area responsible for attracting, selecting, and hiring the best professionals for the organization. Unlike traditional recruitment, TA acts as a strategic business partner, aligning talent acquisition with the company's long-term objectives.
Key skills include advanced sourcing, employer branding, labor market analysis, talent pipeline management, and candidate experience. Tools like LinkedIn Recruiter, ATS (Greenhouse, Lever, Ashby), and assessment platforms are essential.
TA professionals in technology companies are highly valued, especially those who master tech sourcing, workforce planning, and recruitment metrics like time-to-hire and cost-per-hire.
Comments 0